A Deep Dive Into Attempted Exploitation of CVE-2023-33538
2026-04-17T08:51:38Z•e3b2e59572b16e5103b13c40b806908b74625fb4003f68b28c12696f7cd3e7f5
agentcoreagentic aiamazon bedrockaxioscommand injectioncredential exposurecve-2023-33538dns tunnelingdouble agentiam privilege escalationkubernetesmiraimulti-agent aipalo altopasswordless authentication','google cloud authenticator','ai inphishingprompt injectionrecruitment scamsandbox escapesupply chainteampcptp-linkunit42vect ransomwarevertex ai
What happened
Palo Alto Unit 42 published multiple investigations (Mar–Apr 2026) covering: attempted exploitation of CVE-2023-33538 (TP-Link command‑injection activity with Mirai‑style payloads); critical flaws in Amazon Bedrock AgentCore (IAM "Agent God Mode" and sandbox escape enabling DNS tunneling and credential exposure); escalating Kubernetes attacks exploiting identities and vulnerabilities; several supply‑chain campaigns (Axios supply‑chain incident, TeamPCP multi‑stage attacks and ties to Vect ransomware); overprivileged/malicious AI agent risks (Vertex AI “double agent”, multi‑agent prompt‑injekc‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- e3b2e59572b16e5103b13c40b806908b74625fb4003f68b28c12696f7cd3e7f5
- Enrichment time
- 2026-04-17T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.