wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
297 stars 59 forks source link

[Contribution] AWS deletion policy issue #319

Open korniko98 opened 1 month ago

korniko98 commented 1 month ago

Summary (give a brief description of the issue)

"In early 2023, Apple spotted unusual activity around the data and contents associated with its terminated cloud accounts on AWS. By April 2023, Apple escalated concerns to AWS's security team, and asked the cloud giant to investigate whether the data and contents were deleted from roughly 2,200 of its AWS accounts that had been closed for more than 90 days. AWS customers expect their data to be permanently deleted 90 days after accounts are shut. An internal AWS investigation found that it had failed to remove almost 2,000 pieces of content or metadata linked to those Apple terminated accounts, according to the document."

References (provide links to blogposts, etc.)

https://www.businessinsider.com/apple-alerted-amazon-potential-cloud-security-risk-aws-2024-6 https://archive.is/FIbU4