Cybersecurity News

Filters
Tag
Reset

Filtered by tag: credentials × Clear

Researchers Uncover Thousands of Leaked AWS Keys

Truffle Security researchers discovered more than 9,000 active, publicly exposed AWS key pairs on GitHub. The leaked credentials, embedded in public repositories, could allow attackers to access cloud resources and sensitive data. Many keys remained valid despite being public. The findings highlight ongoing risks from developers accidentally committing credentials to code repositories without proper secrets management practices.

Lessons Learned from CISA’s Recent GitHub Leak

CISA released a postmortem after a contractor accidentally exposed dozens of internal credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months. The leak went undetected until KrebsOnSecurity notified the agency. Security experts say the incident highlights critical gaps in credential monitoring and third-party contractor oversight that all security teams should learn from.