Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

2026-04-08T08:51:38Z1da80529a01a3c5853361b1b8f253723383ee402bf8c5c8fbfb26c171f963f8c
agentcoreagentic aiai-in-malwareamazon bedrockawsaxioscloud securitycredential exposurecyberespionagedns tunnelinggcpiranian threat activitykubernetesllm guardrailsmulti-agent systemspasswordless authenticationphishingprompt fuzzingprompt injectionretail fraudsandbox escapesupply chainteampcpvect ransomwarevertex ai

What happened

Palo Alto Networks Unit 42 published multiple investigations (Apr 2026) highlighting urgent cloud and AI-security risks. Key findings include critical sandbox escape vulnerabilities in Amazon Bedrock AgentCore enabling DNS tunneling and credential exposure; new attack surfaces and prompt-injection risks in multi‑agent Bedrock applications; an over‑privileged “double agent” flaw in Google Cloud Vertex AI; escalations in Kubernetes-targeting activity and identity exploitation; several high‑impact supply‑chain incidents (Axios, TeamPCP with links to Vect ransomware); evolving Iranian cyberespion

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
1da80529a01a3c5853361b1b8f253723383ee402bf8c5c8fbfb26c171f963f8c
Enrichment time
2026-04-08T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox · Baitaphish