Signum
Feed
Useful signal8 Oct 2026high confidence

Zenity Labs discloses "AgentCorruption" flaws in AWS Bedrock AgentCore allowing takeover of all agents in an account and region via one prompt; AWS partially mitigated

Zenity Labs published technical findings showing that a single chat prompt to one public AgentCore agent could make it query the instance metadata service (169.254.169.254) and exfiltrate its temporary AWS credentials. Overly broad default execution-role permissions then let the researchers list, download and invoke every agent in the same account and region, read private conversations, retrieve stored secrets, and poison long-term memory. Reported to AWS on Dec 25, 2025. AWS has since made IMDSv2 the default for new AgentCore deployments and, around August, tightened the default execution role (no invoking other agents, reading private conversations, or retrieving Secrets Manager credentials). Zenity still recommends custom least-privilege roles.

InfrastructureAdoptionCapability

Entities: Zenity Labs, Amazon Web Services, Amazon Bedrock AgentCore, Strands, Michael Bargury, OpenAI

72Useful signal
1 source
0 primary
Was this useful?
01

What happened

Zenity Labs published research showing that one chat prompt to a public-facing agent on Amazon Bedrock AgentCore could make it query the instance metadata service (169.254.169.254) and hand over its temporary AWS credentials. Because the default execution role was too broad, those credentials let the researchers list, download and invoke every agent in the same account and region, read private conversations, retrieve stored secrets and poison long-term memory. Zenity reported this to AWS on 25 December 2025. AWS has since made IMDSv2 the default for new AgentCore deployments and, around August, narrowed the default role so it can no longer invoke other agents, read private conversations or fetch Secrets Manager credentials.

02

Why it matters

Teams running AgentCore, especially those with a public-facing agent alongside internal ones in the same account and region, should check which execution role each agent uses. The practical decision is to replace default roles with custom least-privilege ones, as Zenity recommends. The wider lesson is old but useful: agents are workloads, and normal cloud hygiene (metadata protection, scoped roles, account separation) applies to them. Agents deployed before AWS's changes may still carry the broad defaults, and the article does not say whether existing deployments were updated, so that needs checking.

03

What is noise

"A single prompt hijacks every agent" is dramatic framing: the attack depended on a public agent that could reach the metadata service and on overly permissive default roles, and AWS has since narrowed both for new deployments. Zenity is a security vendor, so the "systemic" claim and the comparison with OpenAI's four-day fix in a separate case are partly positioning, and there is no evidence of exploitation in the wild. The article also gives no independent confirmation from AWS of the full scope.

04

Watch next

  1. 01Whether AWS publishes a security bulletin or documentation update confirming that existing AgentCore deployments, not just new ones, get IMDSv2 and the tighter default role.
  2. 02Independent reproductions or similar metadata-service credential theft reports against other agent platforms (Azure, Google Cloud, OpenAI) within the next few months.
  3. 03Any evidence of real-world exploitation, or customer incident disclosures, involving AgentCore agents using the pre-change default roles.

Coverage

1 story

More infrastructure signals

Full feed →