mimile
mimile.ai
Back to feed

Aryon Security Finds 3.7M Short-Lived AWS Resources Exposed Annually

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Aryon Security Finds 3.7M Short-Lived AWS Resources Exposed Annually

Research from Aryon Security has found that 3.7 million short-lived AWS cloud resources are publicly exposed each year, often containing sensitive data. These exposures typically last only minutes or hours, evading traditional CSPM and CNAPP tools. The findings highlight a growing risk as AI-driven attack automation accelerates.

Exposure Scope

Aryon Security’s research identified 3,731,699 short-lived AWS cloud resources publicly exposed annually. These resources contain highly sensitive information and are tied to any organization using AWS services that support public sharing. Large, multi-account environments face greater risk due to higher resource creation volumes, automation reliance, and distributed administration.

Security Tool Limitations

Exposures lasting minutes or hours are too brief for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy. The research demonstrates a fundamental limitation of the reactive “find and remediate later” model. AI-driven attack automation is expected to further shrink the time between misconfiguration and exploitation.

What's Next

Aryon Security recommends organizations use resource-specific AWS Service Control Policies to prevent exposures proactively. It remains unclear how widely such measures will be adopted across multi-account cloud environments.

1 source

Aryon Security Finds 3.7M Short-Lived AWS Resources Exposed Annually