AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining

2026-07-09T20:51:41Z1387dafe809e9adee6f75218961670ea5ed6d1d2a03d1dce8f4505668e10888f
AI coding assistantsAI gateway compromiseAPTAmazon BedrockArmored LikhoBusySnake stealerGhostApprovalGitHub AI agentLiteLLMRoundcubeSSH exposureUNK_MassTractioncryptominingdata exfiltrationphishingprompt injectionsymlink vulnerability

What happened

Multiple high-risk incidents affecting AI tooling and enterprise mail/web infrastructure: a LiteLLM AI gateway tied to Amazon Bedrock was hijacked (exposed SSH activity) for cryptomining; Wiz disclosed GhostApproval symlink flaws in major AI coding assistants that can hide file targets, bypass approvals and enable system access; a prompt-injection campaign (GitLost) tricked GitHub’s AI agent into leaking private repository data; and threat actors (Armored Likho, UNK_MassTraction) are actively exploiting malware/stealer tooling and Roundcube flaws to target governments, energy, and academia.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
1387dafe809e9adee6f75218961670ea5ed6d1d2a03d1dce8f4505668e10888f
Enrichment time
2026-07-09T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.