Back The-Decoder A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
A chain of vulnerabilities in Amazon's Bedrock AgentCore platform let researchers take over all of a company's AI agents in the same AWS region through a single chat message to one public agent.
Agents lacked proper isolation and handed over internal AWS credentials when asked. Because the platform granted broad default permissions across the entire region, the researchers could access and manipulate source code, passwords, private conversations, and the long-term memory of other agents.
AWS has partially fixed the issue by making it harder for new agents to retrieve internal metadata and by tightening the default execution role. The researchers still recommend that companies manually assign their AI agents stricter roles with minimal access rights.
Researchers at Zenity Labs say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call "AgentCorruption."
An attacker needed only chat access to one public agent to exploit the flaws. The researchers say a single prompt let them take over every AgentCore agent in the same AWS account and region, exposing private conversations, source code, and stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools in multiple AWS accounts.
The agent handed over its own credentials
AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that provides temporary credentials for instances and workloads to authenticate with AWS. Anyone who captures those credentials can use them to impersonate the instance.
An AI agent normally shouldn't be able to reach that service, but AgentCore lacked proper isolation, according to Zenity's technical blog post . The researchers built a test agent using Strands , an open-source framework from AWS that ships with a web tool. When asked in plain language to query the metadata service and send the results to an external server, the agent followed the instructions. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.
The stolen credentials worked on the researchers' own machine outside the platform, so they no longer needed the agent to continue the attack. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage that didn't belong to the researchers' account.
Removing the web tool wouldn't have helped, according to Zenity, because the flaw was in the platform itself. The researchers also carried out the attack through a command-line tool.
Default permissions exposed every agent in the region
The takeover was possible because AgentCore's default permissions weren't limited to the agent receiving them. According to Zenity, they applied to every agent in the same account and region, granting read, write, and delete access that allowed destructive operations.
With those permissions, the researchers could list every agent, download their code packages in seconds, and invoke each one. Those packages often contain forgotten passwords or API keys alongside source code, potentially exposing more than the agents themselves. An attacker could, for example, move from a public-facing customer service agent to an internal finance agent and access its data. The researchers could also read all private conversations between users and agents.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
