Affected Technology
Amazon Bedrock incidents
Amazon Bedrock platform security
Bedrock Leaked Credentials Vulnerability
Evidence indicates that Bedrock is affected by a security issue.
From credentials to cloud admin in 8 minutes: AI supercharges AWS attack chain
An attack chain exploited exposed AWS credentials in public S3 buckets, leveraging Large Language Models (LLMs) to rapidly escalate privileges through a misconfigured Lambda function. This allowed threat actors to achieve full AWS administrative control and abuse GPU resources within an Amazon Bedrock environment in under eight minutes.
Amazon Bedrock Security Breach
An AI-accelerated attack successfully breached an AWS environment by exploiting exposed credentials in public S3 buckets. This led to rapid administrative privilege escalation via Lambda function code injection, lateral movement across 19 principals, data exfiltration, and LLMjacking within the Amazon Bedrock service for resource abuse.