AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
2026-07-09T20:51:41Z•1387dafe809e9adee6f75218961670ea5ed6d1d2a03d1dce8f4505668e10888f
AI coding assistantsAI gateway compromiseAPTAmazon BedrockArmored LikhoBusySnake stealerGhostApprovalGitHub AI agentLiteLLMRoundcubeSSH exposureUNK_MassTractioncryptominingdata exfiltrationphishingprompt injectionsymlink vulnerability
What happened
Multiple high-risk incidents affecting AI tooling and enterprise mail/web infrastructure: a LiteLLM AI gateway tied to Amazon Bedrock was hijacked (exposed SSH activity) for cryptomining; Wiz disclosed GhostApproval symlink flaws in major AI coding assistants that can hide file targets, bypass approvals and enable system access; a prompt-injection campaign (GitLost) tricked GitHub’s AI agent into leaking private repository data; and threat actors (Armored Likho, UNK_MassTraction) are actively exploiting malware/stealer tooling and Roundcube flaws to target governments, energy, and academia.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 1387dafe809e9adee6f75218961670ea5ed6d1d2a03d1dce8f4505668e10888f
- Enrichment time
- 2026-07-09T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.