LIVE · cybersecurity feed
Live wire
CVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreCISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
breach

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise already finds and verifies leaked credentials across 800+ secret types, and with TruffleHog Analyze, it can also provide

zeroday.news ·

Truffle Security has introduced TruffleHog AWS Analyze, an expansion of its TruffleHog Enterprise platform designed to accelerate the remediation of leaked AWS credentials. This new feature enriches discovered AWS keys with detailed information on their permissions and access levels, enabling security teams to better assess risk and prioritize their response efforts.

TruffleHog Enterprise already identifies and verifies over 800 types of leaked secrets. With the addition of AWS Analyze, it now provides identity and access context for AWS, alongside existing support for SaaS platforms and Google Cloud. This allows organizations operating in multi-cloud environments to quickly understand the potential impact of a leaked secret and prioritize its remediation across all three platforms.

When an AWS credential is leaked, determining its potential impact often requires manual investigation into identity, permissions, and IAM relationships. TruffleHog AWS Analyze automates this process by identifying the AWS user or role associated with the credential, mapping its effective permissions, and revealing any roles it can assume to gain further access. This provides a clearer picture of the potential "blast radius." The tool also indicates when AWS returns incomplete results, alerting teams to a partial view of the analysis.

According to Dylan Ayrey, CEO of Truffle Security, the rapid creation and exposure of AWS credentials through agentic workflows often outpace a security team's ability to track them. Once embedded in automated processes, keys can be copied and reused extensively, persisting long after their original purpose is forgotten. TruffleHog AWS Analyze aims to provide the necessary context within the same workflow, helping teams understand exactly what has been exposed for quicker remediation.

AWS keys are frequently leaked, and many remain active long after exposure. A single AWS key can grant access to compute, storage, and databases, meaning a leak can expose the permissions controlling numerous systems, not just one. Recent research by Truffle Security found 64,024 unique leaked AWS keys from public code, container images, and datasets, with 88% still active. The median active leaked key had been exposed for five years, and only 14% had ever been rotated.

Among the closely examined keys, 84% had full administrator access, and one in six was a root key, granting full access to an AWS account. Surprisingly, 929 of these credentials had been flagged by AWS's own compromised-key quarantine policy, some more than three years prior, yet all remained authenticable. This indicated that despite AWS detecting the exposure, no remediation had occurred.

A scan of 7.6 petabytes of public AI training data on Hugging Face by TruffleHog revealed similar widespread exposure, with 3,343 live AWS keys still active. Over 900 of these keys could list S3 buckets containing at least 51.7 TB of private data. Julien Chaumond, CTO of Hugging Face, noted that while they proactively scan their platform with TruffleHog and notify publishers of verified secrets, an alert is just the beginning. He emphasized that a leaked key remains vulnerable until it is rotated, and showing teams the identity and access behind a credential helps translate notifications into action. Hugging Face users are advised to confirm their notification settings and rotate, rather than delete, any exposed keys.

By combining TruffleHog Enterprise's ability to find and verify every instance of a leaked key with the new access context provided by TruffleHog AWS Analyze, security teams are expected to achieve faster remediation of critical vulnerabilities.

breachcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

HOL Guard: Open-source antivirus for AI agents

HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with no internet connection. The people exposed here ar

ransomware

The cybercrime supply chain has five stages, each with a price

In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers who verify and resell access, ransomware-as-a-service operators who build the toolkit, affiliates who run the intrusion, a

security

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a written baseline. TCG’s requirements for Trusted Platfor

nation-state

Cybersecurity jobs available right now: August 25, 2026

Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, location, and call record information while acting as custodian of

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.