Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
2026-04-08T08:51:38Z•1da80529a01a3c5853361b1b8f253723383ee402bf8c5c8fbfb26c171f963f8c
agentcoreagentic aiai-in-malwareamazon bedrockawsaxioscloud securitycredential exposurecyberespionagedns tunnelinggcpiranian threat activitykubernetesllm guardrailsmulti-agent systemspasswordless authenticationphishingprompt fuzzingprompt injectionretail fraudsandbox escapesupply chainteampcpvect ransomwarevertex ai
What happened
Palo Alto Networks Unit 42 published multiple investigations (Apr 2026) highlighting urgent cloud and AI-security risks. Key findings include critical sandbox escape vulnerabilities in Amazon Bedrock AgentCore enabling DNS tunneling and credential exposure; new attack surfaces and prompt-injection risks in multi‑agent Bedrock applications; an over‑privileged “double agent” flaw in Google Cloud Vertex AI; escalations in Kubernetes-targeting activity and identity exploitation; several high‑impact supply‑chain incidents (Axios, TeamPCP with links to Vect ransomware); evolving Iranian cyberespion
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 1da80529a01a3c5853361b1b8f253723383ee402bf8c5c8fbfb26c171f963f8c
- Enrichment time
- 2026-04-08T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.