Skip to content

Topic

Cloud Credential Theft

Theft of cloud API keys, tokens, or IAM credentials from compromised hosts, dev tools, or services to gain unauthorized access to cloud resources.

Current stories

security3 publishers

A hand-debugged Python toolkit turned marimo CVE-2026-39987 into bastion SSH in eight seconds

Sysdig's threat research team watched one operator work a marimo notebook host for nine hours with hand-written scripts, and the eight-second jump to a bastion host at the end ran on tooling already staged on disk.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 60%
Investor
Investor 7%

Reality

Evidence68
Adoption66
Hype gap+8
Incentives72
Confidence70
security3 publishers

Mass scanners are pulling AWS keys and Terraform state from Vite dev servers exposed with --host

F5 Labs logged more than 800 attacks and about 32,000 raw events against its honeypots in a month, using an April bypass of Vite's server.fs.deny to read .env files, cloud credentials and terraform.tfstate.

Perspective Coverage

3 publishers
Builder
Builder 42%
Operator
Operator 51%
Investor
Investor 7%

Reality

Evidence62
Adoption45
Hype gap+20
Incentives55
Confidence66