Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
A prompt injection flaw in Amazon Kiro IDE v0.7.45 allowing attacker-controlled repository content to exfiltrate sensitive data via the powersRecommendationUrl setting and Kiro Powers, exploitable in both trusted and untrusted workspaces.
https://mindgard.ai/blog/amazon-kiro-data-exfiltration
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3❤1👍1
🔶 Extend your data perimeter to the AWS Management Console with Private Access
AWS Management Console Private Access is now GA, routing all console traffic (auth, static assets, service APIs) through AWS PrivateLink VPC endpoints with no internet path required. VPC endpoint policies and Sign-In RCPs enforce identity, resource, and network perimeter controls on interactive console sessions.
https://aws.amazon.com/ru/blogs/security/extend-your-data-perimeter-to-the-aws-management-console-with-private-access
#aws
AWS Management Console Private Access is now GA, routing all console traffic (auth, static assets, service APIs) through AWS PrivateLink VPC endpoints with no internet path required. VPC endpoint policies and Sign-In RCPs enforce identity, resource, and network perimeter controls on interactive console sessions.
https://aws.amazon.com/ru/blogs/security/extend-your-data-perimeter-to-the-aws-management-console-with-private-access
#aws
❤2👍1🔥1
🔶 Automate IAM Identity Center governance with continuous discovery and reporting
A walkthrough deploying two AWS CDK stacks for IAM Identity Center governance: a reporting stack (EventBridge, Step Functions, Lambda, DynamoDB, API Gateway, S3) for automated daily discovery and CSV export, and a remediation stack for real-time event-driven enforcement and SNS notifications on non-compliant application assignments.
https://aws.amazon.com/ru/blogs/security/automate-iam-identity-center-governance-with-continuous-discovery-and-reporting
#aws
A walkthrough deploying two AWS CDK stacks for IAM Identity Center governance: a reporting stack (EventBridge, Step Functions, Lambda, DynamoDB, API Gateway, S3) for automated daily discovery and CSV export, and a remediation stack for real-time event-driven enforcement and SNS notifications on non-compliant application assignments.
https://aws.amazon.com/ru/blogs/security/automate-iam-identity-center-governance-with-continuous-discovery-and-reporting
#aws
❤1👍1🔥1
🔶 A scenario to evaluate your Agentic SOC
A downloadable multi-source log dataset built around a 7-phase GitHub Actions cache poisoning → Kubernetes → AWS attack chain, used to benchmark agentic SOC harnesses.
https://unsecure.sh/blog/agentic-soc-scenario/
#aws
A downloadable multi-source log dataset built around a 7-phase GitHub Actions cache poisoning → Kubernetes → AWS attack chain, used to benchmark agentic SOC harnesses.
https://unsecure.sh/blog/agentic-soc-scenario/
#aws
❤1👍1🔥1
🔶 Incident response guide for AWS CloudTrail investigations
AWS's Security Incident Response Team (SIRT) walks through two real-world CloudTrail investigation scenarios, cross-account S3 data deletion with ransomware implications and cryptocurrency mining via stolen console credentials, teaching investigators how to read key log fields, recognize attacker patterns, and apply practical response checklists. You can also check out Part 2.
https://aws.amazon.com/ru/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1
#aws
AWS's Security Incident Response Team (SIRT) walks through two real-world CloudTrail investigation scenarios, cross-account S3 data deletion with ransomware implications and cryptocurrency mining via stolen console credentials, teaching investigators how to read key log fields, recognize attacker patterns, and apply practical response checklists. You can also check out Part 2.
https://aws.amazon.com/ru/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1
#aws
❤1👍1🔥1
🔶 Agentic SOC alert triage: 60% to 92% AI accuracy
Elastic's InfoSec team describes how enriching a three-agent SOC triage pipeline with per-rule investigation guides, user risk data, and 30 days of historical case verdicts lifted AI alert accuracy from 60% to 92%, enabling analysts to close most alerts with a single Slack button click.
https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents
#aws
Elastic's InfoSec team describes how enriching a three-agent SOC triage pipeline with per-rule investigation guides, user risk data, and 30 days of historical case verdicts lifted AI alert accuracy from 60% to 92%, enabling analysts to close most alerts with a single Slack button click.
https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents
#aws
❤2👍1🔥1
This AI threat update provides GTIG's findings on adversarial misuse of AI including Gemini and other non-Google tools.
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
Microsoft researchers discovered a high-volume phishing campaign that repurposed ASCII smuggling to split financial keywords like "funding" and evade email filters, generating over 2.3 million messages daily at its February 2026 peak.
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1🔥1👏1