惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
T
The Blog of Author Tim Ferriss
H
Help Net Security
博客园 - 叶小钗
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
DataBreaches.Net
博客园 - 聂微东
A
About on SuperTechFans
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
G
Google Developers Blog
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
B
Blog
Engineering at Meta
Engineering at Meta
V
V2EX
Hugging Face - Blog
Hugging Face - Blog

Enterprise – Silicon Republic

EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
Hacker used commercial AI to breach 600 firewalls: AWS
Suhasini Srinivasaragavan · 2026-02-23 · via Enterprise – Silicon Republic

AWS describes the campaign as an ‘AI-powered assembly line for cybercrime’.

Commercial AI services are lowering the technical barrier needed to commit cybercrimes, and Amazon has warned that this trend will continue.

Amazon Web Services (AWS) said it recently observed what it described as a Russian-speaking, financially motivated threat actor leveraging multiple commercial generative AI (GenAI) services to compromise more than 600 FortiGate devices across more than 55 countries between 11 January and 18 February.

FortiGate is a newer generation firewall that provides advanced network protection when compared to more traditional ones.

AWS described the hacker as an “unsophisticated” individual or small group armed with AI tools that helped them achieve an operational scale to carry out the attacks, something that would have previously required a significantly larger and more skilled team.

The campaign stuck out to AWS because of the hacker group’s use of multiple commercial GenAI services. AWS described the campaign as an “AI-powered assembly line for cybercrime, helping less skilled workers produce at scale”, in a blog authored by CJ Moses, who leads security engineering and operations at Amazon.

The threat actor compromised globally dispersed FortiGate appliances, accessing credentials and device configuration information. They then used these stolen credentials to connect to victims’ internal networks to access more credentials and attempt to access backup infrastructure.

According to AWS’s observations, FortiGate vulnerabilities were not exploited by the hacker. Instead, the campaign exploited exposed management ports and weak credentials with single-factor authentication.

Moreover, when the actor encountered more secure environments, they moved on to softer targets rather than persisting, meaning their capability probably lies in AI-augmented efficiency and scale, not deeper technical skills, according to AWS.

The targeting seemed opportunistic rather than sector-specific, attacking vulnerable appliances via mass scanning using AI tools, AWS noted.

The threat actor in this campaign is not known to be associated with any advanced persistent threat group with state-sponsored resources, the blog explained. Amazon said it was not compromised in this incident.

To respond, AWS recommended that organisations running FortiGate appliances should ensure management interfaces are not exposed to the internet, and advised that organisations change all default and common credentials on FortiGate appliances, including administrative and VPN user accounts.

In addition, AWS recommended that organisations enforce unique, complex passwords for all accounts.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.