Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026

Twenty Million US IP Connections Used by Proxy Services

June 25, 2026

Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Security Flaw in AWS Bedrock Code Interpreter Raises Alarms
Cyber Security

Security Flaw in AWS Bedrock Code Interpreter Raises Alarms

Team-CWDBy Team-CWDMarch 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A method for exfiltrating sensitive data from AI-powered code execution environments using domain name system (DNS) queries has been demonstrated by security researchers, highlighting potential risks in cloud-based AI tooling.

The Phantom Labs Research report, published on March 16, focuses on AWS Bedrock AgentCore Code Interpreter and shows how attackers could bypass expected network restrictions in Sandbox Mode to retrieve data from cloud resources.

The technique relies on DNS resolution capabilities that remain active even when outbound network connections are otherwise restricted. According to the researchers, this behaviour allows malicious instructions embedded in files to create a covert command-and-control (C2) channel.

How the Technique Works

The attack begins with the creation of a malicious CSV file containing embedded instructions. When an AI agent processes the file and prepares code for execution within the Code Interpreter, the embedded content can influence the generated Python code.

Instead of performing standard analysis tasks, the code may be modified to communicate with an external C2 server via DNS queries. The system polls the server using DNS requests and executes any returned commands.

The researchers demonstrated several capabilities during testing:

  • Executing basic commands such as whoami within the sandbox

  • Listing available Amazon S3 buckets and their contents

  • Extracting full file contents, including credentials, personal data and financial information

Despite these actions, the environment continued to report that network access was disabled.

Ram Varadarajan, CEO at Acalvio, said the findings illustrate a deeper architectural challenge. “AWS Bedrock’s sandbox isolation failed at the most fundamental layer, DNS, and the lesson isn’t that AWS shipped a bug, it’s that perimeter controls are architecturally insufficient against agentic AI execution environments.”

Potential Impact on Cloud Environments

The findings also indicate that risks increase when Code Interpreter instances are assigned overly permissive IAM roles. In some configurations, the interpreter may inherit roles designed for other AgentCore services that require broader access.

The default AgentCore Starter Toolkit role, for example, can include wide permissions such as:

If attackers can influence code execution within the interpreter, these permissions could enable the discovery and extraction of sensitive information.

“Organizations must understand that the ‘Sandbox’ network mode in AWS Bedrock AgentCore Code Interpreter does not provide complete isolation from external networks,” warned Jason Soroko, senior fellow at Sectigo.

Read more on DNS data exfiltration: DNS Hijacking, A Major Cyber Threat for the UK Government

AWS Response and Security Recommendations

AWS reviewed the research and determined the behaviour reflects intended functionality rather than a vulnerability. Instead of issuing a patch, the company updated its documentation to clarify that Sandbox Mode provides limited external network access and allows DNS resolution.

Because the behaviour is considered intentional, Soroko said organizations must adapt their security approach. “To protect sensitive workloads, administrators should inventory all active AgentCore Code Interpreter instances and immediately migrate those handling critical data from Sandbox mode to VPC mode.”

The study highlights a broader challenge as AI systems gain the ability to execute code and interact with infrastructure: without strict permission boundaries and network controls, automated agents may become an unexpected path for data exposure.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCrackArmor Flaws Expose Linux Systems to Privilege Escalation
Next Article Can the Security Platform Finally Deliver for the Mid-Market?
Team-CWD
  • Website

Related Posts

Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

What are brushing scams and how do I stay safe?

December 24, 2025

When ‘hacking’ your game becomes a security risk

October 17, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.