AWS Bedrock AgentCore flaw let single prompt hijack agents

According to security firm Zenity Labs, a single chat message to a public-facing assistant on Amazon's Bedrock AgentCore platform could compromise an entire AWS account and region. The researchers uncovered a vulnerability chain that bypassed sandbox boundaries, allowing an attacker to extract internal AWS credentials and manipulate every other agent in the same environment.
How did a single prompt breach cloud credentials?
Agents running on the platform lacked proper isolation from AWS's internal Instance Metadata Service. When the researchers asked a test agent in plain language to query the metadata service at 169.254.169.254 and transmit the results externally, the agent followed the instructions without restriction. The service returned full temporary AWS credentials, including keys and session tokens, which remained valid outside the platform.
Why were all agents in the region exposed?
The takeover escalated because AgentCore's default permissions applied broadly across every agent in the same region, rather than isolating individual workloads. With the stolen credentials and overly broad execution roles, researchers could list every agent, download their code packages in seconds, and invoke them remotely. This exposed stored passwords, private user conversations, and allowed memory poisoning to alter the behavior of other internal agents.
What changes for development teams using cloud agents?
Although AWS has updated default execution roles to restrict agents from invoking other agents or reading secrets manager data, security experts emphasize that default settings remain insufficient. Development teams must manually configure custom roles with strict, minimal access rights to ensure that public-facing customer service agents cannot interact with internal financial or operational systems.
Sources
Frequently asked questions
- What caused the Bedrock AgentCore security flaw?
- The platform lacked proper isolation from the internal metadata service, allowing agents to retrieve temporary AWS credentials when prompted.
- How many agents were affected in an attack?
- Because default execution roles were overly broad, compromising one public agent allowed researchers to access every agent in the same AWS account and region.
- Has Amazon patched the vulnerability?
- Yes, AWS made IMDSv2 the default and tightened execution roles to prevent agents from invoking each other or reading secrets manager data.
Comments
0 commentsDeixe seu comentário
Be the first to comment.
Continue Lendo

OpenAI Math Proofs: Risks to Crypto Security and Research
OpenAI's massive release of AI-generated math proofs triggers academic backlash and sparks urgent security debates in crypto.

AI streaming fraud: 10K bots net 18 months in prison
A federal court sentenced a man to 18 months in prison for using AI-generated tracks and 10,000 bots to siphon $8 million in royalties.

OpenAI Publishes 372 AI Math Proofs on GitHub
OpenAI released 372 AI-generated math proofs on GitHub, using Lean for machine verification and averaging three hours of compute per result.