AWS keeps patching AI agent security holes that keep coming back
Researchers at Palo Alto Networks' Unit 42 and Zenity Labs detailed repeated security flaws in AWS AgentCore: default configurations let attackers extract plaintext credentials and temporary STS keys via prompt injection. AWS patched entry vectors in February and June 2026, but Zenity says some attack paths stayed open until at least October 8.
- Unit 42 reported on Sept 18, 2026 that AgentCore's default shell tool runs as root, enabling credential exfiltration
- Zenity Labs extracted live STS credentials and pulled source code for all agents in the region
- AWS patched the first vector on Feb 14, 2026, but a June check found a new attack path
- Zenity said the role's permissions allowed reading user conversations, poisoning memory and invoking other agents
Read next
AI