{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aamazonbedrock/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:amazon:bedrock:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS Bedrock"],"_cs_severities":["low"],"_cs_tags":["cloud","bedrock","persistence","aws","unauthorized-ai-usage"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries possessing compromised AWS IAM user or root account credentials can leverage Amazon Bedrock to create rogue autonomous agents. These agents serve as persistent, AI-driven footholds that operate independently of the initial compromise point. By configuring these agents with specific system instructions and malicious action groups (Lambda functions), attackers can execute multi-step tasks, query internal knowledge bases, and pivot to external services.\u003c/p\u003e\n\u003cp\u003eDefenders must differentiate between legitimate automated deployment pipelines, which typically utilize AssumedRole sessions, and interactive creation via human IAM identities. The creation of Bedrock agents by IAM users or the root account is a high-signal indicator of potential unauthorized activity, as production infrastructure is almost exclusively managed via service-linked roles. This threat is particularly concerning because the AI agent itself acts as a persistent command-and-control channel that can perform actions autonomously over extended periods without further interaction from the adversary.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of rogue Bedrock Agents grants attackers an autonomous capability to interact with cloud environments, potentially leading to unauthorized data exfiltration through Lambda-based action groups, lateral movement into internal services, and the establishment of a persistent, non-traditional C2 channel that is difficult to detect using standard network-based traffic analysis.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy detection logic to monitor 'CreateAgent' API calls originating from human IAM identities (IAMUser or Root).\u003c/li\u003e\n\u003cli\u003eRestrict the 'bedrock:CreateAgent' permission to authorized CI/CD roles using IAM policies or Service Control Policies (SCPs).\u003c/li\u003e\n\u003cli\u003eAudit existing Bedrock agent configurations, specifically reviewing the 'instruction' system prompt and the 'actionGroupExecutor' Lambda ARNs for anomalous or unauthorized code.\u003c/li\u003e\n\u003cli\u003eInvestigate 'PrepareAgent', 'CreateAgentAlias', and 'AssociateAgentKnowledgeBase' events following any detected agent creation to determine the scope of agent deployment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:11:46Z","date_published":"2026-10-01T20:11:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-aws-bedrock-agent-persistence/","summary":"Adversaries with compromised human IAM credentials can create rogue Bedrock Agents to establish persistent AI-driven footholds for data exfiltration, service pivoting, or C2 signaling.","title":"Unauthorized AWS Bedrock Agent Creation for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-10-aws-bedrock-agent-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:amazon:bedrock:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}