Feeds.Feedburner Nearly 20 Billion Files Exposed Due to Misconfigured Cloud Buckets
Article Content
- •Nearly 20 billion files exposed due to misconfigured cloud storage buckets.
- •Exposed data includes 685K credential files and nearly 1M database dumps.
- •Amazon S3 accounts for over two-thirds of the exposed storage.
Researchers from Mysterium VPN reported that nearly 20 billion files have been exposed due to misconfigured cloud storage buckets across major providers like Amazon S3, Google Cloud, and Azure. The exposed files include 685,047 credential files and nearly 1 million database dumps, all accessible without authentication. The issue stems from user misconfigurations rather than vulnerabilities in the cloud platforms themselves. Amazon S3 accounts for over two-thirds of the exposed storage. The interconnectedness of these files increases the risk of complete data breaches from a single misconfigured bucket. Recommendations for mitigation include defaulting to private settings, avoiding the storage of sensitive data in object storage, and implementing regular vulnerability scans. Users are advised to use unique passwords and enable multi-factor authentication. The report emphasizes the urgent need for better security practices among cloud storage users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…