Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)
2026-04-18T08:51:45Z•bad19df710421abc277695bf506da9ac350d777e5964858c093fd2b828a83992
agent-god-modeagentcoreamazon-bedrockawsaxioscloud-securitycredential-exposurecve-2023-33538cyberespionagedns-tunnelingdouble-agenthacktivistirankubernetesmiraipasswordless-authentication','passkeys'phishingprivilege-escalationrecruitment-phishingsandbox-bypasssupply-chainteampcptp-linkvect-ransomwarevertex-ai
What happened
Unit42 published a batch of April 2026 advisories covering multiple high‑risk trends: critical vulnerabilities in Amazon Bedrock AgentCore (an "Agent God Mode" overprivilege issue and sandbox/network‑isolation bypasses enabling DNS tunneling, credential exposure and privilege escalation), active exploitation attempts against TP‑Link routers using CVE‑2023‑33538 with Mirai‑style command injection payloads, and an escalation of Iran‑linked cyber activity (phishing, hacktivism, cybercrime). Additional coverage includes growing attacks on Kubernetes environments exploiting identity/critical CVEs,:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- bad19df710421abc277695bf506da9ac350d777e5964858c093fd2b828a83992
- Enrichment time
- 2026-04-18T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.