ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
CRITICAL Cloud

Leaked AWS access keys stayed active and grant full account control

Source headline: Hundreds of leaked AWS keys give full control over corporate accounts

Threat level Critical
Signal strength 95/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

More than 9,300 Amazon Web Services (AWS) access keys were publicly exposed between August 2022 and August 2026. The article states that many of those keys are still active and valid. With the exposed keys, attackers can gain full control over corporate accounts. This creates a direct risk of unauthorized access to cloud resources and associated systems. The key exposure window spans four years, which increases the chance that credentials have been used and reused. Rotate or revoke any exposed AWS access keys immediately and audit for unauthorized use using AWS logging and monitoring.

Recommended Action

Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#credential-theft #aws #account-compromise #access-keys #cloud
Original reporting BleepingComputer Hundreds of leaked AWS keys give full control over corporate accounts
Open original source