AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

2026-03-18T01:24:12Ze062250c1ed8cdc184cc65993cb7afdae3b87f3cc8681e3c392e6784e050697c
AI securityAmazon BedrockCVE-2026-21666CVE-2026-21667CVE-2026-3909Chrome zero-dayClickFixDNS exfiltrationDeno loaderGitHub token theftGlassWormLangSmithLeakNetMacSyncOpen VSXOpenClawSGLangVeeam RCEVulnerabilitiesWing FTP CVE-2025-47813 (KEV) info-leaker CISA flagged vuln 4.3/prompt injectionransomwaresandbox escapesocial engineeringsupply chain

What happened

A broad set of active threats and security gaps were reported: researchers disclosed DNS-query-based data exfiltration and sandbox escape risks in AI code-execution platforms (notably Amazon Bedrock AgentCore, LangSmith and SGLang), while supply-chain and developer-targeting campaigns (GlassWorm) use stolen GitHub tokens and abused extension dependencies to inject malware. Social-engineering ClickFix campaigns continue to deliver macOS and ransomware payloads (LeakNet, MacSync) and novel loaders (Deno in-memory), and SEO-poisoning and trojanized VPN clients are being used for credential theft.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e062250c1ed8cdc184cc65993cb7afdae3b87f3cc8681e3c392e6784e050697c
Enrichment time
2026-03-18T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.