AWS Bedrock AgentCore Sandbox Bypass Allows Covert C2 Channels and Data Exfiltration
ID: 00fd4916-47d4-5a0e-90de-1d9d79266428
STIX ID: report--00fd4916-47d4-5a0e-90de-1d9d79266428
Feed Name: cybersecurityNews.com
BeyondTrust Phantom Labs discovered that AWS Bedrock AgentCore Code Interpreter’s Sandbox mode, advertised as providing complete network isolation, allowed outbound DNS A/AAAA queries. Researchers built a bidirectional DNS-based C2 and reverse shell to demonstrate command execution and exfiltration (including S3 data via the instance IAM role), disclosed the issue to AWS (HackerOne report), and published findings after AWS chose not to issue a permanent fix and recommended migration to VPC mode.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
