Researchers at Zenity Labs say a single publicly accessible AI agent on Amazon’s Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.
Amazon Bedrock AgentCore is AWS’ platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call “AgentCorruption.”
An attacker needed only chat access to one public agent to exploit the flaws. The researchers say a single prompt let them take over every AgentCore agent in the same AWS account and region, exposing private conversations, source code, and stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools in multiple AWS accounts.
The agent handed over its own credentials
AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that provides temporary credentials for instances and workloads to authenticate with AWS. Anyone…



