The DecoderT2·85 pts
Zenity Discloses AgentCorruption: Single Prompt Hijacks All AWS Bedrock AgentCore Agents and Steals Credentials
Original: A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
- Minimal Attack Surface: A single prompt to one public agent enables lateral movement across all AgentCore instances in the entire AWS account.
- Root Cause: Default IAM roles in AWS Bedrock AgentCore violate the principle of least privilege and fail to isolate agents from the internal metadata service (169.254.169.254).
- Severe Impact: Successful exploitation allows stealing temporary cloud credentials, leading to access to other agents' private memories, source code, and sensitive business data.