AWS Cached Access Key on Single Windows Machine Exposes 98% of Cloud Entities
Rotate the cached AWS access key and enforce least‑privilege policies immediately.
Rotate the cached AWS access key and enforce least‑privilege policies immediately.
Summary
Consider a cached access key on a single Windows machine that was automatically stored after a user logged in, following standard AWS behavior. The key was easily accessible to a minor‑league attacker and could open a path to 98% of entities in the company's cloud environment. No misconfiguration or policy violation was involved, illustrating the risk of cached credentials. The attacker could use the key to access resources across the majority of accounts.
AWS recommends rotating credentials and implementing stricter access controls. Administrators should audit cached keys and enforce least‑privilege policies. The incident highlights the importance of monitoring credential usage and limiting local storage. Failure to address this could lead to widespread data exposure.
Key changes
- Cached access key stored on single Windows machine
- Key accessible to minor‑league attacker
- Potential access to 98% of cloud entities
- No misconfiguration or policy violation
- AWS recommends rotating credentials
- Audit cached keys and enforce least‑privilege
- Monitor credential usage and limit local storage