HomeCyber Balkans768 Leaked AWS Keys Remain Active with Full Admin Access to Corporate...

768 Leaked AWS Keys Remain Active with Full Admin Access to Corporate Accounts

Published on

spot_img

Investigation Exposes 768 Active AWS Access Keys, Heightening Security Risks

A comprehensive investigation has revealed a staggering 768 AWS access keys that have been publicly exposed, a situation posing a severe threat to the integrity of corporate cloud environments. These active keys, which grant full administrative privileges, present significant risks including account takeover, data theft, infrastructure exploitation, and even potential cloud billing fraud. The identification of these vulnerabilities raises urgent concerns about security practices across organizations utilizing Amazon Web Services (AWS).

Among the compromised credentials, researchers documented finding 526 root access keys and 242 IAM (Identity and Access Management) user keys associated with AWS’s AdministratorAccess managed policy. In the wrong hands, these access keys could grant an attacker sweeping control over an organization’s AWS resources. This includes critical functions related to identity management, storage, compute instances, security configurations, and billing settings. An attacker could essentially gain comprehensive control over an entire AWS account.

The investigation, notably conducted by Truffle Security, scrutinized publicly exposed AWS credentials from August 2022 to August 2026. The findings were alarming, as the research efforts involved re-validating over 10,616 key pairs on August 10, revealing that a significant 88% of these keys successfully authenticated. The exposed keys were discovered in numerous publicly accessible locations, including Git histories, Hugging Face datasets, Docker images, package registries, and CI/CD logs. Even though the research deliberately refrains from naming organizations impacted by these vulnerabilities, the sheer number of active secrets signifies that publicly leaked cloud credentials often remain valid and usable for extended periods—sometimes for years.

During the course of this analysis, Truffle Security identified a total of 64,024 unique AWS access key pairs among 431,875 publicly reported instances. Alarmingly, a considerable portion of these—10,625, or 16.6%—were classified as root credentials. Root access keys are particularly hazardous due to their lack of affiliation with IAM permissions, effectively granting an attacker complete ownership of the AWS account. This level of access allows malicious actors to create new users, alter vital security controls, manipulate data, deploy additional resources, adjust billing configurations, and in some extreme cases, even terminate the account entirely.

The research highlighted Hugging Face as the most significant source of exposed AWS credentials, with an unsettling 8,482 unique active keys discovered across 3,394 public datasets. It was noted that 17.9% of these keys were classified as root keys. Many datasets comprised public code collected for artificial intelligence training and development, complicating the long-term management of credentials. Once a key finds its way into a public repository, it risks replication across training datasets, container images, and package archives, rendering efforts to delete the original file ineffective in eliminating the leaked secret from the broader internet landscape.

Significantly, the investigation also pointed out that numerous active credentials were quite old. For the 2,903 keys whose creation dates were ascertainable, the median age of these active leaked keys was an astonishing 1,831 days, translating to roughly five years. The oldest discovered credential was a staggering 17.4 years old. Only a small fraction of these keys—merely 25—had been created within the past 30 days, underscoring a critical insight: the biggest risks stem from forgotten, outdated credentials rather than just new developer errors.

Rotation practices appear to be alarmingly inadequate. Among the 2,903 keys, just 398 were associated with a newer credential linked to the same IAM user, indicating that around 86% of these keys had neither been replaced nor revoked. Additionally, AWS had already flagged 929 active IAM keys via its AWS Compromised Key Quarantine policy, yet they continue to exist in affected environments, representing a failure in remedial actions.

Out of 817 active keys linked to business accounts, a surprising 768 still held full administrative capabilities. The investigation also flagged 130 live root keys connected to AWS Organizations management accounts, consequently putting associated member accounts at further risk.

In light of these alarming discoveries, organizations are urged to take immediate action. Best practices include the elimination of root access keys, enforcement of key-age limits, immediate rotation of exposed credentials, and continuous monitoring for unauthorized activities. Furthermore, configurations for budget alerts should be set up to mitigate unexpected charges. Any publicly exposed secret should be treated as permanently compromised, necessitating urgent organizational response strategies to secure vulnerable cloud environments effectively.

As the digital landscape continues to evolve, organizations must remain vigilant in their cybersecurity efforts, ensuring that such serious vulnerabilities are addressed swiftly to prevent future incidents.

Source link

Latest articles

GitHub’s 8-Hour Outage Linked to Autoscaling Failure

On August 17, GitHub experienced a significant service disruption lasting 7 hours and 47...

Webinar Announcement – Governance of AI Agents by Fortune 500 Security Teams

Transforming Security: Fortune 500 Leaders Adapt to AI Agents Organizations within the Fortune 500 are...

Zero-Click Grok Attack Enables Hackers to Steal Chat History via Encrypted Prompt Injection

New Prompt-Injection Technique Exposes Potential Vulnerabilities in AI Systems A recently revealed prompt-injection technique raises...

Meta Collects Three Times More Data Than Apple and Microsoft

A recent study conducted by the virtual private network (VPN) provider Surfshark has uncovered...

More like this

GitHub’s 8-Hour Outage Linked to Autoscaling Failure

On August 17, GitHub experienced a significant service disruption lasting 7 hours and 47...

Webinar Announcement – Governance of AI Agents by Fortune 500 Security Teams

Transforming Security: Fortune 500 Leaders Adapt to AI Agents Organizations within the Fortune 500 are...

Zero-Click Grok Attack Enables Hackers to Steal Chat History via Encrypted Prompt Injection

New Prompt-Injection Technique Exposes Potential Vulnerabilities in AI Systems A recently revealed prompt-injection technique raises...