logo

A Single Cloud Compromise Can Feed an Army of AI Sex Bots

ID: df08e4d1-a729-594c-b7fb-76fd94cf2ed2

STIX ID: report--df08e4d1-a729-594c-b7fb-76fd94cf2ed2

Feed Name: Krebs on Security

Threat Score
68/100

Date Published: 2024-10-03

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Permiso Security researchers leaked a test AWS key and observed attackers quickly using the stolen Bedrock access to power subscription AI sex-chat services that employ jailbreak prompts to bypass model restrictions; their two-day honeypot recorded ~75,000 model invocations and generated a $3,500 bill, with several prompts indicating illegal sexual content including child exploitation. The report highlights widespread risks from exposed cloud credentials, gaps in default logging of LLM prompts/outputs, and ongoing attacker techniques to detect and avoid accounts with logging enabled, while vendors like AWS and Anthropic describe mitigations and policy work.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.