AI-assisted cloud intrusion achieves admin access in 8 minutes
ID: b521aa9a-403c-5f05-a7d4-e10a4ccb1464
STIX ID: report--b521aa9a-403c-5f05-a7d4-e10a4ccb1464
Feed Name: Sysdig Blog
Threat Score
On 2025-11-28 Sysdig TRT observed a rapid offensive cloud operation against an AWS environment where attackers recovered credentials from public S3 buckets, injected malicious Lambda code to create admin access within minutes, moved laterally across 19 AWS principals, abused Amazon Bedrock (LLMjacking) and provisioned GPU instances for model training; the report provides a full attack timeline, IoCs, detection rules, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
