ADA A.I CyberSecurity Scoring
ADA
Company Information
Website:https://aws.amazon.com/products/databases/
Employees number:None
Number of followers:266,743
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:amazon.com
ADA Risk Score (AI oriented)
Between 750 and 799
ADAIT Services and IT Consulting
Updated:
09/07/2026
09/07/2026
752/1000
Fair
Baa
ADA Global Score (TPRM)
xxxx
ADAIT Services and IT Consulting
Score locked

ADAFair
Current Score
752Baa (FAIR)
01000
2 incidents
-16.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
753
JULY 2026
752
JUNE 2026
751
MAY 2026
750
APRIL 2026
750
MARCH 2026
748
FEBRUARY 2026
748
JANUARY 2026
764
Cyber Attack
15 Jan 2026 • ADA
Ctrl-Alt-Intel and AWS: Suspected DPRK Threat Actors Compromise Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks
North Korea-Linked Hackers Target Crypto Supply Chain in Coordinated Campaign
746
LOW-18
HUNAWS1772735373
North Korea-Linked Hackers Target Crypto Supply Chain in Coordinated Campaign
A sophisticated cyberattack campaign, attributed to North Korea-linked threat actors, has targeted multiple layers of the cryptocurrency supply chain, compromising staking platforms, exchange software providers, and exchanges themselves. The operation, uncovered in January 2026, resulted in the theft of proprietary source code, private keys, and cloud-stored secrets, marking one of the most calculated intrusions in the crypto sector in recent months.
The attackers employed two distinct intrusion methods: exploiting CVE-2025-55182, a vulnerability in the React2Shell framework, to breach crypto staking platforms, and leveraging stolen AWS access tokens to bypass initial exploitation and directly infiltrate cloud infrastructure. Researchers at Ctrl-Alt-Intel gained rare insight into the attackers’ operations after discovering exposed open directories containing shell history logs, archived source code, and tool configurations, revealing the full scope of the campaign.
Among the stolen assets were .env files containing hardcoded private keys for Tron blockchain wallets, with blockchain records showing 52.6 TRX transferred during the exploitation window though it remains unclear whether the North Korea-linked actors or another threat group executed the transfer. Additionally, compromised Docker container images from a cryptocurrency exchange contained hardcoded database credentials, internal configurations, and proprietary exchange logic, aligning with North Korea’s documented strategy of pre-positioning for large-scale crypto theft.
In the AWS-focused phase, the attackers conducted broad enumeration of EC2 instances, RDS databases, S3 buckets, Lambda functions, and EKS clusters, using grep searches to extract sensitive files like .pem, .key, and .ppk credentials. They also downloaded Terraform state files, which often store infrastructure secrets, and pivoted into Kubernetes clusters by updating kubeconfig files. Once inside, they exfiltrated ConfigMaps, Kubernetes Secrets, and Docker container images in plaintext.
For command-and-control, the threat actors deployed VShell on port 8082 and used FRP as a tunneling proxy over port 53 (DNS), evading standard network monitoring. Connections to their primary VPS were routed over IPv6, further bypassing detection tools designed for IPv4 traffic. The campaign underscores the attackers’ meticulous planning and deep access to critical crypto infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
764
NOVEMBER 2025
778
Cyber Attack
01 Nov 2025 • ADA
AWS: A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
AI-Powered AWS Intrusion Demonstrates Rapid Cloud Compromise in 72 Hours
763
CRITICAL-15
AWS1783621498
AI-Powered AWS Intrusion Demonstrates Rapid Cloud Compromise in 72 Hours
A recent large-scale AWS intrusion highlights how AI-assisted attackers can escalate from initial access to full environmental compromise in just 72 hours without relying on novel exploits. Instead, threat actors leveraged unprecedented speed, scale, and orchestration to chain familiar cloud techniques, exploiting pre-existing weaknesses in visibility, permissions, and credential management.
The attack began when the financially motivated threat actor gained an AWS access key by exploiting a vulnerability in an internet-facing application. From there, they pivoted across cloud infrastructure, source-control repositories, CI/CD pipelines, and runtime services, harvesting credentials to trigger overlapping "attack waves" of discovery, persistence, and impact-oriented actions. Rather than deploying ransomware, the actor sought control over critical cloud services to threaten disruption as extortion leverage.
Forensic evidence suggests AI-driven tooling played a key role. In one instance, four access keys tied to different accounts were used from the same IP and user-agent within a single second a level of concurrency nearly impossible for manual operators. The attacker also executed hundreds of unique SQL queries across databases, rapidly mapping cloud relationships with environment-specific adaptations. Some artifacts were even framed as a "pentest" or "red team" exercise, potentially to mislead investigators or bypass AI tool restrictions.
This incident aligns with broader 2026 trends, where AI has compressed cloud attack timelines. In a separate November 2025 case, a threat actor used large language models to escalate from initial access to full AWS administrative control in just eight minutes without zero-days or malware by automating reconnaissance, privilege escalation, and lateral movement across 19 AWS identities. Researchers note AI "removes friction," enabling attackers to enumerate services and evaluate privilege paths faster than manual operators.
The attack’s success stemmed from long-standing security gaps: exposed secrets in S3 buckets and CI/CD environments, overly permissive cloud permissions, and a lack of predefined containment playbooks. A 2026 Sygnia CISO survey found 73% of security leaders believe their organizations are unprepared for such rapid, AI-driven intrusions.
Defensive shifts are emerging, including momentum-based incident response that runs investigation and containment in parallel. Key recommendations include aggressive credential rotation, identity-first security (MFA, session revocation), broad network containment, and automated detection workflows to match attacker speed. Rebuilding compromised environments from trusted infrastructure-as-code templates is also advised over manual remediation.
The broader lesson: as offensive AI adoption accelerates, defenders must adopt equally integrated, automated response capabilities to counter fragmented, tool-by-tool defenses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
OCTOBER 2025
778
SEPTEMBER 2025
778
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ADA ??
What was ADA's A.I Rankiteo Cyber Score in July 2026 ??
What was ADA's A.I Rankiteo Cyber Score in June 2026 ??
What was ADA's A.I Rankiteo Cyber Score in May 2026 ??
What was ADA's A.I Rankiteo Cyber Score in April 2026 ??
What was ADA's A.I Rankiteo Cyber Score in March 2026 ??
What was ADA's A.I Rankiteo Cyber Score in February 2026 ??
What was ADA's A.I Rankiteo Cyber Score in January 2026 ??
What was ADA's A.I Rankiteo Cyber Score in December 2025 ??
What was ADA's A.I Rankiteo Cyber Score in November 2025 ??
What was ADA's A.I Rankiteo Cyber Score in October 2025 ??
What was ADA's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on ADA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ADA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ADA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?