• Sources: BleepingComputer report, HN discussion
  • Summary: Truffle Security scanned public sources and reported 431,875 exposed secrets and 64,024 unique AWS keys across 50,654 accounts. Of a re-verifiable subset of 10,616 keys, 88 percent still authenticated as of 2026-08-10, more than 9,300 keys. 526 of those were root keys and 242 were IAM users holding AdministratorAccess, summing to the 768 with full account control. The keys are old rather than newly leaked, with a median age of 1,831 days and only 398 of 2,903 dated keys ever given a successor. The Truffle Security research post did not resolve to a URL this run, so every figure here comes from the BleepingComputer article, published 2026-08-21 and updated 2026-08-22, which also carries an Amazon statement about quarantine policies. The only date that article gives for the research itself is the 2026-08-10 re-verification cutoff.
  • Why it matters: This is a rotation failure rather than a vulnerability waiting on a vendor patch, so an owner can close the exposure today by rotating and revoking rather than by upgrading.

send feedback on this story