> and the bucket itself had no protection against outside access with a compromised key
Any advice on how to safeguard against this?
Any advice on how to safeguard against this?
If possible, use VPC endpoints and lock down the bucket to only allow access from them.