A significant blind spot in cloud security known as "ShutterGap" allows millions of AWS resources to be briefly exposed and then disappear before traditional monitoring tools can detect them This article explores rds snapshots aws. . Researchers Ariel Litmanovich, Tom Tsabar, and Ido Dar discovered that Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools, which typically scan environments once every 24 hours, cannot effectively identify exposures that appear and disappear within minutes.
While monitoring public RDS snapshots in AWS’s us-east-1 region, the team observed a fluctuation of snapshot counts 12 times in just 90 minutes, with six creations and six deletions occurring during this short window.
This rapid turnover means attackers can cause significant damage almost immediately, as copying a snapshot to an external AWS account takes just seconds afterward. Every single snapshot included AWS account IDs, revealing numerous exposed secrets, private keys, email addresses, and even credit card numbers. Using AWS Service Control Policies (SCPs) as guardrails across each affected resource type can prevent such exposures entirely.
This research builds upon earlier findings by Mitiga regarding exposed RDS snapshots but diverges sharply on remediation strategy, arguing that detection-first approaches are insufficient for threats that materialize and disappear within seconds. By cutting through SOC investigation blind spots and containing threats earlier, ANY.RUN can help reduce response costs and minimize business disruptions.












