Aryon Security Finds 3.7M Short-Lived AWS Resources Exposed Annually
This digest was compiled by AI from multiple sources — links to the originals are below.

Research from Aryon Security has found that 3.7 million short-lived AWS cloud resources are publicly exposed each year, often containing sensitive data. These exposures typically last only minutes or hours, evading traditional CSPM and CNAPP tools. The findings highlight a growing risk as AI-driven attack automation accelerates.
Exposure Scope
Aryon Security’s research identified 3,731,699 short-lived AWS cloud resources publicly exposed annually. These resources contain highly sensitive information and are tied to any organization using AWS services that support public sharing. Large, multi-account environments face greater risk due to higher resource creation volumes, automation reliance, and distributed administration.
Security Tool Limitations
Exposures lasting minutes or hours are too brief for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy. The research demonstrates a fundamental limitation of the reactive “find and remediate later” model. AI-driven attack automation is expected to further shrink the time between misconfiguration and exploitation.
What's Next
Aryon Security recommends organizations use resource-specific AWS Service Control Policies to prevent exposures proactively. It remains unclear how widely such measures will be adopted across multi-account cloud environments.
1 source
Aryon Security Finds 3.7M Short-Lived AWS Resources Exposed Annually



