Abandoned cloud storage buckets present a major, but largely overlooked, threat to Internet security, new research has shown. The risks arise when bad actors discover and re-register these neglected digital repositories under their original name, and then use them to deliver malware or carry out other malicious actions against anyone still requesting files from them. The threat is far from theoretical, and the weakness is, in fact, incredibly easy to exploit, researchers from watchTowr discovered recently. The findings came as a follow-up to previous research they conducted last year on risks tied to expired and abandoned Internet domain names. For the latest study, the researchers first searched the Internet for Amazon AWS S3 buckets referenced in deployment code or a software update mechanism. They then checked to see if those mechanisms were pulling down unsigned or unverified executables or code from the S3 buckets. The researchers discovered some 150 S3 buckets that at some time a government organization, Fortune 500 company, technology company, cybersecurity vendor or major open source project had used for software deployment, updates, configurations and similar purposes, and then abandoned. To check what would happen, watchTowr registered the unused buckets using their original names for a total of around $400, and enabled logging on them to see who might request files from each S3 bucket. The company also wanted to find out what these users would request from the stor...
Abandoned AWS Cloud Storage: A Major Cyberattack Vector
Dark Reading
·Jai Vijayan
·Published Feb 5, 2025
·Updated
Affected Software
2 affected components
Amazon AWS S3
Amazon AWS S3 Bucket
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the security risks associated with abandoned AWS cloud storage buckets and their potential exploitation by cybercriminals.
2
What security implications are discussed in the article?
The article highlights how neglected cloud storage can be re-registered by attackers, leading to unauthorized access and data breaches.
3
What products or software are affected by these security risks?
The primary affected products mentioned in the article are Amazon AWS S3 and AWS S3 Buckets.
4
How can organizations mitigate the risks of abandoned cloud storage?
Organizations can mitigate risks by regularly auditing their cloud storage accounts and removing unused or outdated buckets.
5
What recommendations are made for securing AWS cloud storage?
The article suggests implementing strict access controls and monitoring for any unauthorized activities in cloud storage.