// AWSHIGH
An AWS customer's LiteLLM-Proxy EC2 instance, functioning as an AI gateway to Amazon Bedrock, was compromised on June 12, 2026 via brute-force attacks against an exposed SSH port (0.0.0.0/0). Attackers deployed XMRig cryptomining malware and established persistence through the instance's privileged IAM role. Suspicious IAM activity detected a day later suggested possible credential misuse targeting Amazon Bedrock services. Darktrace's managed threat detection alerted the customer.
- Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to(opens in a new tab)
- Cybersecurity Newsletter Weekly - The 40 Biggest Cybersecurity S(opens in a new tab)
// Get alerts for AWS