A new type of long-lived key on AWS: Bedrock API keys
ID: a2567b01-bf9c-590a-bc16-f7629ef71fb0
STIX ID: report--a2567b01-bf9c-590a-bc16-f7629ef71fb0
Feed Name: Wiz Blog
Threat Score
This report examines AWS Bedrock API keys (long-term service-specific credentials and client-generated short-term bearer tokens), documents that long-term keys have been found leaked in public GitHub repositories, explains how the keys are formatted and detected (secret scanning and CloudTrail events), and recommends mitigations including preventing IAM Users, denying the bedrock:CallWithBearerToken privilege, and relying on existing authentication flows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
