Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeEvaluation & SafetyAI Gateway Hijack
Evaluation & Safety

Attackers hijacked an AI gateway with a path to Amazon Bedrock

A LiteLLM proxy with Bedrock credentials, SSH open to the internet, and a brute-force attack later, the routing layer under the agent stack became the attack surface.

AJ
Andrew Jamerson
Founding Editor
Jul 11, 2026 · 3 min read
Illustration: the choke point becomes the target. // GaaS News
TL;DR
  • Darktrace disclosed the compromise of a customer's EC2 instance running a LiteLLM proxy AI gateway with IAM access to Amazon Bedrock.
  • Attackers brute-forced SSH left open to the internet, deployed XMRig cryptomining malware, and attempted to enumerate and invoke Bedrock foundation models and create new IAM users.
  • No CVE involved: this was exposure and misconfiguration, on the layer that concentrates credentials, model access, and policy.

Security firm Darktrace has disclosed an incident that should reorder some threat models: attackers compromised a customer's AWS EC2 instance running a LiteLLM proxy, the AI gateway pattern that routes an organization's model traffic, and used their foothold to reach toward Amazon Bedrock, the company wrote.

Anatomy of a boring, effective attack

Nothing here required novel tradecraft. The instance, named LiteLLM-Proxy, had SSH port 22 open to the internet. A single external IP brute-forced its way in, delivered XMRig cryptomining malware in a ZIP, and began beaconing to a known mining pool; the mining activity was first observed June 12, per SiliconANGLE. More interesting were the failed InvokeModel and ListFoundationModels API calls and attempts to create new IAM users, though Darktrace says the evidence linking the mining and the Bedrock probing is not conclusive. There is no CVE; this was misconfiguration meeting exposure.

The gateway is the crown jewels now

"AI gateways concentrate credentials, cloud permissions, and model access into a single choke point," BeyondTrust CISO Sean Malone told CSO Online. That is the whole story in one sentence. Nearly every multi-model agent deployment routes through something like LiteLLM, and that box holds cloud credentials, model invocation rights, and visibility into prompts and logs all at once. The industry is responding by selling governance for that layer, like the MCP gateway Citrix just bolted onto NetScaler, but a governed choke point is still a choke point. After a spring in which an agent platform made CISA's must-patch list, the lesson repeats: the plumbing under the agents is being attacked before the agents themselves.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.