logo

AI-assisted cloud intrusion achieves admin access in 8 minutes

ID: b521aa9a-403c-5f05-a7d4-e10a4ccb1464

STIX ID: report--b521aa9a-403c-5f05-a7d4-e10a4ccb1464

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-05-01

...
...

On 2025-11-28 Sysdig TRT observed a rapid offensive cloud operation against an AWS environment where attackers recovered credentials from public S3 buckets, injected malicious Lambda code to create admin access within minutes, moved laterally across 19 AWS principals, abused Amazon Bedrock (LLMjacking) and provisioned GPU instances for model training; the report provides a full attack timeline, IoCs, detection rules, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.