

Phantom Labs discovered that AWS Bedrock AgentCore Code Interpreter’s sandbox mode allows DNS queries, enabling bypass of network isolation through DNS-based command-and-control. This research details the discovery, proof-of-concept exploit, disclosure timeline, and defensive guidance for organizations using Code Interpreter workloads.
This blog explains how to make CIEM actionable and practical, offering steps to successful cloud infrastructure entitlement management and providing an overview of how BeyondTrust operationalizes CIEM best practices for organizations of all sizes.

In this blog, we will answer the question “what is cloud infrastructure access” and look at the who, what, and how of accessing infrastructure. We will also look at how BeyondTrust Privileged Remote Access (PRA) delivers secure Cloud Infrastructure Access capabilities to boost user satisfaction, productivity, and security.

The 2025 KuppingerCole Enterprise Secrets Management report named BeyondTrust a leader in all four categories evaluated. The report highlights how our offerings cross multiple identity disciplines, including Privileged Access Management (PAM), Cloud Infrastructure Entitlement Management (CIEM), and Identity Threat Detection and Response (ITDR). Read on for key findings and takeaways from this analyst report.
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.