Zenity Finds Single Prompt Compromised AWS AgentCore Accounts
Tech

Zenity Finds Single Prompt Compromised AWS AgentCore Accounts

TechNews Editorial
TechNews EditorialOct 8, 2026 · 2 min read
Share

Why it matters

According to Zenity, overly broad default permissions in cloud platforms can allow a single prompt to compromise multiple AI agents.

The facts

  • Zenity Labs found a single prompt could hijack every AI agent in an AWS account and region through Amazon Bedrock AgentCore.
  • The flaw allowed attackers to access private conversations, source code, and stored credentials due to overly broad default permissions.
  • Zenity reported the issue to AWS in December 2025, prompting AWS to adopt IMDSv2 and restrict default execution roles.

Researchers at Zenity Labs discovered that a single publicly accessible AI agent on Amazon Bedrock AgentCore could compromise every agent in the same AWS account and region. Amazon Bedrock AgentCore is a platform for running enterprise AI agents with tools, memory, and access management. The security firm identified a chain of vulnerabilities called AgentCorruption.

An attacker needed only chat access to one public agent to exploit the flaws. A single prompt allowed researchers to take over every AgentCore agent in the same account and region. This exposure included private conversations, source code, and stored credentials. Zenity stated the problem was systemic and affected agents with built-in tools across multiple AWS accounts.

AgentCore lacked proper isolation

AWS operates an Instance Metadata Service at the internal address 169.254.169.254 to provide temporary credentials for workloads. Anyone capturing those credentials can impersonate the instance. AI agents normally should not reach this service, but AgentCore lacked proper isolation according to Zenity. Researchers built a test agent using Strands, an open-source framework from AWS that includes a web tool. When asked in plain language to query the metadata service and send the results externally, the agent followed the instructions.

The stolen credentials functioned on the researchers outside the platform. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage. Removing the web tool did not fix the issue because the flaw existed in the platform itself. Researchers also executed the attack using a command-line tool.

An external computer uses exposed credentials to activate multiple agent workloads and download their code from one shared server environment.
Illustration: AI & Tech News

Default permissions allowed broad access

The takeover succeeded because AgentCore default permissions were not limited to the receiving agent. Zenity reported that permissions applied to every agent in the same account and region. These permissions granted read, write, and delete access that permitted destructive operations. Researchers could list every agent, download code packages quickly, and invoke each one.

Code packages often contain forgotten passwords or API keys. An attacker could move from a public customer service agent to an internal finance agent. Researchers could also read private conversations between users and agents. For agents with long-term memory enabled, researchers altered that memory to forward future conversations externally.

Read nextAI Tools Enabled Single Attacker to Breach South Korean Banks

AWS updated default security settings

Zenity reported these findings to AWS on December 25, 2025. Afterward, AWS made IMDSv2 the default for new AgentCore deployments. AWS also changed the default execution role around August to restrict permissions. Zenity CTO Michael Bargury noted a conflict between cloud security and agent flexibility.

These findings follow other research by Zenity on AI agents. OpenAI CEO Sam Altman previously stated agents should receive minimal access. AWS makes AgentCore available to enterprises, with Sony and Ericsson among its users. Zenity reported the vulnerability to AWS in late December 2025.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading