Infosys leaked FullAdminAccess AWS keys on PyPi for over a year. The key was still active and still had access to what appeared to be patient data. This is definitely something that should be reported to them. It’s not a good idea to assign these to long-lived credentials issued to developers.
Table of contents
Infosys has a lot to say about securityThe LeakThe KeysThe BucketThe PermissionsThe TakedownThe CleanupThe ConclusionSort: