Aryon Security disclosed "ShutterGap," a cloud visibility gap that allows attackers to discover and copy briefly exposed public AWS resources before CSPM and CNAPP scans detect them. The issue stems from customer misconfigurations rather than an AWS flaw and affects public-sharing features for resources including Amazon RDS snapshots, Amazon DocumentDB snapshots, Amazon Machine Images (AMIs), and AWS Systems Manager documents. Aryon reported that many exposures are extremely short-lived: about 20% of public RDS snapshots were visible for less than two minutes, and 99% of deleted RDS and DocumentDB snapshots disappeared within 30 minutes of creation.
Researchers showed that once a public snapshot is copied into another AWS account, it can be analyzed later even after the owner revokes access, creating a durable data-exposure risk from fleeting mistakes. In a sample of 24 public RDS snapshots, Aryon found AWS account IDs, email addresses, potential secrets, private-key-related patterns, and signs of financial data; earlier research by Mitiga similarly found hundreds of exposed public RDS snapshots and identified databases containing PII, password hashes, tokens, and business data. The findings underscore that short-lived public sharing can still lead to lasting compromise, and the recommended mitigations include blocking public sharing where possible, enforcing encryption and least privilege, applying Service Control Policies, and monitoring public-sharing events with CloudTrail, AWS Config, and Trusted Advisor.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Aryon Security disclosed the "ShutterGap" cloud visibility gap, describing how briefly exposed public AWS resources can be discovered and copied before security scans detect them. The research said the issue stems from customer misconfigurations affecting resources such as RDS snapshots, DocumentDB snapshots, AMIs, and SSM documents.
In a study running from 2022-09-21 to 2022-10-20, Mitiga observed 2,783 publicly shared Amazon RDS snapshots across regions. After filtering likely intentional or test cases, it identified 650 interesting snapshots and found 171 MySQL databases that potentially contained sensitive information.
As part of the ShutterGap research, Aryon demonstrated that attackers can copy a public snapshot into another AWS account during a brief exposure window and analyze it later even after access is revoked. In a sample of 24 public RDS snapshots, the researchers found sensitive business data including AWS account IDs, email addresses, potential secrets, private-key-related patterns, and indicators of financial data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcearyon.security
Open sourceunit42.paloaltonetworks.com
Open sourcecrowdstrike.com
Open sourcemitiga.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.