Top StoriesTechFinanceHealthEnergySportsCulture
Tech & Science

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

By The Hacker News · 2026-03-17
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
Why it matters: DNS‑based C2 defeats sandbox promises, exposing cloud AI workloads to data breaches.
BeyondTrust researchers discovered that Amazon Bedrock's AgentCore Code Interpreter sandbox permits outbound DNS queries, enabling attackers to establish command‑and‑control channels, exfiltrate data, and achieve remote code execution. Amazon says this behavior is intentional and advises moving to VPC mode and using DNS firewalls, while security experts warn that over‑privileged IAM roles amplify the risk.

Share this story

More tech & science → Read original →

Get tech & science in your inbox

The best stories, summarized daily. Free.

No spam. Unsubscribe anytime.