// Alert

AWS threat report

// AWSHIGH

An AWS customer's LiteLLM-Proxy EC2 instance, functioning as an AI gateway to Amazon Bedrock, was compromised on June 12, 2026 via brute-force attacks against an exposed SSH port (0.0.0.0/0). Attackers deployed XMRig cryptomining malware and established persistence through the instance's privileged IAM role. Suspicious IAM activity detected a day later suggested possible credential misuse targeting Amazon Bedrock services. Darktrace's managed threat detection alerted the customer.

// Get alerts for AWS