
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Quick Answer
Zenity Labs discovered that a single prompt to a public AI agent on AWS Bedrock AgentCore could hijack all agents in the same account, exposing sensitive data.
Quick Take
This vulnerability, termed 'AgentCorruption,' allowed attackers to access private conversations, source code, and AWS credentials due to inadequate isolation and default permissions.
Key Points
- A single prompt exploited vulnerabilities in AWS Bedrock AgentCore, affecting all agents in the account.
- The attack revealed private conversations and AWS credentials due to poor isolation.
- Default permissions allowed destructive operations across all agents in the same region.
- Researchers could alter agents' memory, influencing future interactions with users.
- AWS has since tightened metadata access and default permissions to mitigate risks.
DeepSignal Analysis
What happened
Zenity Labs identified a vulnerability in AWS Bedrock AgentCore that allowed a single prompt to a public AI agent to hijack all agents within the same AWS account and region. This flaw, termed 'AgentCorruption,' exposed sensitive data, including private conversations and AWS credentials, due to inadequate isolation and broad default permissions.
Key evidence
- Zenity Labs reported that an attacker could exploit a single public agent to take control of all AgentCore agents in the same AWS account and region.
- The researchers demonstrated that the compromised agent could access the AWS Instance Metadata Service, revealing its own temporary credentials and other sensitive information.
- AWS has since implemented IMDSv2 as the default for new AgentCore deployments to enhance security, following Zenity's report on December 25, 2025.
Why it matters
This incident highlights significant security vulnerabilities in cloud-based AI systems, particularly regarding the management of permissions and isolation. The ability for one compromised agent to access and control others poses a serious risk to organizations, potentially leading to data breaches and unauthorized access to sensitive information. As AI agents become more prevalent in enterprise environments, ensuring robust security measures is crucial to prevent exploitation.
📖 Reader Mode
~5 min readResearchers at Zenity Labs say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call "AgentCorruption."
An attacker needed only chat access to one public agent to exploit the flaws. The researchers say a single prompt let them take over every AgentCore agent in the same AWS account and region, exposing private conversations, source code, and stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools in multiple AWS accounts.
The agent handed over its own credentials
AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that provides temporary credentials for instances and workloads to authenticate with AWS. Anyone who captures those credentials can use them to impersonate the instance.
An AI agent normally shouldn't be able to reach that service, but AgentCore lacked proper isolation, according to Zenity's technical blog post. The researchers built a test agent using Strands, an open-source framework from AWS that ships with a web tool. When asked in plain language to query the metadata service and send the results to an external server, the agent followed the instructions. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.

The stolen credentials worked on the researchers' own machine outside the platform, so they no longer needed the agent to continue the attack. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage that didn't belong to the researchers' account.

Removing the web tool wouldn't have helped, according to Zenity, because the flaw was in the platform itself. The researchers also carried out the attack through a command-line tool.
Default permissions exposed every agent in the region
The takeover was possible because AgentCore's default permissions weren't limited to the agent receiving them. According to Zenity, they applied to every agent in the same account and region, granting read, write, and delete access that allowed destructive operations.

With those permissions, the researchers could list every agent, download their code packages in seconds, and invoke each one. Those packages often contain forgotten passwords or API keys alongside source code, potentially exposing more than the agents themselves. An attacker could, for example, move from a public-facing customer service agent to an internal finance agent and access its data. The researchers could also read all private conversations between users and agents.

For agents with long-term memory enabled, the researchers could alter that memory to influence future behavior. Their post on memory poisoning describes how they planted instructions that made agents forward future conversations to an external destination. Users would have continued talking to a seemingly trusted agent without noticing anything wrong.
AWS recommends keeping passwords and API keys separate from agents in secure storage, but AgentCore's default permissions undermined that protection. According to Zenity's post on credential theft, those permissions allowed agents to access the stored credentials, including keys for services outside AWS.
AWS tightens metadata access and default permissions
Zenity says it reported the AgentCore findings to AWS on December 25, 2025, after which AWS made IMDSv2 the default for new AgentCore deployments. IMDSv2 is a more secure version of the metadata service that Zenity's attack used as its entry point. Zenity also sells a security platform for AI agents, giving the company a business interest in reporting vulnerabilities in this area.
According to Zenity's updated account, AWS also changed AgentCore's default execution role around August. The updated role no longer allowed agents to invoke other agents, read private conversations, or retrieve credentials from AWS Secrets Manager. AWS significantly restricted other permissions as well, though the researchers still recommend that companies create custom roles with narrower access. They explain those recommendations in their analysis of the default role.
Zenity CTO Michael Bargury sees a conflict between cloud security and the flexibility agents need to work. "Cloud security is about segmentation and least-privilege access. But AI agents need creative freedom to be useful," he said. Every company running agents in the cloud faces that tradeoff, particularly when public-facing and internal agents share an environment. In that setup, a single vulnerability can compromise security boundaries across the entire system.
Other attacks have exposed similar weaknesses in AI agents
The AgentCore findings follow a pattern Zenity has documented elsewhere, in which a harmless-looking input turns an agent against its own organization. In its AgentFlayer research, zero-click attacks made Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a tampered ChatGPT link was enough to create an autonomous agent in OpenAI's Workspace Agents with approval requirements disabled.
OpenAI fixed its vulnerability within four days, while AgentCore's overly broad default permissions persisted for months after Zenity's report. AWS has made AgentCore available to all enterprises, and Amazon says its users include Sony and Ericsson.
Research on agent memory has documented similar weaknesses. Google DeepMind lists long-term memory manipulation as a separate attack class in its taxonomy of "AI Agent Traps," finding that just a few poisoned documents in a knowledge base can steer responses. In the red-teaming study "Agents of Chaos," researchers remotely controlled an OpenClaw agent through an externally editable document linked in its memory file, while another agent handed over unredacted bank details.
OpenAI CEO Sam Altman has said agents should receive only the minimum access they need. According to Zenity, AgentCore's default role violated that principle.
— Originally published at the-decoder.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

