Today for AI
HOT RADAR
agentHEAT 9.7°

AI CLUSTERED EVENT · 10/8/2026

Zenity Discloses AgentCorruption: Single Prompt Hijacks All AWS Bedrock AgentCore Agents and Steals Credentials

1 reports archived1 independent sourcesupdated 10/8/2026, 21:01:01
Synthesis & Latest Updates
1 Sources Cross-Validated

Security firm Zenity Labs discovered a systemic vulnerability named 'AgentCorruption,' allowing attackers to hijack all agents within an AWS account and region via a single prompt sent to one publicly accessible Amazon Bedrock AgentCore agent. The exploit leverages excessive default role permissions and lack of isolation from the Instance Metadata Service (IMDS), enabling theft of private conversations, source code, and temporary cloud credentials.

LATEST/Security firm Zenity Labs discovered a systemic vulnerability named 'AgentCorruption,' allowing attackers to hijack all agents within an AWS account and region via a single prompt sent to one publicly accessible Amazon Bedrock AgentCore agent. The exploit leverages excessive default role permissions and lack of isolation from the Instance Metadata Service (IMDS), enabling theft of private conversations, source code, and temporary cloud credentials.

TIMELINECoverage timeline

Total 1 reports · Latest first
  1. The DecoderT2·85 pts

    Zenity Discloses AgentCorruption: Single Prompt Hijacks All AWS Bedrock AgentCore Agents and Steals Credentials

    Original: A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

    • Minimal Attack Surface: A single prompt to one public agent enables lateral movement across all AgentCore instances in the entire AWS account.
    • Root Cause: Default IAM roles in AWS Bedrock AgentCore violate the principle of least privilege and fail to isolate agents from the internal metadata service (169.254.169.254).
    • Severe Impact: Successful exploitation allows stealing temporary cloud credentials, leading to access to other agents' private memories, source code, and sensitive business data.
Zenity Discloses AgentCorruption: Single Prompt Hijacks All AWS Bedrock AgentCore Agents and Steals Credentials | AI Clustered Intelligence | Today for AI