[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmZVf0NOVA3k7hbzCVOwKBiqzxQjPjAbn7wkSBhqian8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"38163e0e-9d8e-49c7-8d4d-acdbc6298f4a","exposed-ssh-port-on-ai-gateway-leads-to-cryptomining-compromise","0f50de7d-786c-4b76-a57f-c4b7dd8a6c38","Exposed SSH Port on AI Gateway Leads to Cryptomining Compromise","An AI gateway (LiteLLM) connected to Amazon Bedrock was hijacked for Monero cryptomining after an SSH port was left exposed to the internet, allowing attackers to deploy XMRig malware. The root issue is a misconfigured, internet-facing service with insufficient access restrictions on a privileged component that had direct cloud infrastructure access. This matters because AI gateways often carry elevated permissions to cloud services like Bedrock, making them high-value targets — a single compromise can cascade into broader cloud account abuse, cost explosion, and data exposure. Organizations are rapidly deploying AI infrastructure without applying the same hardening rigor used for traditional systems, creating a growing and underappreciated attack surface.","**Immediate actions:**\n- Disable or firewall all non-essential ports (including SSH) on internet-facing AI gateway instances immediately.\n- Audit existing cloud permissions granted to AI gateways and apply least-privilege IAM policies to limit blast radius.\n\n**Long-term improvements:**\n- Replace direct SSH access with a bastion host or VPN-based access model so management interfaces are never publicly exposed.\n- Enforce Infrastructure-as-Code (IaC) security scanning to catch exposed ports and overly permissive security groups before deployment.\n- Treat AI gateway infrastructure with the same hardening standards as privileged cloud management systems.\n\n**Detection measures:**\n- Deploy anomaly-based monitoring on cloud egress traffic to flag unexpected outbound connections to mining pools or unknown IPs.\n- Implement host-based intrusion detection (e.g., Falco, Wazuh) on AI gateway instances to alert on suspicious process execution like XMRig.\n- Set cloud cost and API usage alerts to detect abnormal Bedrock invocation spikes that may indicate compromise.",[12,13,14,15,16,17,18,19,20],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 SI-3: Malicious Code Protection","AWS Well-Architected Framework: Security Pillar — Infrastructure Protection","MITRE ATT&CK T1496: Resource Hijacking (Cryptomining)","published","2026-07-09T18:20:36.690049+00:00","2026-07-09T18:20:36.582+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fhackread.com\u002Fai-gateway-amazon-bedrock-hijacked-cryptomining\u002F","ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining-d32997","AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]