<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:amazon:bedrock:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aamazonbedrock/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:11:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aamazonbedrock/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthorized AWS Bedrock Agent Creation for Persistence</title><link>https://feed.craftedsignal.io/briefs/2026-10-aws-bedrock-agent-persistence/</link><pubDate>Thu, 01 Oct 2026 20:11:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-aws-bedrock-agent-persistence/</guid><description>Adversaries with compromised human IAM credentials can create rogue Bedrock Agents to establish persistent AI-driven footholds for data exfiltration, service pivoting, or C2 signaling.</description><content:encoded><![CDATA[<p>Adversaries possessing compromised AWS IAM user or root account credentials can leverage Amazon Bedrock to create rogue autonomous agents. These agents serve as persistent, AI-driven footholds that operate independently of the initial compromise point. By configuring these agents with specific system instructions and malicious action groups (Lambda functions), attackers can execute multi-step tasks, query internal knowledge bases, and pivot to external services.</p>
<p>Defenders must differentiate between legitimate automated deployment pipelines, which typically utilize AssumedRole sessions, and interactive creation via human IAM identities. The creation of Bedrock agents by IAM users or the root account is a high-signal indicator of potential unauthorized activity, as production infrastructure is almost exclusively managed via service-linked roles. This threat is particularly concerning because the AI agent itself acts as a persistent command-and-control channel that can perform actions autonomously over extended periods without further interaction from the adversary.</p>
<h2 id="impact">Impact</h2>
<p>Successful deployment of rogue Bedrock Agents grants attackers an autonomous capability to interact with cloud environments, potentially leading to unauthorized data exfiltration through Lambda-based action groups, lateral movement into internal services, and the establishment of a persistent, non-traditional C2 channel that is difficult to detect using standard network-based traffic analysis.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy detection logic to monitor 'CreateAgent' API calls originating from human IAM identities (IAMUser or Root).</li>
<li>Restrict the 'bedrock:CreateAgent' permission to authorized CI/CD roles using IAM policies or Service Control Policies (SCPs).</li>
<li>Audit existing Bedrock agent configurations, specifically reviewing the 'instruction' system prompt and the 'actionGroupExecutor' Lambda ARNs for anomalous or unauthorized code.</li>
<li>Investigate 'PrepareAgent', 'CreateAgentAlias', and 'AssociateAgentKnowledgeBase' events following any detected agent creation to determine the scope of agent deployment.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>cloud</category><category>bedrock</category><category>persistence</category><category>aws</category><category>unauthorized-ai-usage</category></item></channel></rss>