One prompt let researchers take over every AWS AgentCore agent in a region
Zenity Labs used a single prompt to a public-facing Amazon Bedrock AgentCore agent to take over every AgentCore agent in the same AWS account and region. The AgentCorruption chain let researchers read private conversations, copy agent source code, steal credentials and plant persistent memories.
- Attack began by asking the agent to fetch instance metadata service credentials
- Default AgentCore role covered resources across the whole account and region
- Researchers read private conversations and downloaded agent source code
- AWS fixed some permissions only by September 29; no CVE was assigned
Read next
Security