On February 4, 2026, Sysdig described an AWS intrusion that began with credentials exposed in S3 and escalated through Lambda to access Bedrock.
Published on February 4, 2026, Sysdig’s account describes an AWS intrusion that began with credentials exposed in S3, passed through a Lambda function, and escalated to access Bedrock. The text does not say when the incident occurred or detail its impact.
Sysdig also points to an Elastic rule that detects external layers being added to Lambda functions. The incident and rule may support investigations of suspicious changes and privilege escalation in the cloud. Consult Sysdig’s original account and the Elastic rule to verify the details and assess their relevance to your organization’s environment.