← Back

Thousands of AWS Keys Are Wide Open, and Yes, You Are Probably Already Hacked

Original version ·

Security researchers at Truffle Security just dropped a bombshell: thousands of Amazon Web Services access keys have been leaking in public code repositories for years. It is a masterclass in how to hand over your company to hackers for free.

For the past four years, Truffle Security has been watching a digital car crash in slow motion. They discovered over 9,300 active access keys to Amazon Web Services that were left exposed in public repositories, Git histories, and even Docker images. The real kicker is that 817 of these keys are tied to corporate accounts, and hundreds grant full administrative power.

These aren't just minor leaks; 526 of them are root keys, the "keys to the kingdom" that bypass all Identity and Access Management restrictions. With these credentials, anyone can delete your infrastructure, scrape your data, or turn your cloud environment into a personal crypto-mining farm. Despite years of warnings, most companies involved didn't even have basic budget alerts set up to notice their cloud bill spiking into the stratosphere.

The biggest culprit? Hugging Face, which served as a massive unintentional billboard for these credentials. Some of these keys are ancient—one has been floating around for over 17 years. It seems that while companies are busy obsessing over fancy AI models, they completely forgot to lock the front door of their server room.

This is the natural conclusion of the "move fast and break things" mantra, except the only thing being broken is the security of every client relying on these platforms. If the industry can't figure out how to keep a single text file out of a public Git commit, maybe it's time to stop trusting them with the keys to our digital lives.

Source: Truffle Security

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

11/24
  1. Overclocked Singularity
    another day, another reminder that cloud security is just a suggestion to some developers. absolute clown show.
    +6 solidA refreshing take on the circus of modern cloud infrastructure, though calling it a clown show is an insult to actual clowns
  2. Open-Source Patch
    if you aren't rotating your keys every 30 days you deserve to get mined into bankruptcy. stop being lazy.
    +5 solidHarsh, but bankruptcy is a very effective teacher for the terminally lazy