Wiz found that S3-compatible object-storage offerings from Nebius, Crusoe, Vultr, Lambda Labs, Cloudflare R2, and DigitalOcean can differ substantially from Amazon S3 in public-bucket behavior, IAM semantics, access-key handling, encryption, logging, and API implementation. The assessment warns that application teams may mistake S3 API compatibility—including Cloudflare R2's S3-compatible interface—for equivalent security guarantees and least-privilege controls.
Across the providers reviewed, Wiz identified inconsistent protections against exposed credentials, limited granular key restrictions and data-plane logging in some services, and differences in anonymous bucket and object-listing behavior; DigitalOcean was noted as an exception where public-bucket object listing may be possible. The report also highlighted cross-provider risks from bucket namesquatting and reusable presigned URLs, urging organizations to validate each provider's authorization, public-access, audit, and credential-control behavior rather than relying on AWS S3 assumptions.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Wiz assessed S3-compatible object storage from Nebius, Crusoe, Vultr, Lambda Labs, Cloudflare R2, and DigitalOcean, finding that API compatibility with AWS S3 did not provide equivalent public-access controls, credential protections, IAM semantics, logging, or least-privilege capabilities. The analysis also identified cross-provider risks including bucket namesquatting and reusable presigned URLs, and documented provider-specific API behaviors that could produce unsafe assumptions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.