A Single Cloud Compromise Can Feed an Army of AI Sex Bots
ID: df08e4d1-a729-594c-b7fb-76fd94cf2ed2
STIX ID: report--df08e4d1-a729-594c-b7fb-76fd94cf2ed2
Feed Name: Krebs on Security
Permiso Security researchers leaked a test AWS key and observed attackers quickly using the stolen Bedrock access to power subscription AI sex-chat services that employ jailbreak prompts to bypass model restrictions; their two-day honeypot recorded ~75,000 model invocations and generated a $3,500 bill, with several prompts indicating illegal sexual content including child exploitation. The report highlights widespread risks from exposed cloud credentials, gaps in default logging of LLM prompts/outputs, and ongoing attacker techniques to detect and avoid accounts with logging enabled, while vendors like AWS and Anthropic describe mitigations and policy work.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
