Researchers disclosed multiple Amazon Bedrock AgentCore security issues that can break the isolation expected in AI agent execution environments. One finding showed that AgentCore Code Interpreter sandboxes allowed outbound DNS queries despite a no-network-access design, enabling attackers to create a bidirectional command-and-control channel, exfiltrate data over DNS, and obtain an interactive shell. The impact depends heavily on the IAM role attached to the runtime: overprivileged access could expose AWS resources such as S3 and allow broader compromise of data and connected services.
A separate Bedrock AgentCore issue, tracked as CVE-2026-4269, affected the AgentCore Starter Toolkit and allowed unauthenticated remote code execution through S3 bucket squatting. By registering a predictable bucket name before a victim's build process, an attacker could inject malicious content into the agent runtime, gain control of the execution environment, manipulate model inputs and outputs, and potentially achieve lateral movement based on the runtime's IAM permissions. The flaw also introduced a software supply chain risk because compromised dependencies could be cached or embedded into CI/CD artifacts and persist across later deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Orca Security identified three unsafe pickle deserialization vulnerabilities in SGLang, including two unauthenticated remote code execution flaws rated CVSS 9.8. The vulnerabilities were still unpatched at the time of reporting.
Miggo Security disclosed CVE-2026-25750, a high-severity URL parameter injection vulnerability in LangSmith that could enable token theft and account takeover through crafted links. The issue was remediated in LangSmith version 0.12.71.
BeyondTrust disclosed that Amazon Bedrock AgentCore Code Interpreter's sandbox mode permits outbound DNS queries, which can be abused for command-and-control, data exfiltration, and interactive shell access despite expected isolation. Amazon reportedly classified the behavior as intended functionality and recommended using VPC mode and DNS firewalling as mitigations.
A vulnerability tracked as CVE-2026-4269 was disclosed in the Amazon Bedrock AgentCore starter toolkit/runtime, where S3 bucket squatting could allow unauthenticated remote code execution. Successful exploitation could give attackers control of the AI agent execution environment, enabling data exfiltration, output manipulation, and possible lateral movement via the runtime's IAM role.
2 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.