logo

Researchers Find Data Leak Risk in AWS Bedrock AI Code Interpreter

ID: dfa952e9-1260-55e8-88c9-2133e1377293

STIX ID: report--dfa952e9-1260-55e8-88c9-2133e1377293

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers at Phantom Labs disclosed a DNS-based vulnerability in AWS Bedrock AgentCore Code Interpreter’s sandbox that allows attackers to smuggle commands and exfiltrate data via DNS A/AAAA queries (a two-way DNS C2 using chunked ASCII in A records). The report includes a proof-of-concept, a 7.5/10 severity rating, a disclosure timeline in which AWS released and then rolled back a fix and ultimately updated documentation instead of patching, and recommended mitigations such as migrating instances to VPC mode and enforcing least-privilege IAM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.