A newly disclosed attack chain in Amazon Bedrock AgentCore that could turn a single malicious prompt into credential theft and compromise of other AI agents within the same AWS account and region.
Dubbed AgentCorruption, the research linked metadata access to an overprivileged execution role, enabling lateral movement, conversation exposure, memory poisoning, and theft of credentials for connected services.
AgentCore runs containerized agents inside Firecracker microVMs. Researchers demonstrated that an exposed agent equipped with HTTP or shell tools could be instructed to contact the local metadata endpoint at 169.254.169.254.
AWS Bedrock AgentCore Flaw
The resulting requests originated inside the workload, creating a server-side request forgery path to sensitive metadata. The endpoint returned temporary credentials for the agent’s execution role, including an access key ID, secret access key, and session token.
Researchers exported those credentials to…
https://gbhackers.com/aws-bedrock-agentcore-flaw-allowed-attackers/



