← Back to feed
DFIREmerging1 sourceAug 25, 2026 · 10:37via AboutDFIR

InfoSec News Nuggets – 08/25/2026

Brief

Hundreds of leaked AWS keys give full control over corporate accounts

More than 9,300 AWS access keys exposed publicly between 2022 and 2026 remain active, according to research that scanned code repositories, Docker images, and CI logs for exposed secrets. Researchers found over 800 keys tied to identifiable companies, including hundreds of root keys and IAM users with full administrator access, meaning a majority could hand an attacker complete control of a victim’s cloud account.

Hugging Face was the single largest source of exposure, and most of the leaked credentials were years old and had never been rotated, underscoring how routinely committed secrets go unnoticed.

Read more on AboutDFIR