The first confirmed LLM-agent cyberattack just happened — AI hacked a server, stole AWS creds, and exfiltrated a DB in under 1 hour

Reddit r/AI_Agents News

Summary

Sysdig researchers documented the first confirmed LLM-agent cyberattack where an AI agent autonomously hacked a server, stole AWS credentials, and exfiltrated a database in under an hour.

Sysdig's Threat Research Team documented what they believe is the first confirmed in-the-wild attack where an AI agent autonomously drove the entire post-exploitation chain — zero human input between steps. \> The attack chain: 1. Exploited a Marimo RCE vulnerability (CVE) 2. Harvested AWS credentials from the environment 3. Scanned internal infrastructure 4. Pivoted through an SSH bastion (in under 2 min) 5. Exfiltrated a full PostgreSQL database \> Total time from initial access to exfiltration: under 60 minutes. \> The age of autonomous AI-powered attacks has arrived. What does this mean for agent security best practices?
Original Article

Similar Articles

Terabytes of credentials leaked in massive supply-chain attack

Ars Technica

A massive supply-chain attack on the open-source AI tool LiteLLM exposed terabytes of credentials from thousands of organizations, including Microsoft, Amazon, and Cisco, during a 40-minute window in March. Security firms CloudSEK and Hudson Rock disclosed the breach, attributing it to the TeamPCP gang.