Tuesday, 02 January 2024 12:17 GMT

Leaked AWS Keys Expose Bedrock Models To Llmjacking Arabian Post


(MENAFN- The Arabian Post) clearfix">Threat actors are exploiting leaked Amazon Web Services credentials to hijack costly generative AI models on Amazon Bedrock, turning compromised cloud identities into a route for unauthorised inference and potentially large charges against victim accounts.

FortiGuard Labs disclosed on September 3 that it had analysed an AWS account compromise involving a long-lived Identity and Access Management access key carrying AdministratorAccess permissions. The stolen credential was used to create a new IAM user, subscribe to foundation models through AWS Marketplace and invoke those models, generating inference costs for the victim.

The incident illustrates a technique known as LLMjacking, in which attackers abuse valid cloud credentials to consume hosted large language model services without paying for them. Rather than stealing model weights or training data, the objective is to make another organisation's account fund expensive model usage, which can be consumed directly or resold to third parties.

MENAFN05092026000152002308ID1111624410



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story