[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmxeij1n8Oz4LunMMR_4yRpKa52PCrsbURxolJGQQ4qQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"46a1cc8a-25ff-403b-be3a-f607141a56a1","aws-bedrock-sandbox-escape-via-dns-tunneling","c21f5053-b57a-46d1-9070-e8dcec4d5081","AWS Bedrock Sandbox Escape via DNS Tunneling","Researchers discovered a critical vulnerability in Amazon Bedrock AgentCore that allows attackers to escape sandbox isolation using DNS tunneling techniques. This exploit enables unauthorized data exfiltration and command-and-control communication by bypassing network controls designed to contain AI workloads. The vulnerability exposes fundamental weaknesses in cloud-based AI service isolation, demonstrating that even managed services require additional security controls. Organizations relying on cloud AI platforms must implement defense-in-depth strategies rather than trusting vendor isolation alone.","**Immediate actions:**\n- Implement DNS monitoring and filtering to detect suspicious DNS queries and tunneling attempts\n- Configure egress filtering rules to restrict outbound network traffic from AI workloads\n- Enable detailed logging for all DNS requests from Bedrock AgentCore instances\n\n**Network security measures:**\n- Deploy network segmentation to isolate AI workloads from sensitive data and systems\n- Implement DNS security solutions that can detect and block covert channel communications\n- Configure firewall rules to limit AI agent network access to only required services\n\n**Long-term improvements:**\n- Establish regular security assessments of cloud AI service configurations\n- Develop incident response procedures specifically for AI workload compromises\n- Implement data loss prevention (DLP) controls around AI processing environments",[12,13,14,15,16],"CIS Control 12 (Network Infrastructure Management)","CIS Control 13 (Data Protection)","NIST SC-7 (Boundary Protection)","NIST SI-4 (Information System Monitoring)","NIST AC-4 (Information Flow Enforcement)","published","2026-04-13T23:08:48.540326+00:00","2026-04-13T23:08:48.392+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002FUnit42_Intel\u002Fstatus\u002F2043822563118186588","our-research-shows-it-s-possible-to-break-the-isolation-in-amazon-bedrock-agentc-c71254","Our research shows it's possible to break the isolation in Amazon Bedrock AgentCore's sandbox usi...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]