Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys
Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...
Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...
Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.
In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...
AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here...
The $1.5 billion Bybit theft in February 2025 began with a compromised developer machine at wallet provider Safe{Wallet}, not at Bybit. Attackers altered the web interface Bybit's signers trusted. Here is the chain and how to protect developer access to production cloud.
In January 2025, the Codefinger campaign encrypted Amazon S3 data using AWS's own SSE-C feature and stolen keys — no malware involved. AWS has since disabled SSE-C by default for new buckets. Here is how it worked and how to make S3 data recoverable.
Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.
The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...
When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...
The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...
On October 20, 2025, AWS's US-EAST-1 region suffered a major outage that disrupted a wide range of services — from banking and gaming apps to smart home...
Many AWS workloads depend on US-EAST-1 more than their owners realize. Here is how to reduce dependence on a single region's control plane.
Use this checklist to check whether an AWS workload is ready for a regional failure.
The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...
The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...
Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.
The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...
Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.
Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.
The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...
In November 2024, AWS launched centralized root access management for AWS Organizations. It lets security teams remove root user credentials from member...
AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your...
Use this checklist to lock down the AWS root user across your organization.
The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....