Researchers found that many cloud secrets leaked online were still powerful enough to let outsiders take over company systems. Truffle Security said more than 700 exposed Amazon Web Services keys still granted full account control among 10,616 keys reviewed from 2022 to 2026, while Intruder found 28,000 exposed Git repositories across 3.5 million active hosts containing active AWS, Stripe, OpenAI, Telegram, and GitHub credentials.
Why it matters: This is a direct risk to organizations because exposed keys can let attackers enter cloud accounts, source-code systems, and payment or messaging platforms without exploiting a software bug. Companies should rotate leaked credentials immediately, scan public repositories and hosts for exposed secrets, and review access logs for abuse.
SecurityWeek News
2026.08.28
100% relevant
The article provides concrete new research findings about active leaked credentials and exposed repositories, with actionable scope and affected platforms.
← Back to all stories