One Prompt Took over Every AWS AgentCore Agent in a Region
Zenity said a single prompt let researchers pull temporary STS credentials and use them to access ECR images and other resources.
6 Articles
6 Articles
One prompt took over every AWS AgentCore agent in a region
Researchers at Zenity Labs used a single prompt to one public-facing AI agent on Amazon Bedrock AgentCore to take over every AgentCore agent in the same AWS account and region. The security firm published the research on Thursday, alongside a talk at the SecTor 2026 conference in Toronto. AgentCore is AWS’s managed service for building […] This story continues at The Next Web
AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Throughout this year, Amazon Web Services (AWS) has repeatedly had to patch autonomous agent security holes, which have then reemerged in slightly different forms, according to cybersecurity researchers at Palo Alto Networks’ Unit 42 and at Zenity Labs. But the problem is not with AWS, which seems to be reacting quickly to address security reports, as much as it is with the essential nature of autonomous AI agents and the difficulty in controlli…
A single chat message would have been enough for Zenity researchers to exploit faults in Bedrock AgentCore and access other agents from the same AWS account and region. The case exposed credentials, code and private conversations, and led Amazon to modify some default protections.
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction. AWS has since patched the issue and significantly tightened the agents' default permissions. The article A single prompt was enough to hijack every…
A single publicly accessible AI agent on Amazon's Bedrock AgentCore was sufficient by Zenity Labs researchers to take over all AgentCore agents in the same AWS account and region. This was possible via an internal AWS interface for temporary cloud access data. AWS improved and later significantly restricted the agent's default rights. The article Vulnerability in Amazon's AgentCore: A prompt was enough to take over entire AI fleets first appeare…
Coverage Details
Bias Distribution
- 50% of the sources lean Left, 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







