chiprook
← Security
SecurityOctober 8, 2026, 20:05

AWS keeps patching AI agent security holes that keep coming back

Researchers at Palo Alto Networks' Unit 42 and Zenity Labs detailed repeated security flaws in AWS AgentCore: default configurations let attackers extract plaintext credentials and temporary STS keys via prompt injection. AWS patched entry vectors in February and June 2026, but Zenity says some attack paths stayed open until at least October 8.

AWS keeps patching AI agent security holes that keep coming back
#AWS#Amazon#AgentCore
Read next
AI

AWS Deploys Production Agentic Tools in Vietnam at Cloud and AI Day Hanoi

Security

AWS Bedrock AgentCore fixed the same install_packages() injection bug twice

Security

Amazon Bedrock AgentCore SDK flaws exposed AWS credentials

Security

MCP SDK OAuth fix audit: patching alone leaves the hole open