WorkThe story, in brief

Darktrace finds AI gateway with Amazon Bedrock access hijacked for cryptomining

An AI gateway to Amazon Bedrock was hijacked for cryptomining. Here's what it means for your cloud infrastructure security.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

As enterprises scale AI deployments on cloud platforms, exposed AI gateways are becoming high-value attack surfaces for threat actors. This real-world intrusion demonstrates a critical vulnerability in how companies manage access to foundation model APIs.

The key facts

5 to know
  1. Compromised system: Amazon EC2 instance running LiteLLM-Proxy (open-source software)

  2. Target: Amazon Bedrock AI gateway with direct API access

  3. Attack vector: Hijacking for cryptomining (likely indicating credential compromise or misconfiguration)

  4. Source: Darktrace Holdings Ltd. (U.K. cybersecurity firm)

  5. Implication: AI infrastructure security gaps create operational and financial risk for enterprises

Go to the source

SiliconAnglesiliconangle.com

Publisher excerpt: Researchers at U.K.-based cybersecurity company Darktrace Holdings Ltd. today detailed a cloud intrusion in which a compromised artificial intelligence gateway tied to Amazon Web Services Inc.’s Amazon Bedrock was hijacked to mine cryptocurrency. The compromised system was an Amazon Elastic Compute…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work