LIVE · cybersecurity feed
Live wire
aihigh

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target

Researchers have identified threat actors leveraging agentic artificial intelligence to significantly speed up cloud compromises. What would typically take weeks of manual effort was accomplished in a mere 72 hours, demonstrating a new level of efficiency in cyberattacks.

zeroday.news · 24d ago

A threat actor utilized agentic artificial intelligence to compromise an Amazon Web Services (AWS) cloud environment within 72 hours, a task that would typically take weeks, according to a report by the security vendor Sygnia. The attack, aimed at extortion, leveraged familiar cloud infrastructure exploitation techniques but at an accelerated pace due to AI assistance.

The report, titled "Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed," detailed how the attacker exploited control gaps in secrets management, identity governance, deployment workflows, and cloud permissions. The initial entry point was an internet-facing application that exposed an access key to one of the AWS accounts.

Once inside, the threat actor employed AI-assisted or agentic workflows to simultaneously pursue four key objectives. These included searching for and stealing secrets and credentials across various layers of the AWS environment, such as plaintext secrets in S3 buckets, API keys from application databases, and sensitive information stored in AWS Secrets Manager and AWS Systems Manager Parameter Store.

Concurrently, the attacker focused on establishing persistence mechanisms. This involved creating new access keys and Identity and Access Management (IAM) users, setting up reverse shells on EC2 instances and ECS containers, and altering deployment files to maintain access and control.

Data exfiltration was another critical objective, with the attacker targeting data stored in Relational Database Service (RDS) databases. The final phase involved impact actions designed to demonstrate their capabilities to the victim organization.

These impact actions included denying access to S3 buckets, reducing ECS services or containers to zero capacity, implementing Access Control List (ACL) rules to block network access, and purging Simple Queue Service (SQS) queues.

Sygnia's report highlighted that the organization's existing gaps in visibility, monitoring, identity controls, and incident preparedness significantly aided the attacker's rapid progress.

Avi Dayan, VP of incident response at Sygnia, emphasized that the most striking aspect of the attack was the speed and volume of malicious activity executed in a compressed timeframe post-intrusion. He noted that the increasing accessibility of large language models and agentic AI lowers the barrier to entry for threat actors, enabling them to operate with unprecedented speed and scale, even for those with fewer resources or less sophistication.

To mitigate such threats, Sygnia recommended several containment measures for network defenders. These include restricting cloud management access through IP allowlisting, disabling remote access VPN connectivity until containment is complete, and limiting outbound internet connectivity for cloud resources to approved destinations. Additionally, applying firewall policies and network ACLs to block malicious infrastructure and unknown assets, enforcing IP restrictions on code repositories, routing all application traffic through web application firewalls (WAFs), and implementing network segmentation and isolation controls were advised.

aicloud securitythreat actorsautomation
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.