The Amazon Spheres in Seattle. Some Amazon AWS API keys are potentially threatened by the SolarWinds supply chain hack. (Joe Mabel, CC BY-SA 4.0 https://creativecommons.org/licenses/by-sa/4.0, via Wikimedia Commons)

The SolarWinds Orion supply chain hack endangers Amazon Web Services and Microsoft Azure API keys and their corresponding accounts, a security blog post from identity and access security company Ermetic has warned, reminding readers that this game-changing incident risks not just organizations' on-premises systems but also their cloud-based infrastructure.

Additional experts similarly confirmed to SC Media that the SolarWinds threat poses a valid threat to cloud-based services, and recommended a series of counter responses, including rotating credential, instituting least privilege protocols, and deploying Orion on standalone accounts isolated from all other cloud-based resources.

Please register to continue.

Already registered? Log in.

Once you register, you'll receive:

  • News analysis

    The context and insight you need to stay abreast of the most important developments in cybersecurity. CISO and practitioner perspectives; strategy and tactics; solutions and innovation; policy and regulation.

  • Archives

    Unlimited access to nearly 20 years of SC Media industry analysis and news-you-can-use.

  • Daily Newswire

    SC Media’s essential morning briefing for cybersecurity professionals.

  • Learning Express

    One-click access to our extensive program of virtual events, with convenient calendar reminders and ability to earn CISSP credits.