BeyondTrust shows how AWS Bedrock AgentCore’s ‘isolated’ environment can be tricked into data exfiltration and command execution via DNS. AWS’ promise of “complete isolation” for agentic AI workflows ...