logo

Cracks in the Bedrock: Agent God Mode

ID: 841204be-3d46-56a5-914c-af868e8869bd

STIX ID: report--841204be-3d46-56a5-914c-af868e8869bd

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: Ori Hadad

...
...

Palo Alto Networks researchers found that the Amazon Bedrock AgentCore starter toolkit auto-creates overly broad IAM roles (dubbed “Agent God Mode”) that allow an agent to pull any ECR image, read or poison any agent memory, and invoke code interpreters across an AWS account; they demonstrate a multi-stage attack (ECR token retrieval → image exfiltration → extract MemoryID → cross-agent memory compromise), disclosed to AWS, and recommend creating least-privilege custom IAM roles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.