Zenity Labs discloses "AgentCorruption" flaws in AWS Bedrock AgentCore allowing takeover of all agents in an account and region via one prompt; AWS partially mitigated
Zenity Labs published technical findings showing that a single chat prompt to one public AgentCore agent could make it query the instance metadata service (169.254.169.254) and exfiltrate its temporary AWS credentials. Overly broad default execution-role permissions then let the researchers list, download and invoke every agent in the same account and region, read private conversations, retrieve stored secrets, and poison long-term memory. Reported to AWS on Dec 25, 2025. AWS has since made IMDSv2 the default for new AgentCore deployments and, around August, tightened the default execution role (no invoking other agents, reading private conversations, or retrieving Secrets Manager credentials). Zenity still recommends custom least-privilege roles.
Entities: Zenity Labs, Amazon Web Services, Amazon Bedrock AgentCore, Strands, Michael Bargury, OpenAI
0 primary
What happened
Zenity Labs published research showing that one chat prompt to a public-facing agent on Amazon Bedrock AgentCore could make it query the instance metadata service (169.254.169.254) and hand over its temporary AWS credentials. Because the default execution role was too broad, those credentials let the researchers list, download and invoke every agent in the same account and region, read private conversations, retrieve stored secrets and poison long-term memory. Zenity reported this to AWS on 25 December 2025. AWS has since made IMDSv2 the default for new AgentCore deployments and, around August, narrowed the default role so it can no longer invoke other agents, read private conversations or fetch Secrets Manager credentials.
Why it matters
Teams running AgentCore, especially those with a public-facing agent alongside internal ones in the same account and region, should check which execution role each agent uses. The practical decision is to replace default roles with custom least-privilege ones, as Zenity recommends. The wider lesson is old but useful: agents are workloads, and normal cloud hygiene (metadata protection, scoped roles, account separation) applies to them. Agents deployed before AWS's changes may still carry the broad defaults, and the article does not say whether existing deployments were updated, so that needs checking.
What is noise
"A single prompt hijacks every agent" is dramatic framing: the attack depended on a public agent that could reach the metadata service and on overly permissive default roles, and AWS has since narrowed both for new deployments. Zenity is a security vendor, so the "systemic" claim and the comparison with OpenAI's four-day fix in a separate case are partly positioning, and there is no evidence of exploitation in the wild. The article also gives no independent confirmation from AWS of the full scope.
Watch next
- 01Whether AWS publishes a security bulletin or documentation update confirming that existing AgentCore deployments, not just new ones, get IMDSv2 and the tighter default role.
- 02Independent reproductions or similar metadata-service credential theft reports against other agent platforms (Azure, Google Cloud, OpenAI) within the next few months.
- 03Any evidence of real-world exploitation, or customer incident disclosures, involving AgentCore agents using the pre-change default roles.
Coverage
1 storyMore infrastructure signals
Full feed →- Anthropic commits $11.6B over seven years to Akamai for CPU-focused cloud infrastructure, with warrant tied to spending milestones25 Sept 202688
- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI discloses sandbox-escape and credential-leak incidents, confirms pause on tool-use for its most capable models26 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680