INTEL_REPORT
Palo Alto Networks Unit 42 · published 4/8/2026, 10:00:51 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Cracks in the Bedrock: Agent God Mode Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42 . Cracks in the Bedrock: Agent God Mode Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedrock: Agent God Mode 8 min read Related Products Cort…
https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode
sha256:0181d8811a2155d9215f34cd0d166d75735b67babf9fee4cbc7227bc43b1c818
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.