BleepingComputer reports that more than 9,300 Amazon Web Services access keys publicly exposed between August 2022 and August 2026 are still active and valid. The finding turns an old leak into a live access problem: keys that should have died with the incident are still able to reach corporate AWS accounts.
An exposed AWS access key works like a standing password for cloud APIs. If it is still enabled and still has privileges, anyone who finds it can create resources, read data, or move deeper into the account until the key is disabled.
For teams that store credentials in code, tickets, paste sites, or public repos, the lasting exposure is not the disclosure date but whether the key was ever revoked. A leak can remain an operational admin path long after the original mistake and long after people or projects have changed.