Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

AI Gateways Offer Attackers the Keys to the Kingdom

AI gateways are emerging as a new attack surface, as demonstrated by a cryptomining incident where a threat actor compromised an EC2 server hosting an AI gateway connected to Amazon Bedrock. This access could be exploited to manipulate connected AI models, exfiltrate data, or pivot deeper into cloud infrastructure, leveraging the gateway's privileged position at the intersection of identity, cloud services, and proprietary data.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Cybersecurity Operations European Organizations Have a Collaboration Security Confidence Gap European Organizations Have a Collaboration Security Confidence Gap by Jai Vijayan Jul 9, 2026 4 Min Read Сloud Security Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours by Alexander Culafi Jul 8, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Application Security Identity & Access Management Security Threat Intelligence News AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data. Jai Vijayan , Contributing Writer July 9, 2026 4 Min Read Source: Daniel Pinkpank via Shutterstock As a growing number of organizations deploy AI gateways to manage access to foundation models, all signs point to them becoming yet another surface for security defenders to protect. Researchers at Darktrace recently investigated an incident where a threat actor gained access to an EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker used the access for cryptomining but could just as easily have abused the AI gateway to access connected models and data, manipulate AI workflows, or pivot deeper into the unnamed organization's cloud environment to make it a much more serious compromise. The Tip of the Iceberg? "This incident should be viewed as the tip of the iceberg," advises Nathaniel Jones, vice president, security and AI strategy and field CISO at Darktrace. "AI gateways increasingly sit at the intersection of identity, cloud infrastructure, proprietary data, and access to multiple foundation models." Related: Mexico's New Cyber Plan Faces Its First Real Test As organizations centralize AI access through gateways, expect them to become attractive aggregation points for attackers. "While cryptomining may have been the payload in this case, the initial access technique could be reused by more sophisticated actors with very different objectives," Jones says, ticking off credential theft, data access, and cloud persistence as possibilities. For organizations racing to AI-enable applications and workflows, the incident is another reminder of how every new AI component in the environment can expand the attack surface . The risks include those tied to AI models themselves, such as model poisoning and prompt injection ; vulnerabilities and weakness in AI infrastructure such as Model Context Protocol (MCP) servers and AI gateways; insecure use of coding agents, and agentic AI more generally. Darktrace uncovered the incident involving the AI gateway when investigating activity consistent with cryptomining from an externally exposed AWS EC2 instance connected to Amazon Bedrock , a managed AWS service that provides access to AI models from multiple providers via APIs. Organizations use the service to build generative AI apps without having to manage underlying infrastructure. Though Darktrace was unable to confirm definitively, the attacker appeared to have gained initial access to the EC2 server via brute-force login attempts. The threat actor then downloaded the XMRig cryptominer software on the compromised system and a few minutes later connected to a cryptomining pool. Darktrace's investigation showed the compromised system likely functioned as an AI gateway with access to a much broader range of enterprise assets and data. Related: 'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows 'Think of Them as a Mini Supply Chain' "Depending on the permissions granted to the gateway, an attacker might have accessed sensitive prompts and model outputs, stolen API keys, secrets, or cloud credentials, or queried proprietary knowledge bases connected through retrieval-augmented generation (RAG)," Jones says. They could have also leveraged "attached [identity and access management, or IAM] roles to pivot into broader AWS resources, generated significant financial impact through abuse of AI inference services, or established persistence within the cloud environment." The key takeaway here is not what actually happened, but what could have easily transpired if the attacker decided to leverage the AI gateway. "While cryptomining is noisy and relatively easy to detect, credential theft and cloud persistence would have been far more concerning outcomes." AI gateways, Jones says, are attractive targets for threat actors because they often aggregate capabilities that traditionally existed in separate systems. For example, they typically have centralized access to multiple AI providers, high-value API credentials, enterprise identity integration access to internal documents and enterprise knowledge, and connectivity to development tools, databases, and software-as-a-service (SaaS) platforms. "Compromising one gateway may provide access to multiple downstream systems without needing to compromise each individually. Think of them as a mini supply chain." Related: Chinese LLMs Broaden the Gap Between Attackers & Defenders When deploying AI gateways, organizations should make sure not to grant overly broad IAM permissions or expose management interfaces to the Internet, Jones advises. He also advocates use of short-lived API keys instead of long-lived credentials, segmentation between AI infrastructure and production environments, monitoring of AI-specific administrative actions and prompt activity, and treating AI gateways as privileged cloud assets. "We're already seeing observations across our customer base that reinforce why additional controls need to be in place," Jones says. "The most common risks are not necessarily compromised models or advanced AI attacks. They are employees and business functions exposing sensitive information through entirely legitimate-looking interactions." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. See more from Jai Vijayan Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars Editor's Choice Cybersecurity Operations Why Identity Security Is Your Cyber Career Entry Point Why Identity Security Is Your Cyber Career Entry Point by Kristina Beek Jun 30, 2026 Cyberattacks & Data Breaches EdTech Attackers Shift From Schools to Their Software Suppliers EdTech Attackers Shift From Schools to Their Software Suppliers by Arielle Waldman Jun 25, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. Subscribe Aug 1-6 | Mandalay Bay, Las Vegas Use code: DARKRE

Share this article