[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-768-leaked-aws-keys-still-work-fix-has-gaps":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},5786,"768-leaked-aws-keys-still-work-fix-has-gaps","768 Leaked AWS Keys Still Work, Fix Has Gaps","Truffle Security found 768 active AWS keys, including 526 root keys, and says AWS's quarantine policy still leaves plenty of damage possible.","Security researchers found hundreds of live AWS keys sitting in public code, and Amazon's automatic safety net still leaves the vault door open.\n\nTruffle Security uncovered 768 leaked Amazon Web Services keys that grant full control over corporate cloud accounts. Of those, 526 are root keys - the master credentials meant to be locked away, not left in a repository. Eighty-eight percent of the keys the researchers tested were still active, meaning anyone who found them first could have used them. AWS does quarantine keys it detects as compromised, but that policy still permits a long list of potentially damaging actions.\n\nThat gap matters because root keys are the crown jewels of any AWS account: they can create and delete resources, spin up new users, and rack up bills with no upper limit. A quarantine that stops short of full lockdown is a half-closed door, and 768 working keys is a lot of doors to check.\n\nRate-limiting a burglar is not the same as changing the locks.","[\"aws\",\"cloud-security\",\"credential-leaks\",\"security-research\"]","2026-08-22T10:35:10.000Z","2026-08-22T11:10:05.238Z","2026-08-22T11:10:17.141Z","published",null,[],"security",[26,27,28,29],"aws","cloud-security","credential-leaks","security-research",[31],{"name":32,"url":33},"The Next Web","https:\u002F\u002Fthenextweb.com\u002Fnews\u002Fresearchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-possible",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3303,"2026-08-22T16:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",454,"2026-08-22T13:57:17.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",212,"2026-08-21T12:20:54.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",144,"2026-08-21T14:58:28.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Science","science",91,"2026-08-20T10:01:48.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",49,"2026-08-22T10:10:57.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]