The Maivia Gazette

Verified AI news, every morning

Security

Researchers say one prompt to a public AWS AgentCore agent let them take over every agent in the same account and region

Zenity Labs' 'AgentCorruption' chain exposed credentials, source code and agent memories. AWS has partially fixed the issue.

A green thread runs from one open brass mailbox into every other mailbox in a wall of mailboxes.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

Zenity Labs has disclosed AgentCorruption, a chain of security flaws in Amazon Bedrock AgentCore, the AWS platform for running enterprise AI agents with tools, memory and access management. The researchers say a single prompt to one public-facing agent let them take over every AgentCore agent in the same AWS account and region. Zenity says the flaws were systemic and affected any agent with built-in tooling, across AWS accounts. The researchers reached internal agents they were not authorized to use, as well as private conversations, source code, long-term memories, API keys, OAuth tokens and other credentials stored in AWS Secrets Manager. They also planted malicious memories that told agents to send future conversations to an attacker-controlled destination. The Decoder reports that agents were not properly isolated, handed over internal AWS credentials when asked, and ran with broad default permissions that covered the whole region. According to The Decoder, AWS has partly fixed the problem by making it harder for new agents to retrieve internal metadata and by tightening the default execution role. The researchers still advise companies to give each agent a strict, least-privilege role themselves. Zenity presented the work at SecTor 2026 in Toronto. "Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful," said Zenity CTO Michael Bargury.

Sources

  1. The DecoderOne public-facing AI agent on AWS could read, rewrite, and delete every other agent in the regionPublished · fetched
  2. Zenity | Secure AI Agents EverywhereAgentCorruption: AWS AgentCore Flaws Let One Prompt Hijack All AgentsPublished · fetched

Also in this edition