logo

AWS Bedrock AgentCore Sandbox Bypass Enables Stealthy C2 and Data Exfiltration

ID: 278baf48-edf8-511e-8254-e711fdf4f572

STIX ID: report--278baf48-edf8-511e-8254-e711fdf4f572

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Divya

...
...

A disclosed sandbox escape in AWS Bedrock AgentCore Code Interpreter Sandbox mode allows outbound DNS resolution that attackers can abuse to establish a bidirectional DNS-based C2 channel and exfiltrate sensitive data (including PII and API keys). Researchers rated the issue CVSSv3 7.5 and demonstrated interactive shells and access to other AWS services when the interpreter has overprivileged IAM permissions; AWS declined to patch the behavior and recommends moving sensitive workloads to VPC Mode and enforcing least-privilege IAM roles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.