AgentsThe story, in brief

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

One prompt. Every agent in your AWS account. Zenity researchers found a critical flaw in Bedrock AgentCore that AWS has now patched.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A single publicly accessible agent in AWS Bedrock AgentCore could be hijacked via prompt injection to steal temporary credentials and take over all agents in the same account and region. AWS has patched the vulnerability and tightened default agent permissions, but the finding exposes a systemic permission-boundary risk in agent deployments at scale.

The key facts

7 to know
  1. Attack vector: internal AWS credential interface accessible to agents without restriction

  2. Blast radius: all AgentCore agents in the same AWS account and region could be compromised from one accessible agent

  3. Attack method: single prompt injection (no additional exploitation required)

  4. AWS response: patched the issue and significantly tightened default agent permissions

  5. Researcher: Zenity Labs

  6. Platform affected: Amazon Bedrock AgentCore

  7. Timeline: vulnerability reported and patched (date of patch not specified in article)

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without…
Read original report
Back to today's editionMore agents news

Keep reading

Related stories

More from Agents