Aryon Security's research identifies a "ShutterGap" threat where an estimated 3.7 million short-lived AWS resources with sensitive data are publicly exposed each year. These exposures, often lasting only minutes or hours, evade detection by periodically scanning CSPM and CNAPP tools, creating a window for attackers to discover and exfiltrate data. The findings highlight a fundamental limitation in reactive security models for cloud environments.
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy them.  The findings expose a fundamental limitation of the reactive CSPM/CNAPP model: some cloud misconfigurations can be exploited … More → The post ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility appeared first on Help Net Security .