
Wiz observed campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
Preparing localized stories and source details.
AWS guidance addresses authorization propagation, custom authentication, and guardrails for agent tool interactions, while Wiz reports attacks against AI infrastructure through RCE, prompt injection, and credential theft.
Analysis
AWS guidance addresses authorization propagation, custom authentication, and guardrails for agent tool interactions, while Wiz reports attacks against AI infrastructure through RCE, prompt injection, and credential theft.
Verified evidence
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
Wiz Research · tracked sourceIf you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the [...]
AWS Security Blog · tracked sourceMany teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it might return data the user shouldn’t see. [...]
AWS Security Blog · tracked sourceWhen deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore [...]
AWS Security Blog · tracked sourceRead deeper

Wiz observed campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.

AI agents now cross identity, tool, data, and infrastructure boundaries whenever they act on a user's behalf. AWS implementation guidance and attack activity observed by Wiz show why security controls must follow the complete path from user to model to tool.

An AI agent that accesses enterprise data should not act only through a shared service identity. AWS describes propagating user authorization context so an agent returns data according to the requester’s permissions.
Keep exploring

As AI and third-party software operate on developer machines, workstations can hold direct paths to source code, credentials, and cloud environments. Wiz is framing the developer endpoint as a security perimeter that needs dedicated attention.