❌

Normal view

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

8 April 2026 at 00:00

Unit 42 uncovers critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, demonstrating DNS tunneling and credential exposure.

The post Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox appeared first on Unit 42.

Phishing on the Edge of the Web and Mobile Using QR Codes

14 February 2026 at 00:00

We discuss the extensive use of malicious QR codes using URL shorteners, in-app deep links and direct APK downloads to bypass mobile security.

The post Phishing on the Edge of the Web and Mobile Using QR Codes appeared first on Unit 42.

Novel Technique to Detect Cloud Threat Actor Operations

7 February 2026 at 00:00

We introduce a novel method that maps cloud alert trends to MITRE ATT&CK techniques. The patterns created could identify threat actors by behavior.

The post Novel Technique to Detect Cloud Threat Actor Operations appeared first on Unit 42.

Privileged File System Vulnerability Present in a SCADA System

31 January 2026 at 00:00

We detail our discovery of CVE-2025-0921. This privileged file system flaw in SCADA system Iconics Suite could lead to a denial-of-service (DoS) attack.

The post Privileged File System Vulnerability Present in a SCADA System appeared first on Unit 42.

❌