On Thursday, Aug. 23 -- The research team at Truffle Security Co. spent four years watching a problem get worse.

768 active AWS access keys with full control over corporate Amazon cloud accounts are sitting in public repositories right now, still working, still dangerous. The researchers found them by extracting and verifying 64,024 unique AWS credential pairs from across the internet. The number that should unnerve every chief information security officer is the median age of a live leaked key: 1,831 days, or roughly five years, suggesting that many of the companies affected don't know they have a problem.

The biggest single source isn't some obscure software repository. It's Hugging Face.

The AI model-sharing platform, which has beco...