HomeSecurityHalf of Organizations Have Unmanaged Cloud Credentials

Half of organizations have unmanaged cloud credentials

Nearly half (46%) of organizations have unmanaged accounts with long-standing credentials in cloud services, putting them at high risk of data breaches, according to Datadog's State of Cloud Security 2024 report

See also: Serious flaws in E2EE cloud storage platforms

Cloud credentials

Long-lived credentials are cloud authentication tokens or keys that remain valid for a long period of time. They are a major cause of cloud breaches, with attackers having a large window to successfully compromise these credentials. They can also allow attackers to gain permanent access, with the same access and privileges as the original owner.

Datadog's new report found that long-lived credentials are widespread across all major cloud service providers, including Google Cloud, Amazon Web Services (AWS) , and Microsoft Entra.

Many of these credentials are also old and even unused, with 60% of Google Cloud service accounts , 60% of AWS Identity and Access Management (IAM) users, and 46% of Microsoft Entra ID applications having an access key that is more than a year old.

See also: Three Call of Duty games will be added to Xbox Cloud Gaming

Half of organizations have unmanaged cloud credentials

Commenting on the findings, Andrew Krug, Head of Security Advocacy at Datadog, warned that it is unrealistic for organizations to expect that long-lived credentials can be managed securely , and companies need a strategy to mitigate these risks.

The report also found that 18% of AWS EC2 instances and 33% of Google Cloud virtual machines have sensitive permissions for a project. These permissions put organizations at higher risk of breaches because they allow any attacker who compromises the workload to steal the relevant credentials and gain access to the cloud environment.

See also: Google accuses Microsoft of antitrust practices

Long-lived cloud credentials are authentication details that remain valid for a long period of time, enabling continuous access to cloud services without frequent refreshes. While they provide seamless access and ease of use for developers and applications, they also present significant security risks. Because these credentials are valid for a longer period of time, they become attractive targets for malicious actors looking for opportunities to exploit. It is critical for organizations to enforce strict access management policies and diligently monitor usage patterns to prevent unauthorized access. Employing strategies such as credential rotation, implementing principles of least privilege, and using tools such as identity and access management (IAM) solutions can significantly mitigate the risks associated with long-lived cloud credentials.

Source: infosecurity-magazine

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS