Cracks in the Bedrock: Agent God Mode

2026-04-09T20:51:37Z99ea96eb494f236a22c117034b25870b79b3bf48c8fba724a43198f8efa81acd
AI agent securityAgent God ModeAgentCoreAmazon BedrockDNS tunnelingGCP Vertex AIIAM overprivilegeKubernetes threatsUnit42cloud securitycredential exposuredata exfiltrationmalware and AImulti-agent AIprivilege escalationprompt fuzzingprompt injectionsandbox escapesecurity researchsupply chain attack

What happened

Palo Alto Unit 42 published multiple research posts (April 2026) exposing serious security weaknesses in agentic AI and cloud agent runtimes. Key findings include an “Agent God Mode” in Amazon Bedrock AgentCore where excessively broad IAM permissions enable privilege escalation and data exfiltration, sandbox escapes from AgentCore demonstrating DNS tunneling and credential exposure, new attack surfaces in multi‑agent Bedrock applications (prompt injection risks), and related over‑privilege issues in GCP Vertex AI. The feed also highlights broader cloud/Kubernetes threat trends and activeSupply

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
99ea96eb494f236a22c117034b25870b79b3bf48c8fba724a43198f8efa81acd
Enrichment time
2026-04-09T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cracks in the Bedrock: Agent God Mode · Baitaphish