Artificial IntelligenceCybersecurityNewswireTechnology

ShutterGap: 3.7M AWS Resources Exposed Outside CSPM/CNAPP View

Originally published on: July 30, 2026
▼ Summary

– Each year, 3,731,699 short-lived cloud resources with highly sensitive information are publicly exposed on AWS, often lasting minutes or hours.
– Traditional CSPM and CNAPP platforms fail to detect these exposures because they are too brief, yet attackers can discover and copy them quickly.
– The reactive “find and remediate later” model is ineffective as AI-driven attack automation narrows the window between misconfiguration and exploitation.
– Organizations can prevent these exposures by using resource-specific AWS Service Control Policies that block dangerous public-sharing configurations before creation.
– Under the shared responsibility model, AWS customers are responsible for ensuring public resources contain no sensitive data, but misconfigurations still expose private information.

New research from Aryon reveals a staggering security blind spot: 3,731,699 short-lived AWS resources containing highly sensitive data are publicly exposed each year. This vulnerability affects any organization using AWS services that allow public sharing, and the exposures often last just minutes or hours,too brief for periodic scanning by CSPM and CNAPP platforms to catch, yet long enough for attackers to discover and exfiltrate the data.

The findings expose a critical flaw in the reactive cloud security model. Some cloud misconfigurations can be exploited before detection and remediation are possible. As AI-driven attack automation accelerates exploitation, this gap is becoming increasingly dangerous. The research also shows how organizations can prevent these exposures using resource-specific AWS Service Control Policies that block dangerous public-sharing configurations before they are created.

Why it matters. The attack is trivially easy to execute and can hit any organization. Today’s cloud security stack offers little protection against this type of threat. This is not an AWS vulnerability,public-sharing settings are controlled by customers under the shared responsibility model. But the traditional “find and remediate later” approach offers scant defense when exposure can be exploited faster than it can be detected. With AI-powered attack automation growing more capable and adaptable, the window between misconfiguration and exploitation will only shrink further.

Who is at risk. Any organization using AWS services that support public sharing. Large, multi-account cloud environments face greater exposure because they generate more resources, rely heavily on automation, and distribute cloud administration across many teams and business units.

What readers learn. How attackers discover and copy short-lived publicly shared AWS resources, why traditional CSPM and CNAPP tools miss these exposures, what sensitive data may be exposed, and how to prevent the risk using resource-specific AWS Service Control Policies.

Service provider response. AWS documentation makes clear that customers are responsible for ensuring publicly shared resources contain no sensitive data: “Make sure when sharing a snapshot as public that none of your private information is included in the public snapshot.” Yet Aryon’s research identified a large volume of short-lived public exposures caused by customer misconfigurations that, in sample tests, contained private information.

(Source: Help Net Security)

Topics

cloud security 95% short-lived exposures 92% cspm/cnapp limitations 90% ai-driven attacks 88% aws service control policies 87% public sharing risks 86% shared responsibility model 85% multi-account environments 82% Data Privacy 80% attack automation 79%