MediumNewsLLM-specific
Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access
- Published
- Record updated
Summary
Unit 42 describes validation patterns attackers use to test stolen AWS credentials for Amazon Bedrock access. It observed the KMON_NOC credential harvesting platform, which targets Datadog Cloud SIEM customers, and analyzed its public JavaScript bundle. The frontend first checks keys with STS GetCallerIdentity using SigV4 signing, then separately checks for Bedrock access and tracks keysWithBedrock in its dashboard.
Related items
- InfoHow to keep AI agents within their permissionsSame vendor · BleepingComputer
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSame vendor · Dark Reading
- InfoSpaceXAI backs Omarchy, the controversial Linux distro, with $1.5 million in computeSame vendor · The Verge (AI)
- MediumAWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemmaSame vendor · CSO Online
- InfoAWS takes aim at runaway AI agent behavior with Strands BoxSame vendor · CSO Online