Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Security Concerns in Amazon Bedrock and Other Platforms

AI Security Concerns in Amazon Bedrock and Other Platforms

Posted on March 17, 2026 By CWS

Recent findings from cybersecurity experts have revealed potential vulnerabilities in several AI platforms, including Amazon Bedrock. These flaws could allow unauthorized data exfiltration via domain name system (DNS) queries. BeyondTrust’s report highlights that the Amazon Bedrock AgentCore Code Interpreter’s sandbox mode permits DNS queries, which can be exploited for network infiltration, despite its intended isolation.

Amazon Bedrock’s Vulnerability Details

Amazon Bedrock, a service launched in August 2025, facilitates secure AI code execution in isolated environments. However, the ability to make outbound DNS queries poses a threat as malicious actors could establish control channels using these queries. This vulnerability, identified with a CVSS score of 7.5, allows attackers to potentially access and extract data from AWS resources like S3 buckets.

In particular, DNS queries can be manipulated to deliver commands and receive responses, effectively bypassing network isolation. This risk is heightened by overprivileged IAM roles that grant unintended access to sensitive data, emphasizing the need for strict access controls.

LangSmith Flaw and Account Compromises

Another critical security flaw has been discovered in LangSmith, an AI observability platform. This issue, identified as CVE-2026-25750 with a CVSS score of 8.5, involves URL parameter injection that can lead to token theft and account takeover. Affected versions have been patched in LangSmith 0.12.71, released in December 2025.

The vulnerability arises from inadequate validation of the baseUrl parameter, allowing attackers to steal user tokens through crafted links. This weakness underscores the importance of robust security measures in AI platforms, which often prioritize flexibility at the cost of potential security gaps.

SGLang’s Deserialization Risks

SGLang, a popular AI framework, faces security issues related to unsafe pickle deserialization, potentially enabling remote code execution. These vulnerabilities, with CVSS scores up to 9.8, affect its multimodal generation and disaggregation modules.

Orca Security’s findings indicate that SGLang’s improper handling of untrusted data could be exploited to execute arbitrary code. Users are advised to limit network exposure and implement stringent access controls to mitigate these risks. Monitoring for unusual network activity and implementing network segmentation are also recommended to prevent unauthorized access.

The discovery of these vulnerabilities across various AI platforms highlights the evolving landscape of cybersecurity threats. Users and administrators must prioritize the adoption of protective measures and regular audits to safeguard sensitive data.

The Hacker News Tags:AI security, Amazon Bedrock, Cybersecurity, data exfiltration, DNS queries, IAM roles, LangSmith, network isolation, remote code execution, SGLang

Post navigation

Previous Post: Enhancing Online Shopping Security for Better Deals
Next Post: Tech Giants Unite to Tackle Online Scams and Fraud

Related Posts

Insights from 160 Million Attack Simulations Insights from 160 Million Attack Simulations The Hacker News
USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More The Hacker News
U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme The Hacker News
SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats The Hacker News
New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack The Hacker News
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • React Native Packages Targeted by Credential-Stealing Malware
  • Tracebit Secures $20M to Enhance Cybersecurity Solutions
  • Ransomware Tactics Evolve Amid Declining Profits, Google Reports
  • Tech Giants Unite to Tackle Online Scams and Fraud
  • AI Security Concerns in Amazon Bedrock and Other Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • React Native Packages Targeted by Credential-Stealing Malware
  • Tracebit Secures $20M to Enhance Cybersecurity Solutions
  • Ransomware Tactics Evolve Amid Declining Profits, Google Reports
  • Tech Giants Unite to Tackle Online Scams and Fraud
  • AI Security Concerns in Amazon Bedrock and Other Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News