[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts-mt4mql0n":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"a1874569-8364-428b-9945-1641164164d4","Hundreds of leaked AWS keys give full control over corporate accounts","hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts-mt4mql0n","Over 9,300 active AWS access keys with admin privileges have been publicly exposed in code repositories and public sources, with Hugging Face identified as a major leak vector. Attackers with these keys can take full control of affected AWS accounts, exfiltrate data, compromise infrastructure, and deploy cryptominers. Any organization using AWS needs to assume their credentials may be compromised.","critical","advisory",[],[13,14,15,16],"AWS","Amazon","Truffle Security","Hugging Face","Immediately audit all AWS access keys in your environment. Revoke any keys found in public repositories or source code. Rotate all remaining keys and enable CloudTrail logging to detect unauthorized access or API activity. Check CloudTrail for any suspicious activity dating back 90 days.",[19],"a82ae907-6daa-413f-bba9-f1b607b1ce51",null,[22],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts\u002F","active","2026-08-24T17:05:46.044+00:00","2026-08-22T17:05:54.516415+00:00","2026-08-22T17:05:58.085006+00:00",[28],{"id":19,"title":6,"url":22}]