Tech & AI News
The Next Web

Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible

Truffle Security identified 768 exposed AWS credentials, including 526 root keys, from 431,875 secrets gathered across repositories, Docker images and CI logs, and 88% of the 10,616 tested keys remained active as of 10 August. AWS’s quarantine policy still allows compromised keys to assume roles, execute commands, stop CloudTrail logging and set immutable bucket retention, leaving substantial attack surface despite the mitigation.