AWS access keys publicly exposed and still valid
Data Leak
Summary
Hide ▲
Show ▼
More than 9,300 AWS access keys exposed in public sources between August 2022 and August 2026 remained active and valid, creating a live risk of cloud account takeover. The exposed set included company-linked keys, AWS root keys, and AdministratorAccess credentials. Working keys could let attackers access data, change infrastructure, create persistent admin access, or deploy cryptominers.
Related Happenings
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceAbout this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
AWS environment hit by data theft breach
Incident
H score26
First: 08.07.2026 15:30
Last: 08.07.2026 15:30
Sources 1
About this happening:
An AWS environment was compromised in an AI-assisted intrusion that enabled extortion, creating immediate risk of data theft and operational disruption. The actor...
AWS environment hit by data theft breach
IncidentAbout this happening: An AWS environment was compromised in an AI-assisted intrusion that enabled extortion, creating immediate risk of data theft and operational disruption. The actor...
Amazon Q Developer MCP trust flaw (CVE-2026-12957)
Vulnerability
H score32
First: 26.06.2026 16:53
Last: 26.06.2026 16:53
Sources 1
About this happening:
Amazon Q Developer had a high-severity trust-boundary flaw in MCP server handling that could let a malicious repository trigger commands on a developer machine and ste...
Amazon Q Developer MCP trust flaw (CVE-2026-12957)
VulnerabilityAbout this happening: Amazon Q Developer had a high-severity trust-boundary flaw in MCP server handling that could let a malicious repository trigger commands on a developer machine and ste...
CISA contractor GitHub repository exposed internal credentials
Data Leak
H score28
First: 18.05.2026 23:48
Last: 18.05.2026 23:48
Sources 1
About this happening:
A CISA contractor left a public GitHub repository exposing AWS GovCloud credentials, plaintext passwords, and other internal access material tied to CISA and *...
CISA contractor GitHub repository exposed internal credentials
Data LeakAbout this happening: A CISA contractor left a public GitHub repository exposing AWS GovCloud credentials, plaintext passwords, and other internal access material tied to CISA and *...
Latest development: 10.07.2026 19:00
CISA said that within moments of receiving information about internal AWS GovCloud keys and other material in a public GitHub repository owned by a contractor, its Office of the Chief Information Officer took swift and comprehensive action to mitigate exposure to CISA cloud resources and code repositories. The agency said internal incident response began on May 15, no customer or mission data was exposed, and the leaked credentials were not used outside CISA's environments.
AWS exposed-key hardening guidance for Amazon SES phishing abuse
Defensive Guidance
H score14
First: 04.05.2026 23:03
Last: 04.05.2026 23:03
Sources 1
About this happening:
Kaspersky urged organizations to harden AWS IAM and credential handling after exposed access keys were linked to phishing delivery through Amazon SES, reducing the...
AWS exposed-key hardening guidance for Amazon SES phishing abuse
Defensive GuidanceAbout this happening: Kaspersky urged organizations to harden AWS IAM and credential handling after exposed access keys were linked to phishing delivery through Amazon SES, reducing the...
Timeline
-
21.08.2026 18:55 3 articles · 13d ago
Truffle Security finds more than 9,300 exposed AWS access keys still active
Initial DisclosureTruffle Security found that more than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. The exposed set includes 817 keys linked to companies, 526 AWS root keys, and 242 Identity and Access Management (IAM) users with the AdministratorAccess policy. Truffle Security also says 88% of 10,616 reverified keys continued to authenticate as of August 10, that Hugging Face was the largest single source of leaked AWS keys at 8,482 unique exposures, and that the oldest sampled key dates back 17.4 years.
Show sources
- Hundreds of leaked AWS keys give full control over corporate accounts — www.bleepingcomputer.com — 21.08.2026 18:55
- Hundreds of leaked AWS keys give full control over corporate accounts — www.bleepingcomputer.com — 21.08.2026 18:55
- Researchers Uncover Thousands of Leaked AWS Keys — www.infosecurity-magazine.com — 24.08.2026 11:05