LIVE FEED
AWS Adds Native Access Controls for RAG via Amazon Quick and Bedrock

AWS Adds Native Access Controls for RAG via Amazon Quick and Bedrock

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 6.2 AWS Machine Learning Blog

AWS has introduced integrated access control capabilities for Retrieval-Augmented Generation (RAG) pipelines, combining Amazon Quick and Amazon Bedrock to enforce document-level permissions during AI-driven retrieval. This closes a meaningful gap for defenders: RAG systems have historically treated retrieval as a flat, permissionless operation, meaning users could receive AI-synthesised responses derived from documents they would not normally be authorised to read. Residual maturity questions remain around how granular these controls are at the chunk or passage level, whether they support complex identity federation scenarios, and how access policy drift is monitored over time.

AI Gateways Targeted: LiteLLM, RAGFlow, Kestra Compromised

AI Gateways Targeted: LiteLLM, RAGFlow, Kestra Compromised

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 Microsoft Security Blog

Microsoft Security Research documented active intrusions targeting three distinct AI infrastructure components — a LiteLLM gateway, a RAGFlow retrieval platform, and a Kestra workflow orchestrator — revealing a pattern of attackers treating AI control planes as high-value targets for credential theft and compute abuse. Across all three cases, attackers converged on the same objectives: stealing model-provider API keys, establishing persistence, and monetising compromised compute resources. The findings signal that AI-specific middleware and orchestration layers require the same security rigour as traditional enterprise critical infrastructure.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.