{
  "id": 2520651,
  "title": "AWS Security makes an inscrutable choice",
  "url": "https://urgent.news/2026/08/21/aws-security-makes-an-inscrutable-choice-2520651",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T23:42:41.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446"
  },
  "original_language": "en",
  "account": "Amazon Web Services (AWS) has decided not to deactivate leaked root AWS credentials, despite the potential for significant damage. This stance has been criticized, as deactivating these credentials could prevent unauthorized accessing of various AWS services. By quarantining the credentials, AWS aims to limit the potential harm caused by fraud-related activity leading to unauthorized charges, while minimizing the impact on existing resources. However, many argue that deactivating the credentials is the right decision, as it prevents bad actors from performing various actions such as sending spam via Amazon SNS, modifying EC2 instances, and disabling AWS backup capabilities.",
  "summary": "Quarantining leaked credentials is not good enough",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "AWS Security makes an inscrutable choice",
        "url": "https://urgent.news/2026/08/21/aws-security-makes-an-inscrutable-choice",
        "published": "2026-08-21T23:42:41.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}