
From credentials to cloud admin in 8 minutes: AI supercharges AWS attack chain
Threat actors tore through an Amazon Web Services environment in under eight minutes, chaining together credential theft, privilege escalation, lateral movement, and GPU resource abuse with the help of large language models, an attack so fast that defenders had virtually no time to react. According to new findings from Sysdig’s Threat Research Team, the intruders turned a single exposed credential in a public S3 bucket into full administrative control, demonstrating how AI‑assisted automation has collapsed the cloud attack lifecycle from hours to mere minutes. The operation, observed in November 2025, reportedly combined a cloud misconfiguration with large language models (LLMs) to compress...