Breaking
Iranian president says time to end war with US from ‘position of strength’Palestinian-British girl, 6, dies days after family drowned off UK coastMalaysia reaffirms ASEAN Haze-Free commitment by 2030Chinese New Year logistics crisis as invisible organisers retireRussian drones strike Ukrainian shopping centre, killing 16 and injuring over 130SPX Express EV is now in service: Starting with DFSK EC35 electric vans for Klang ValleyMGS5 EV CKD COM launched in Malaysia with RM100,900 starting priceSynkLoader malware hits Microsoft Teams via fake IT-helpdesk phishingHundreds of exposed AWS keys still give full control over corporate accountsMicrosoft turns Defender’s own driver into file-wiper for Windows 7 through 11Suzuki launches e-Vitara EV in Singapore with 345 km range, S$169,888 priceIJM Perennials Lightwater Residences at The Light Waterfront Penang checks off every definition of luxuryIndonesia fast-tracks I-EU CEPA to start in Q4 2026Space mirrors pose new risks to Malaysia’s astronomy and biotech sectorsNvidia takes minority stake in data-centre developer CloverleafSunway Construction Accepts RM1 Billion Engineering Contract From US Tech GiantDissected: How scammers built a fake Zoom call from real videos of Singapore PM Wong and other leadersRoxy Square shove shows clash over child-touching norms in SingaporeStop Hunting, Start Solving: Accelerating Root Cause Analysis with Agentic AIAWS Glue 6.0 launches with 30% lower hourly pricing and full Apache Iceberg v3 support.Iranian president says time to end war with US from ‘position of strength’Palestinian-British girl, 6, dies days after family drowned off UK coastMalaysia reaffirms ASEAN Haze-Free commitment by 2030Chinese New Year logistics crisis as invisible organisers retireRussian drones strike Ukrainian shopping centre, killing 16 and injuring over 130SPX Express EV is now in service: Starting with DFSK EC35 electric vans for Klang ValleyMGS5 EV CKD COM launched in Malaysia with RM100,900 starting priceSynkLoader malware hits Microsoft Teams via fake IT-helpdesk phishingHundreds of exposed AWS keys still give full control over corporate accountsMicrosoft turns Defender’s own driver into file-wiper for Windows 7 through 11Suzuki launches e-Vitara EV in Singapore with 345 km range, S$169,888 priceIJM Perennials Lightwater Residences at The Light Waterfront Penang checks off every definition of luxuryIndonesia fast-tracks I-EU CEPA to start in Q4 2026Space mirrors pose new risks to Malaysia’s astronomy and biotech sectorsNvidia takes minority stake in data-centre developer CloverleafSunway Construction Accepts RM1 Billion Engineering Contract From US Tech GiantDissected: How scammers built a fake Zoom call from real videos of Singapore PM Wong and other leadersRoxy Square shove shows clash over child-touching norms in SingaporeStop Hunting, Start Solving: Accelerating Root Cause Analysis with Agentic AIAWS Glue 6.0 launches with 30% lower hourly pricing and full Apache Iceberg v3 support.
Economy

Hundreds of exposed AWS keys still give full control over corporate accounts

More than 768 active Amazon Web Services access keys exposed between August 2022 and August 2026 still give full control over corporate cloud accounts, Truffle Security said.

Source: BleepingComputer · August 22, 2026 at 1:08 AM · AI-assisted report

Single-source

KUALA LUMPUR, 22 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

More than 768 active Amazon Web Services access keys exposed between August 2022 and August 2026 still give full control over corporate cloud accounts, Truffle Security said.

Market Impact

The security firm tracked 9,300 AWS keys made public during the four-year period and found 768 that remained valid. Of those, 242 belong to Identity and Access Management users with the AdministratorAccess policy, which grants unrestricted rights to create, modify, delete and view virtually all AWS services and resources. Each of the 768 live keys “grants full control of a company’s AWS account,” Truffle Security said.

Truffle Security extracted 64,024 unique AWS keys from code repositories, Git history, Docker images and CI logs, corresponding to 50,654 AWS accounts after removing duplicates. It verified 10,616 keys and found that 88% were still authenticating as of August 10. Attackers can use such access to deploy cryptominers, potentially racking up large cloud charges; only 262 of 2,754 readable accounts had budget alerts enabled.

Hugging Face, a platform where developers share AI models, datasets and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique exposures. Of those, 17.9% were root keys—the highest-privileged identities not restricted by IAM permissions.

For the 2,903 keys with creation dates, the median age was 1,831 days (about five years), and the oldest had existed for 17.4 years. Only 398 (13.7%) had a newer access key associated with the same user, indicating most had never been rotated.

Truffle Security recommends deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, configuring budget alerts and treating any credential committed to a public source as compromised. Truffle Security said its testing was limited to read-only metadata and that it had notified all identifiable owners of the exposed credentials.

Once attackers use valid credentials, signature-based prevention falls to 50%, according to the Blue Report 2026, which measured defenses across 338 million simulations in customer production environments.

Related: Amazon

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.