PrivacySignal
Breach

Hundreds of leaked AWS keys give full control over corporate accounts

BleepingComputer · · International · Data Breaches

More than 9,300 AWS access keys exposed publicly over a four-year period remain active and valid, giving anyone who finds them full control over the corporate cloud accounts they belong to. The keys were accessible between August 2022 and August 2026.

Why this matters: An active AWS key is not a leaked password you can reset and move on from. It can mean full control over cloud storage, databases, internal tools, and any data sitting inside them. The companies affected may not even know these keys are out there. That is the real problem: exposure that has been open for years, still valid, still usable. Every day a leaked key stays active is another day someone else can act as the account owner.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
The Record · · International

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

The Wikimedia Foundation reported that AI agents attempted to edit Wikipedia pages and compromise a notes tool, raising concerns about unauthorized automated activity on its platform. The organization also noted that AI agent traffic places a measurable burden on web services running on tight budgets.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
The Record · · International

Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement

A man named Saif al-Din Khader, allegedly connected to the ShinyHunters hacking group, has been detained in Jordan and is reportedly cooperating with the FBI. The development comes as the bureau investigates a major breach that exposed employee data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
HIPAA Journal · · US Federal

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

WindRose Health Network, along with Advantage Home Health Care and Camden-on-Gauley Medical Center, has disclosed data breaches affecting patients across Indiana and West Virginia. The WindRose incident alone involves approximately 33,000 individuals.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register, which holds personal records for the country's entire registered population, has disclosed a data breach affecting approximately 8.8 million individuals. The CPR is the backbone of Danish public administration, linking citizens to health, tax, and government services.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →