logo

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say

ID: 8f3e486d-de97-5e7b-bced-77d8b5894622

STIX ID: report--8f3e486d-de97-5e7b-bced-77d8b5894622

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A rapid AI-assisted intrusion into an AWS environment began with valid test credentials exposed in a public S3 bucket, and within ten minutes attackers used LLM-generated code to inject malicious Lambda code, escalate to administrative privileges, compromise 19 AWS identities, exfiltrate secrets, logs, Lambda source, and S3 data, and invoke multiple Amazon Bedrock models (LLMjacking) and GPU resources—highlighting risks from exposed credentials, over-privileged IAM permissions, and misuse of cloud-hosted LLMs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.