chiprook
← Security
SecurityOctober 8, 2026, 21:14

One prompt let researchers take over every AWS AgentCore agent in a region

Zenity Labs used a single prompt to a public-facing Amazon Bedrock AgentCore agent to take over every AgentCore agent in the same AWS account and region. The AgentCorruption chain let researchers read private conversations, copy agent source code, steal credentials and plant persistent memories.

One prompt let researchers take over every AWS AgentCore agent in a region
#AWS#Amazon#AgentCore#Zenity
Read next
Security

CVE-2026-41264: A Regex Let Prompts Run Code in Flowise

Security

Denylist let 46 of 75 prompt injections through, CapScope only 3

Security

cPanel flaw lets a hosting account run code as root and take over the server

AI

AlphaGenome Atlas Maps Every DNA Mutation, Free to Any Researcher