Researchers at Zenity Labs discovered that a single publicly accessible AI agent on Amazon Bedrock AgentCore could compromise every agent in the same AWS account and region. Amazon Bedrock AgentCore is a platform for running enterprise AI agents with tools, memory, and access management. The security firm identified a chain of vulnerabilities called AgentCorruption.
An attacker needed only chat access to one public agent to exploit the flaws. A single prompt allowed researchers to take over every AgentCore agent in the same account and region. This exposure included private conversations, source code, and stored credentials. Zenity stated the problem was systemic and affected agents with built-in tools across multiple AWS accounts.
AgentCore lacked proper isolation
AWS operates an Instance Metadata Service at the internal address 169.254.169.254 to provide temporary credentials for workloads. Anyone capturing those credentials can impersonate the instance. AI agents normally should not reach this service, but AgentCore lacked proper isolation according to Zenity. Researchers built a test agent using Strands, an open-source framework from AWS that includes a web tool. When asked in plain language to query the metadata service and send the results externally, the agent followed the instructions.
The stolen credentials functioned on the researchers outside the platform. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage. Removing the web tool did not fix the issue because the flaw existed in the platform itself. Researchers also executed the attack using a command-line tool.

Default permissions allowed broad access
The takeover succeeded because AgentCore default permissions were not limited to the receiving agent. Zenity reported that permissions applied to every agent in the same account and region. These permissions granted read, write, and delete access that permitted destructive operations. Researchers could list every agent, download code packages quickly, and invoke each one.
Code packages often contain forgotten passwords or API keys. An attacker could move from a public customer service agent to an internal finance agent. Researchers could also read private conversations between users and agents. For agents with long-term memory enabled, researchers altered that memory to forward future conversations externally.
Read nextAI Tools Enabled Single Attacker to Breach South Korean BanksAWS updated default security settings
Zenity reported these findings to AWS on December 25, 2025. Afterward, AWS made IMDSv2 the default for new AgentCore deployments. AWS also changed the default execution role around August to restrict permissions. Zenity CTO Michael Bargury noted a conflict between cloud security and agent flexibility.
These findings follow other research by Zenity on AI agents. OpenAI CEO Sam Altman previously stated agents should receive minimal access. AWS makes AgentCore available to enterprises, with Sony and Ericsson among its users. Zenity reported the vulnerability to AWS in late December 2025.



