Amazon has introduced new security features and best practices for its Bedrock platform, focusing on both API key management and the protection of generative AI applications. The release of Amazon Bedrock API keys provides developers with new options for accessing the Bedrock API, but also introduces potential security risks if not managed properly. AWS recommends using temporary security credentials from AWS Security Token Service (STS) as the preferred authentication method, as these credentials are short-lived and reduce the risk of long-term exposure. In cases where API keys must be used, AWS advises choosing short-term API keys over long-term ones, as they have built-in expiration mechanisms that limit the window of vulnerability if a key is compromised. For scenarios requiring long-term API keys, such as with certain third-party software, AWS suggests implementing strict controls and monitoring to mitigate risks. Service control policies (SCPs) can be used to restrict the creation and use of API keys, further reducing the attack surface. In addition to credential management, AWS has launched Amazon Bedrock Guardrails, a suite of configurable safeguards designed to protect generative AI applications from sophisticated attacks, including encoding-based threats. These guardrails provide six key protections: content filters, denied topics, word filters, sensitive information filters, contextual grounding checks, and automated reasoning checks. Encoding-based attacks, where malicious actors encode harmful content to bypass detection, are a growing concern for organizations deploying generative AI. Bedrock Guardrails address this by implementing a defense-in-depth strategy that detects and blocks encoded threats, such as base64 or hexadecimal representations of forbidden words. The safeguards are designed to work across multiple foundation models, including those hosted outside of Amazon Bedrock, ensuring broad applicability. AWS provides detailed guidance on implementing these protections, emphasizing the importance of balancing robust security with usability to avoid friction for legitimate users. Monitoring and auditing of API key usage, as well as regular review of guardrail configurations, are recommended to maintain a strong security posture. The combination of secure API key management and advanced guardrails positions Amazon Bedrock as a platform capable of supporting secure, scalable, and responsible generative AI deployments. Organizations are encouraged to adopt these best practices to protect sensitive data and maintain compliance with internal and external security standards. By leveraging these new features, enterprises can mitigate the risks associated with both credential exposure and advanced AI-specific attack vectors. The comprehensive approach outlined by AWS reflects the evolving threat landscape and the need for proactive, layered defenses in modern cloud environments. Security teams should stay informed about updates to Bedrock's security capabilities and continuously adapt their strategies to address emerging threats. The integration of these controls into development and operational workflows is essential for safeguarding AI-driven applications and maintaining trust in automated systems.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
AWS published a security blog post outlining implementation and management best practices for securing Amazon Bedrock API keys.
AWS published a security blog post describing how to protect generative AI applications against encoding-based attacks using Amazon Bedrock Guardrails.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
aws.amazon.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.