First step on a confirmed breach.
An access key was leaked publicly on GitHub. CloudTrail shows
the key was used by an unknown IP 12 minutes ago. FIRST action:
A) Delete the entire AWS account.
B) Immediately deactivate (then delete) the leaked key, rotate all
potentially affected credentials, snapshot resources for forensics,
then notify the security team and start your incident comms.
C) Wait until tomorrow morning.
D) Push a blog post about the incident before containing it.Sign in to save your code and track progress across devices.