- What: Thousands of active AWS access keys remain publicly exposed
- Impact: Organizations using AWS may be at risk of unauthorized access
Cloud Security Thousands of active AWS access keys remain publicly exposed August 21, 2026 Share By SC Staff (Adobe Stock) More than 9,300 Amazon Web Services (AWS) access keys that were publicly exposed between August 2022 and August 2026 are still active and valid, according to a recent report by Bleeping Computer. Truffle Security has been tracking this exposure for four years, finding that 817 of the exposed keys were linked to companies, with 526 being AWS root keys. Researchers noted that 242 keys were associated with Identity and Access Management (IAM) users holding the AdministratorAccess policy, granting full permissions across AWS services. The company identified 431,875 AWS secrets in various code repositories and extracted 64,024 unique AWS keys. Of the 10,616 keys with verifiable credentials, 88% remained active as of August 10. Hugging Face, a platform for AI models, was the largest source of leaked keys, with 8,482 exposures. Many of these keys were old, with a median age of about five years, and had likely never been rotated. Full control of an AWS account could allow attackers to exfiltrate data, take control of applications, or deploy cryptominers. Truffle Security recommends deleting root access keys, reviewing IAM credentials, rotating exposed keys, and configuring budget alerts. Source: Bleeping Computer An In-Depth Guide to Cloud Security Get essential knowledge and practical strategies to fortify your cloud security. Learn More SC Staff Related Cloud Security Researchers demonstrate faster remote Spectre attack against Cloudflare Workers SC Staff August 20, 2026 The researchers developed an end-to-end experiment using an attacker Worker and a victim Worker within the same production environment. API security What Cloud Security Actually Controls SC Media Editorial Intelligence, reviewed by Dustin Sachs August 18, 2026 In the Cloud, Permissions Define the Blast Radius API security Cloud Governance and Assurance: Evidencing Control Effectiveness Across Providers SC Media Editorial Intelligence, reviewed by Rajan Nagarajan August 18, 2026 When controls exist on paper but fail in practice, the gap is usually in the evidence — not the policy Related Events Cybercast From prompt to exploit: How LLMs are changing API attacks On-Demand Event Cybercast Cloud Security: The AI Effect and How to Proceed On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Cloud Computing Greynet You can skip this ad in 5 seconds