← Back to Feed
Hundreds of leaked AWS keys give full control over corporate accounts
August 21, 2026 · BleepingComputer · Severity: MEDIUM
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
Key Takeaways
- Hundreds of leaked AWS access keys have been discovered that grant full control over corporate cloud environments and resources.
- The exposed keys were found in public code repositories, misconfigured CI/CD pipelines, and exposed environment files.
- Organizations must implement automated secret scanning, enforce key rotation policies, and use IAM roles instead of hardcoded credentials in cloud deployments.