AWS plugs leaky S3 buckets with CloudKnox integration
Partnership aims to address S3's pervasive human error problem


AWS has launched a new tool to help customers avoid data leaks within its simple storage service.
The AWS IAM Access Analyzer is a new function that analyses resource policies to help administrators and security teams protect their resources from unintended access.
It comes from an integration with CloudKnox, a company that specialises in hybrid cloud access management.
It's a strategic integration designed to protect organisations against unintended access to critical resources and mitigate the risks they face, such as overprivileged identities, according to Balaji Parimi, CEO of CloudKnox.
"Exposed or misconfigured infrastructure resources can lead to a breach or a data leak," he said. "Combining AWS IAM Access Analyzer's automated policy monitoring and analysis with CloudKnox's identity privilege management capabilities will make it easier for CloudKnox customers to gain visibility into and control over the proliferation of resources across AWS environments."
Amazon S3 is one of the most popular cloud storage services, but because of human error, it's historically been a bit of a security liability, according to Sean Roberts, GM of Cloud Business Unit at hybrid managed services provider Ensono.
"Over the last few years, hundreds of well-known organisations have suffered data breaches as a direct result of an incorrect S3 configuration -- where buckets have been set to public when they should have been private," he said.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"When sensitive data is unintentionally exposed online, it can damage an organisation's reputation and lead to serious financial implications. In real terms, this sensitive data is often usernames and passwords, compromising not only the business but its customers too."
In July, more than 17,000 domains were said to have been compromised in an attack launched by the prolific hacking group Magecart that preyed on leaky S3 buckets. Looking back over the last two years, a number of companies and organisations such as NASA, Dow Jones and even Facebook have been seen breaches from this S3 Buckets.
With the Access Analyzer, there's a new option in the console for IAM (Identity and Access Management). The toll alerts customers when a bucket is configured to allow public access or access to other AWS accounts. There is also a single-click option that will block public access.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
AWS layoffs: Why Amazon is cutting staff from its most profitable division
News AWS layoffs follow a period of slowing growth and decreasing market share for the cloud division
By Ross Kelly Published
-
AWS invests $6 billion in Malaysia cloud expansion as SEA competition heats up
News While AWS continues expanding its footprint in Southeast Asia, Chinese competitors are edging into this expanding market
By Ross Kelly Published
-
Hyperscaler earnings 'highlight new era of maturity' in global cloud market
News Sluggish earnings for Azure, Google Cloud, and AWS could point to a more moderate cloud market in the year ahead
By Ross Kelly Published
-
AWS splashes $35 billion to expand data centres in Virginia
News The massive figure is close to the total sum AWS has previously invested in the state since 2006
By Zach Marzouk Published
-
AWS launches Australia's first local zone for low-latency workloads and data residency
News The company is aiming to help customers who need infrastructure closer to their data sources or end-users
By Zach Marzouk Published
-
AWS follows Google in opening a cloud region in Thailand
News The region is one of 24 other global regions announced by the company
By Zach Marzouk Published
-
NetApp teams up with VMware to help businesses migrate enterprise workloads
News Amazon FSx for NetApp ONTAP is the first native AWS cloud storage to be certified as a supplemental datastore for VMware cloud on AWS
By Daniel Todd Published
-
AWS announces new region in United Arab Emirates
News The country is already home to AWS’ Middle East (Bahrain) region, launched in 2019
By Praharsha Anand Published