AWS Bedrock Tool Vulnerability Enables Data Exfiltration via DNS Leaks
Published 2026-03-25AI Regulation and GovernanceHigh
Summary
A security vulnerability has been identified in AWS Bedrock's tool-use functionality that could allow attackers to exfiltrate sensitive data through DNS-based covert channels. The attack vector exploits how Bedrock agents handle tool calls, potentially enabling malicious actors to leak data from enterprise AI workloads by encoding information within DNS queries — a technique that can bypass many traditional network security controls. This vulnerability highlights the expanding attack surface in
Alignment: Reinforces current position
Related Positions: ai-governance-and-risk.md, agentic-workflows.md, ai-infrastructure-strategy.md
aws-bedrocksecurity-vulnerabilitydns-exfiltrationagentic-ai-securityai-governancecloud-ai-infrastructuretool-usedata-leakageenterprise-ai-riskagent-sandboxing