ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility
Overview
A recent study by Aryon Security found that over 3.7 million short-lived cloud resources on AWS are exposed to the public, often containing highly sensitive information. These exposures typically last only a few minutes to hours, which makes them difficult for existing security tools like Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platforms (CNAPP) to detect. This gap poses a significant risk for organizations using AWS services that allow public sharing, as attackers could easily exploit these misconfigurations within that short window. The findings raise concerns about the limitations of current security practices and the need for proactive measures to protect cloud resources from being inadvertently exposed. Organizations must reassess their security strategies to address these fleeting vulnerabilities effectively.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: AWS cloud resources, Cloud Security Posture Management (CSPM), Cloud Native Application Protection Platforms (CNAPP)
- Action Required: Organizations should implement more frequent monitoring and automated detection systems for short-lived cloud resources, along with reviewing and tightening permissions on public-facing AWS services.
- Timeline: Newly disclosed
Original Article Summary
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy them.  The findings expose a fundamental limitation of the reactive CSPM/CNAPP model: some cloud misconfigurations can be exploited … More → The post ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility appeared first on Help Net Security.
Impact
AWS cloud resources, Cloud Security Posture Management (CSPM), Cloud Native Application Protection Platforms (CNAPP)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should implement more frequent monitoring and automated detection systems for short-lived cloud resources, along with reviewing and tightening permissions on public-facing AWS services.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Amazon.