{"data":{"id":"9d269e0a-efaa-4649-98b4-b32219461ba7","title":"Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access","summary":"Unit 42 describes validation patterns attackers use to test stolen AWS credentials for Amazon Bedrock access. It observed the KMON_NOC credential harvesting platform, which targets Datadog Cloud SIEM customers, and analyzed its public JavaScript bundle. The frontend first checks keys with STS GetCallerIdentity using SigV4 signing, then separately checks for Bedrock access and tracks keysWithBedrock in its dashboard.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"\n    https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access/","publishedAt":"2026-10-06T00:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["Amazon Bedrock","AWS","AWS SES/SNS","AWS STS","KMON_NOC","Unit 42 token-jacking"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-06T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}