Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cloud storage buckets leaking secret data despite security improvements

By CIO Dive by By CIO Dive
June 24, 2025
Home Enterprise IT
Share on FacebookShare on Twitter


This audio is auto-generated. Please let us know if you have feedback.

Dive Brief:

  • Nearly one in 10 publicly accessible cloud-storage buckets contained sensitive data, with virtually all of that data considered confidential or restricted, according to a new report from Tenable based on scans conducted between October 2024 and March 2025.
  • On the other hand, more than eight in 10 organizations using Amazon Web Services have enabled an important identity-checking service, according to the report, published last week.
  • The number of organizations with triple-threat cloud instances — “publicly exposed, critically vulnerable and highly privileged” — declined from 38% between January and June 2024 to 29% between October 2024 and March 2025.

Dive Insight:

Tenable’s report highlights serious risks facing cloud storage users, as well as some promising security trends.

Amazon Web Services hosted more sensitive data (16.7% of its buckets) than Google Cloud Platform (6.5%) and Microsoft Azure (3.2%), the report showed. According to Tenable, that could be because “users are confident in the AWS security measures they have put in place” or because of AWS’s longevity as a cloud provider.

Cloud buckets’ configuration settings may be leaking secret data, Tenable said. Researchers found sensitive information in 54% of AWS users’ Elastic Container Service task definitions and 52% of Google CloudRun environment variables. In addition, Tenable found that more than a quarter of AWS users were storing sensitive information in their user data. 

Overall, 3.5% of AWS EC2 instances contained secrets in user data. Tenable called this “particularly concerning,” noting that attackers who access these secrets “can use them to trigger a cascade of exploitative activity.”

Tenable’s report also dove into “toxic cloud trilogies” — instances that are publicly exposed to the internet, contain critical vulnerabilities and contain highly privileged data. Researchers saw promising declines in multiple metrics, including the number of organizations with at least one such bucket on AWS or GCP (down from 38% to 29%), the number of organizations with five of them (down from 27% to 13%) and the number of organizations with 10 of them (down from 15% to 7%). Even so, Tenable said, “these findings show that toxic cloud trilogies continue to pose an urgent problem for organizations.”



Source link

By CIO Dive

By CIO Dive

Next Post
Chunghwa Telecom Receives Frost & Sullivan’s 2025 Taiwan Competitive Strategy Leadership Award for Excellence in Data Center Services

Chunghwa Telecom Receives Frost & Sullivan's 2025 Taiwan Competitive Strategy Leadership Award for Excellence in Data Center Services

Recommended.

Tom Lee’s Granny Shots ETF rakes in  billion in AUM just 9 months after inception

Tom Lee’s Granny Shots ETF rakes in $2 billion in AUM just 9 months after inception

July 29, 2025
GlocalMe Delivers Award-Winning Innovative Real-World Connectivity Solutions at IFA 2025

GlocalMe Delivers Award-Winning Innovative Real-World Connectivity Solutions at IFA 2025

September 7, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio