惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
T
The Exploit Database - CXSecurity.com
Cyberwarzone
Cyberwarzone
C
CXSECURITY Database RSS Feed - CXSecurity.com
E
Exploit-DB.com RSS Feed
S
Security @ Cisco Blogs
Scott Helme
Scott Helme
H
Hacker News: Front Page
I
Intezer
N
News and Events Feed by Topic
V
V2EX - 技术
L
LINUX DO - 热门话题
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
K
Kaspersky official blog
S
Securelist
Latest news
Latest news
P
Proofpoint News Feed
C
Cisco Blogs
T
Troy Hunt's Blog
The Register - Security
The Register - Security
V
Vulnerabilities – Threatpost
T
Threat Research - Cisco Blogs
Microsoft Azure Blog
Microsoft Azure Blog
L
LangChain Blog
B
Blog RSS Feed
小众软件
小众软件
T
Tenable Blog
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
SecWiki News
SecWiki News
Jina AI
Jina AI
Know Your Adversary
Know Your Adversary
Recorded Future
Recorded Future
Google Online Security Blog
Google Online Security Blog
D
Docker
W
WeLiveSecurity
Attack and Defense Labs
Attack and Defense Labs
T
Tor Project blog
A
About on SuperTechFans
U
Unit 42
S
Security Archives - TechRepublic
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
O
OpenAI News
NISL@THU
NISL@THU
雷峰网
雷峰网
Vercel News
Vercel News
AWS News Blog
AWS News Blog
L
Lohrmann on Cybersecurity
Google DeepMind News
Google DeepMind News

Security Affairs

Romanian Hacker Gets Nearly 5 Years in US Prison Over Network Intrusion The LA Metro Attack Wasn’t Hacktivism. It Was a State Operation With a Costume On. How cybersecurity firms took down Glassworm botnet in one shot Dutch Government just said no to an American firm buying the keys to their digital State Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. The Hidden Ransomware Economy Running on Exposed Databases Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers Lazarus APT unveils fileless remote access Trojan designed to evade detection Third-Party Cyberattack Impacts Patient Information at The Oncology Institute Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites 340 Million OnlyFans Profiles Allegedly Rebuilt from Leaks Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation FBI director Kash Patel’s brand website taken offline after malware reports SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98 Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION Anthropic’s Project Glasswing: 10,000+ Vulnerabilities Found in One Month, and the Patching Problem Has Never Been More Obvious U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack Why pure extortion is replacing traditional ransomware Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets Authorities arrest 23-year-old accused of running the Kimwolf botnet U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalog One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure U.S. CISA adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog Global law enforcement operation takes First VPN offline Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix Cisco fixed maximum severity flaw CVE-2026-20223 in Secure Workload Discord adds end-to-end encryption to voice and video calls by default PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch Microsoft issues YellowKey mitigation, no patch yet Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free A malicious VS code extension just breached GitHub ‘s internal repositories DirtyDecrypt: PoC Released for yet another Linux flaw Alleged Huawei zero-day blamed for the 2025 Luxembourg telecom crash Drupal is rolling out an emergency security update on May 20. You cannot miss it Microsoft dismantled malware-signing network Fox Tempest Poland shifts away from Signal following cyberattacks on officials’ accounts Massive MENA cybercrime Operation Ramz disrupts infrastructure and arrests 201 suspects Shai-Hulud worm copycats emerge after source code leak Grafana confirms GitHub token breach cybercrime group claims the attack ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed Public Amazon bucket leaks sensitive guest data from Japanese hotel platform Tabiq Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fix Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97 Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog Russian APT Turla builds long-term access tool with Kazuar Botnet evolution OpenAI hit by supply chain attack linked to malicious TanStack packages Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day Ghostwriter group resumes attacks on Ukrainian Government targets Researchers uncover YellowKey and GreenPlasma Windows Zero-Days Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall U.S. CISA adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog Linux Kernel bug Fragnesia allows local root access attacks Broadcom releases VMware Fusion security update for root access bug NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to light FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign Nitrogen Ransomware claims massive data theft from Foxconn Microsoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarming OpenLoop Health confirms January 2026 Data breach affecting 716,000 Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations Instructure settles with hackers following massive student data theft Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator Hackers accessed BWH Hotels reservation system for months The world’s most “Dangerous” AI, Anthropic’s Mythos, found only one flaw in curl Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor WannaCry, the ransomware attack that changed the history of cybersecurity Android banking Trojan TrickMo evolves using TON network for C2 Identity security firm SailPoint discloses GitHub repository breach Google warns artificial intelligence is accelerating cyberattacks and zero-day exploits Crimenetwork returns after takedown, dismantled again by German authorities U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Instagram removed end-to-end encryption for DMs. What should users do? New cPanel vulnerabilities could allow file access and remote code execution Official JDownloader site served malware to Windows and Linux users between May 6 and May 7 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 96 Security Affairs newsletter Round 576 by Pierluigi Paganini – INTERNATIONAL EDITION Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence Braintrust security incident raises concerns over AI supply chain risks RansomHouse says it breached Trellix and exposes internal systems Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident Dirty Frag: A new Linux privilege escalation vulnerability is already in the wild AI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military Strategy Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog Cisco patches high-severity flaws enabling SSRF, code execution attacks From Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacks U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog Taiwan High-Speed Rail Emergency Braking Hack: How a Student Stopped the Trains and Exposed a Major Security Gap After 17 years, Gavril Sandu extradited to U.S. for hacking scheme Iranian cyber espionage disguised as a Chaos Ransomware attack
19.6 Billion Files Are Sitting Open on the Internet. No Password Required
Pierluigi Pa · 2026-05-28 · via Security Affairs

19.6 Billion files are exposed in misconfigured cloud buckets, including 685K credential files and nearly 1M database dumps.

There’s a comfortable myth most people carry around: that the data they hand to companies is locked somewhere safe. Researchers at Mysterium VPN just ran the numbers, and the numbers disagree. Across 535,480 publicly listable cloud storage buckets on Amazon S3, Google Cloud, Azure, DigitalOcean, and Alibaba, they counted 19.6 billion files accessible to anyone with a browser and a URL. No login. No exploit. Just a web request.

The research team analyzed bucket metadata captured in March 2026, categorizing files by type and filename. They didn’t access or download any content. They didn’t need to. The presence of these file types in open storage is the finding, and it’s bad enough on its own.

Most of those 19.6 billion files are mundane: images, documents, logs, the ordinary debris of running software at scale. The question worth asking is how much of the exposure is the kind of material that should never be reachable by a stranger.

“19.6 billion files are currently exposed across 535,480 publicly listable cloud buckets on Amazon S3, Google Cloud, Azure, DigitalOcean, and Alibaba, with no login and no break-in required.” reads a report published by MysteriumVPN.

“685,047 credential and key files (.env files, private keys, password vault databases) are sitting in open buckets, giving would-be attackers direct access to live systems rather than merely exposing data from those systems.”

An .env file is where an application keeps its passwords, API keys, and authentication tokens. A .kdbx file is literally a password manager’s vault. These aren’t interesting artifacts. They’re master keys.

Database exports add another layer. The research found 985,645 .sql files and 733,040 .bak files sitting in publicly accessible buckets. A live database is protected by the application wrapped around it, with authentication, rate limiting, and query controls in place.

“A live database is guarded by the application wrapped around it.” continues the report. “Meanwhile, a database dump sitting in an open bucket just like this is the same data with all the guards removed, downloadable in one click, and analyzable forever.”

Customer names, addresses, order histories, support tickets, and plain-text passwords are all fair game for anyone who finds one.

The filename counts alone signal the scope of the problem. Researchers found 764,015 files containing the word “secret,” 250,563 containing “salary,” 195,475 containing “kyc,” and 124,967 containing “credentials.” Files named “password,” “passport,” “invoice,” and “backup” each exceeded one million, the ceiling at which the query stops counting. People don’t label files “kyc” or “confidential” by accident.

The real danger isn’t any single file. It’s how they connect. An attacker scanning open buckets finds an .env file. Inside are database credentials. Those credentials open a .sql export in the same bucket, which contains customer email addresses and password hashes. The hashes get cracked offline at leisure. Many people reuse passwords, so a fraction of those accounts unlock email inboxes. Those inboxes contain invoice-approval workflows, executive contacts, and password-reset links to everything else. One open bucket becomes a complete attack kit, pre-assembled, requiring no technical skill beyond knowing where to look.

More than two-thirds of the exposed storage sits on AWS. That’s not because S3 is less secure than the alternatives. It’s because it’s the default choice for most of the world, and defaults are where mistakes scale.

“More than two-thirds of exposed storage sits on AWS. Not because S3 is less secure than the alternatives, but because it is the default choice for most of the world, and defaults are where mistakes scale.” continues the report. “The lesson here is not “avoid Amazon.” It’s that exposure follows wherever the crowd goes. When one platform hosts the majority of the world’s cloud workloads, it also hosts the majority of the world’s misconfigured ones.”

There’s no exploit in this story. No zero-day, no malware, no intrusion. Every one of those 19.6 billion files is exposed because of a setting. A bucket flipped to “list” instead of “private.” A backup script pointed at the wrong path. A developer who put an .env file somewhere it didn’t belong. The structural problem is that centralization turns a single wrong toggle into a complete data spill. A credential file only unlocks the kingdom when the kingdom is centralized behind it.

For anyone running cloud storage, the fix is straightforward even if the execution requires discipline: default everything to private, never store secrets in object storage, encrypt every backup, and scan your own footprint the way an attacker would. If you can list a bucket without logging in, so can everyone else. For everyone else, the data sitting in those buckets was handed to companies you’ve dealt with, and you can’t change their settings. What you can do is use unique passwords everywhere, turn on multi-factor authentication on anything that touches money or email, and share less with fewer services. Data that was never collected can’t leak. That’s not a security philosophy. It’s arithmetic.

“The open buckets in this report will keep accumulating faster than they are cleaned up. The filename counts alone prove it.” concludes the report. “The organizations responsible for these buckets should be treating misconfiguration as a structural failure, not an occasional mistake to patch. And if they will not, their users should be shrinking the footprint those organizations can expose on their behalf.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Amazon S3)