A Deep Dive Into Attempted Exploitation of CVE-2023-33538

2026-04-17T08:51:38Ze3b2e59572b16e5103b13c40b806908b74625fb4003f68b28c12696f7cd3e7f5
agentcoreagentic aiamazon bedrockaxioscommand injectioncredential exposurecve-2023-33538dns tunnelingdouble agentiam privilege escalationkubernetesmiraimulti-agent aipalo altopasswordless authentication','google cloud authenticator','ai inphishingprompt injectionrecruitment scamsandbox escapesupply chainteampcptp-linkunit42vect ransomwarevertex ai

What happened

Palo Alto Unit 42 published multiple investigations (Mar–Apr 2026) covering: attempted exploitation of CVE-2023-33538 (TP-Link command‑injection activity with Mirai‑style payloads); critical flaws in Amazon Bedrock AgentCore (IAM "Agent God Mode" and sandbox escape enabling DNS tunneling and credential exposure); escalating Kubernetes attacks exploiting identities and vulnerabilities; several supply‑chain campaigns (Axios supply‑chain incident, TeamPCP multi‑stage attacks and ties to Vect ransomware); overprivileged/malicious AI agent risks (Vertex AI “double agent”, multi‑agent prompt‑injekc‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
e3b2e59572b16e5103b13c40b806908b74625fb4003f68b28c12696f7cd3e7f5
Enrichment time
2026-04-17T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.