INTEL_REPORT
Palo Alto Networks Unit 42 · published 4/7/2026, 10:00:11 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Unit 42 uncovers critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, demonstrating DNS tunneling and credential exposure. The post Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox appeared first on Unit 42 . Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedr…
https://unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode
sha256:5eb92102b01010d6b7246479ce218e68199379be8be19b23fe580220a298dd19
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.