跳到正文
The Decoder· Jonathan Kemper·· 2 小时前AI 评分68

Zenity 发现单个提示词即可劫持 AWS 账户内全部 AgentCore 智能体

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

AI 导读

安全公司 Zenity Labs 称,在 Amazon Bedrock AgentCore 上只需一个公开可访问的智能体,就能用单个提示词接管同一 AWS 账户和区域内所有 AgentCore 智能体,读取私密对话、下载源码并获取凭证。

正文

Researchers at Zenity Labs say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.

Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call "AgentCorruption."

An attacker only needed chat access to one publicly reachable agent. From there, the researchers say they took over all AgentCore agents in the same AWS account and region with a single prompt. They could read private conversations, download source code, and grab stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools across AWS accounts.

The agent handed over its own credentials

The starting point is a well-known cloud problem. AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that serves temporary credentials an instance or workload uses to authenticate with AWS. Anyone who captures those credentials can impersonate the instance.

Normally, an AI agent shouldn't be able to reach that service. But according to Zenity's technical blog post, AgentCore lacked proper isolation. The researchers built a test agent using Strands, an open-source framework from AWS that ships with a web tool. They asked the agent in plain language to query the metadata service and send the results to an external server. The agent complied. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.

Fake online store "TechHub" with an open support chat window showing a red-highlighted Russian-language message instructing the agent to query the IMDS address 169.254.169.254 and send the response to an external server.
A single chat message in the customer support window tricked the agent into sending its own AWS credentials to an external server. | Image: Zenity Labs

The stolen credentials worked outside the platform on the researchers' own machine, and from that point on they didn't need the agent anymore. The metadata service also exposed other sensitive information, including certificate and key material for an internal AWS service and a presigned URL pointing to an internal S3 bucket that didn't belong to the researchers' account.

Burp Collaborator view showing a JSON response from the metadata service containing AccessKeyId, SecretAccessKey, session token, and expiration time for temporary AWS credentials.
The metadata service returned the agent's full temporary AWS credentials, including keys and session token. | Image: Zenity Labs

Skipping the web tool wouldn't have helped, according to Zenity. The attack worked just as well through a command-line tool because the flaw sits in the platform itself.

A default role that acted as a master key

The most damage came from the permissions AgentCore assigned to every agent by default. According to Zenity, these weren't scoped to a single agent but applied to all agents in the region, covering read, write, and delete rights all the way up to destructive actions.

Terminal output of a script sequentially pulling container images of agents like "Ceo_assistant" and "CustomerSupport" from ECR and copying their /app directories.
An automated script pulled the container images of all agents in the region and copied their source code. | Image: Zenity Labs

With those permissions, the researchers could list every agent, download their code packages in seconds, and invoke each one individually. These packages often contain forgotten passwords or API keys alongside source code. An attacker could, for example, pivot from a public-facing customer service agent to an internal finance agent and access its data. Every private conversation between users and agents was readable too.

JSON output of an AgentCore memory event with highlighted session ID, actor ID "amanda_white," and the chat history between a user and a Finance Assistant agent.
The stolen credentials let the researchers read private conversations between other users and any AgentCore agent in the region. | Image: Zenity Labs

For agents with long-term memory enabled, the researchers could tamper with that memory directly. According to their post on memory poisoning, they planted instructions that made agents forward future conversations to an external destination. Users would have kept talking to what looked like a trusted agent without noticing anything wrong.

The safeguards for passwords and API keys also failed. AWS recommends storing credentials separately from agents in a secured vault, but the default permissions allowed direct access to that vault, according to Zenity's post on credential theft. That included keys for services outside AWS.

AWS patches the gaps

Zenity says it reported the AgentCore findings to AWS on December 25, 2025. After the report, AWS made IMDSv2 the default for AgentCore deployments. IMDS is the Instance Metadata Service, the cloud-internal AWS service that workloads use to retrieve runtime information and temporary credentials, and it was the first lever in Zenity's attack. IMDSv2 is a more secure version, and newly deployed agents now launch with it by default. Zenity sells its own security platform for AI agents, which gives the company a business interest in finding flaws in this space.

AgentCore's overly broad default execution role was another problem. According to Zenity's updated account, AWS changed that role around August. The updated version no longer included the permissions that let agents invoke other agents, read private conversations, or pull credentials from AWS Secrets Manager, and other permissions were tightened significantly. The researchers still recommend that companies create their own, narrower roles for their agents. More details are in their analysis of the default role.

Zenity CTO Michael Bargury sees a fundamental tension. "Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful," he said. Every company running agents in the cloud faces that tradeoff. Because public-facing and internal agents often share the same environment, a single vulnerability can break down the boundaries of the entire system.

A pattern of agents turning against their owners

The AgentCore flaw fits into a series of Zenity findings that follow a similar pattern, where a harmless-looking input turns an agent against its own organization. Under the name AgentFlayer, the researchers used zero-click attacks to make Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a single manipulated ChatGPT link was enough to create an autonomous agent inside OpenAI's Workspace Agents with approval requirements turned off.

The comparison doesn't look great for AWS. OpenAI closed its vulnerability within four days, while AgentCore's overblown default permissions persisted for months after Zenity's report. This affects a platform that AWS has opened to all enterprises and that Amazon says is used by Sony and Ericsson, among others.

Agent memory becoming an attack vector lines up with findings from the research community. Google DeepMind lists long-term memory manipulation as its own attack class in its taxonomy of "AI Agent Traps." Just a few poisoned documents in a knowledge base can be enough to skew responses in a targeted way. In the red-teaming study "Agents of Chaos," an OpenClaw agent was remotely controlled through an externally editable document linked in its memory file, and another agent handed over unredacted bank details. OpenAI CEO Sam Altman has spelled out the obvious countermeasure himself, saying agents should only get the minimum access they need. According to Zenity, AgentCore's default role violated exactly that principle.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.

来源:The Decoder · the-decoder.com