• News/
  • https://www.theregister.com/2025/03/31/cloud_security_explained_whats_left/

Cloud security explained: What’s left exposed?

The Register
·
Daniel Andrew, Head of Security Services, Intruder
·
Published Mar 31, 2025
·
Updated

Partner Content AWS customers might assume that security is taken care of for them - however, this is a dangerous misconception. While AWS secures its infrastructure, security within an organization's cloud environment is the customer's responsibility. Think of AWS security like a secure building: AWS provides the sturdy walls and roof, but the organization is in charge of the locks, the alarm system, and ensuring that no valuable data is left exposed. In this blog, we highlight what AWS doesn't secure with real-world examples, and share key actions organizations can take to protect their AWS environments. AWS operates on a Shared Responsibility Model, where both AWS and its customers have distinct security responsibilities. AWS secures the underlying infrastructure that powers its cloud services - including hardware, software, networking, and data centers - essentially providing the "walls and roof." On the other hand, customers are responsible for securing their data, applications, and configurations within the AWS environment - the "locks on the doors" and the "alarm system." In short, AWS handles security of the cloud, while its customers are responsible for security in the cloud. Understanding this distinction is crucial to maintaining a secure environment. Customer responsibilities and actions Let's look at some real-world vulnerabilities that fall under the customer's responsibility and what actions can be taken to mitigate them. The following examples focus on two key...

Read full article

Affected Software

6 affected components
AWS Metadata Service
AWS Identity and Access Management
AWS S3
Ubuntu Ubuntu=24.04 LTS
Unspecified Redis
GitLab GitLab
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary focus of the article on AWS cloud security?

The article emphasizes the misconception that AWS customers do not need to worry about security within their cloud environments.

2

What responsibilities do AWS customers have regarding their cloud security?

AWS customers are responsible for securing their cloud applications and data, despite AWS securing its infrastructure.

3

Which AWS services are highlighted as being critical for security considerations?

Important AWS services mentioned include AWS Metadata Service, AWS Identity and Access Management, and AWS S3.

4

What security risks are associated with the use of cloud services like AWS?

The article discusses how misconfigurations and inadequate security practices can expose cloud environments to vulnerabilities.

5

Are any specific software products mentioned that may be impacted by cloud security issues?

The affected software products mentioned include AWS Metadata Service, AWS Identity and Access Management, AWS S3, Ubuntu 24.04 LTS, Redis, and GitLab.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203