Source: The Next Web
Truffle Security found 768 exposed AWS credentials still active, with over two-thirds being root keys. Most organizations don't revoke compromised keys at scale even after public disclosure. AWS's containment policies allow leaked credentials to persist, shifting responsibility to individual account holders to notice and act—a lag that attackers exploit.