Zenity 发现单个提示词即可劫持 AWS 账户内全部 AgentCore 智能体
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
安全公司 Zenity Labs 称,在 Amazon Bedrock AgentCore 上只需一个公开可访问的智能体,就能用单个提示词接管同一 AWS 账户和区域内所有 AgentCore 智能体,读取私密对话、下载源码并获取凭证。
Researchers at Zenity Labs say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call "AgentCorruption."
An attacker only needed chat access to one publicly reachable agent. From there, the researchers say they took over all AgentCore agents in the same AWS account and region with a single prompt. They could read private conversations, download source code, and grab stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools across AWS accounts.
The agent handed over its own credentials
The starting point is a well-known cloud problem. AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that serves temporary credentials an instance or workload uses to authenticate with AWS. Anyone who captures those credentials can impersonate the instance.
Normally, an AI agent shouldn't be able to reach that service. But according to Zenity's technical blog post, AgentCore lacked proper isolation. The researchers built a test agent using Strands, an open-source framework from AWS that ships with a web tool. They asked the agent in plain language to query the metadata service and send the results to an external server. The agent complied. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.

The stolen credentials worked outside the platform on the researchers' own machine, and from that point on they didn't need the agent anymore. The metadata service also exposed other sensitive information, including certificate and key material for an internal AWS service and a presigned URL pointing to an internal S3 bucket that didn't belong to the researchers' account.

Skipping the web tool wouldn't have helped, according to Zenity. The attack worked just as well through a command-line tool because the flaw sits in the platform itself.
A default role that acted as a master key
The most damage came from the permissions AgentCore assigned to every agent by default. According to Zenity, these weren't scoped to a single agent but applied to all agents in the region, covering read, write, and delete rights all the way up to destructive actions.

With those permissions, the researchers could list every agent, download their code packages in seconds, and invoke each one individually. These packages often contain forgotten passwords or API keys alongside source code. An attacker could, for example, pivot from a public-facing customer service agent to an internal finance agent and access its data. Every private conversation between users and agents was readable too.

For agents with long-term memory enabled, the researchers could tamper with that memory directly. According to their post on memory poisoning, they planted instructions that made agents forward future conversations to an external destination. Users would have kept talking to what looked like a trusted agent without noticing anything wrong.
The safeguards for passwords and API keys also failed. AWS recommends storing credentials separately from agents in a secured vault, but the default permissions allowed direct access to that vault, according to Zenity's post on credential theft. That included keys for services outside AWS.
AWS patches the gaps
Zenity says it reported the AgentCore findings to AWS on December 25, 2025. After the report, AWS made IMDSv2 the default for AgentCore deployments. IMDS is the Instance Metadata Service, the cloud-internal AWS service that workloads use to retrieve runtime information and temporary credentials, and it was the first lever in Zenity's attack. IMDSv2 is a more secure version, and newly deployed agents now launch with it by default. Zenity sells its own security platform for AI agents, which gives the company a business interest in finding flaws in this space.
AgentCore's overly broad default execution role was another problem. According to Zenity's updated account, AWS changed that role around August. The updated version no longer included the permissions that let agents invoke other agents, read private conversations, or pull credentials from AWS Secrets Manager, and other permissions were tightened significantly. The researchers still recommend that companies create their own, narrower roles for their agents. More details are in their analysis of the default role.
Zenity CTO Michael Bargury sees a fundamental tension. "Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful," he said. Every company running agents in the cloud faces that tradeoff. Because public-facing and internal agents often share the same environment, a single vulnerability can break down the boundaries of the entire system.
A pattern of agents turning against their owners
The AgentCore flaw fits into a series of Zenity findings that follow a similar pattern, where a harmless-looking input turns an agent against its own organization. Under the name AgentFlayer, the researchers used zero-click attacks to make Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a single manipulated ChatGPT link was enough to create an autonomous agent inside OpenAI's Workspace Agents with approval requirements turned off.
The comparison doesn't look great for AWS. OpenAI closed its vulnerability within four days, while AgentCore's overblown default permissions persisted for months after Zenity's report. This affects a platform that AWS has opened to all enterprises and that Amazon says is used by Sony and Ericsson, among others.
Agent memory becoming an attack vector lines up with findings from the research community. Google DeepMind lists long-term memory manipulation as its own attack class in its taxonomy of "AI Agent Traps." Just a few poisoned documents in a knowledge base can be enough to skew responses in a targeted way. In the red-teaming study "Agents of Chaos," an OpenClaw agent was remotely controlled through an externally editable document linked in its memory file, and another agent handed over unredacted bank details. OpenAI CEO Sam Altman has spelled out the obvious countermeasure himself, saying agents should only get the minimum access they need. According to Zenity, AgentCore's default role violated exactly that principle.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
来源:The Decoder · the-decoder.com