Sysdig Threat Research Team has
uncovered a chilling demonstration of how AI is supercharging cyber threats: an attacker gained full administrative access to an AWS cloud environment in just 8 minutes after stealing credentials from public S3 buckets. Using large language models (LLMs) to automate reconnaissance, generate malicious code (complete with Serbian comments and hallucinations like fake GitHub repos), and execute rapid privilege escalation via Lambda function injection, the intruder compromised 19 AWS principals, abused Amazon Bedrock for LLMjacking, and even launched expensive GPU instances for potential AI compute theft. This November 2025 incident highlights the alarming speed of AI-assisted attacks, underscoring the urgent need for strict least-privilege IAM policies, proper S3 security, Bedrock logging, and real-time cloud monitoring to defend against such automated, high-velocity intrusions.