Zenity 研究人员发现一条 Prompt 即可劫持同一 AWS 账户内所有 Bedrock AgentCore 智能体
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Zenity Labs 研究人员披露名为 AgentCorruption 的漏洞链,称只需对一个公开的 Amazon Bedrock AgentCore 智能体发送一条 Prompt,即可接管同一 AWS 账户和区域内所有 AgentCore 智能体,泄露私有对话、源代码和存储的凭据。
Researchers at Zenity Labs say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region.
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Security firm Zenity Labs found a chain of vulnerabilities that the researchers call "AgentCorruption."
An attacker needed only chat access to one public agent to exploit the flaws. The researchers say a single prompt let them take over every AgentCore agent in the same AWS account and region, exposing private conversations, source code, and stored credentials. According to Zenity, the problem was systemic and affected agents with built-in tools in multiple AWS accounts.
The agent handed over its own credentials
AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that provides temporary credentials for instances and workloads to authenticate with AWS. Anyone who captures those credentials can use them to impersonate the instance.
An AI agent normally shouldn't be able to reach that service, but AgentCore lacked proper isolation, according to Zenity's technical blog post. The researchers built a test agent using Strands, an open-source framework from AWS that ships with a web tool. When asked in plain language to query the metadata service and send the results to an external server, the agent followed the instructions. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.

The stolen credentials worked on the researchers' own machine outside the platform, so they no longer needed the agent to continue the attack. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage that didn't belong to the researchers' account.

Removing the web tool wouldn't have helped, according to Zenity, because the flaw was in the platform itself. The researchers also carried out the attack through a command-line tool.
Default permissions exposed every agent in the region
The takeover was possible because AgentCore's default permissions weren't limited to the agent receiving them. According to Zenity, they applied to every agent in the same account and region, granting read, write, and delete access that allowed destructive operations.

With those permissions, the researchers could list every agent, download their code packages in seconds, and invoke each one. Those packages often contain forgotten passwords or API keys alongside source code, potentially exposing more than the agents themselves. An attacker could, for example, move from a public-facing customer service agent to an internal finance agent and access its data. The researchers could also read all private conversations between users and agents.

For agents with long-term memory enabled, the researchers could alter that memory to influence future behavior. Their post on memory poisoning describes how they planted instructions that made agents forward future conversations to an external destination. Users would have continued talking to a seemingly trusted agent without noticing anything wrong.
AWS recommends keeping passwords and API keys separate from agents in secure storage, but AgentCore's default permissions undermined that protection. According to Zenity's post on credential theft, those permissions allowed agents to access the stored credentials, including keys for services outside AWS.
AWS tightens metadata access and default permissions
Zenity says it reported the AgentCore findings to AWS on December 25, 2025, after which AWS made IMDSv2 the default for new AgentCore deployments. IMDSv2 is a more secure version of the metadata service that Zenity's attack used as its entry point. Zenity also sells a security platform for AI agents, giving the company a business interest in reporting vulnerabilities in this area.
According to Zenity's updated account, AWS also changed AgentCore's default execution role around August. The updated role no longer allowed agents to invoke other agents, read private conversations, or retrieve credentials from AWS Secrets Manager. AWS significantly restricted other permissions as well, though the researchers still recommend that companies create custom roles with narrower access. They explain those recommendations in their analysis of the default role.
Zenity CTO Michael Bargury sees a conflict between cloud security and the flexibility agents need to work. "Cloud security is about segmentation and least-privilege access. But AI agents need creative freedom to be useful," he said. Every company running agents in the cloud faces that tradeoff, particularly when public-facing and internal agents share an environment. In that setup, a single vulnerability can compromise security boundaries across the entire system.
Other attacks have exposed similar weaknesses in AI agents
The AgentCore findings follow a pattern Zenity has documented elsewhere, in which a harmless-looking input turns an agent against its own organization. In its AgentFlayer research, zero-click attacks made Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a tampered ChatGPT link was enough to create an autonomous agent in OpenAI's Workspace Agents with approval requirements disabled.
OpenAI fixed its vulnerability within four days, while AgentCore's overly broad default permissions persisted for months after Zenity's report. AWS has made AgentCore available to all enterprises, and Amazon says its users include Sony and Ericsson.
Research on agent memory has documented similar weaknesses. Google DeepMind lists long-term memory manipulation as a separate attack class in its taxonomy of "AI Agent Traps," finding that just a few poisoned documents in a knowledge base can steer responses. In the red-teaming study "Agents of Chaos," researchers remotely controlled an OpenClaw agent through an externally editable document linked in its memory file, while another agent handed over unredacted bank details.
OpenAI CEO Sam Altman has said agents should receive only the minimum access they need. According to Zenity, AgentCore's default role violated that principle.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
来源:The Decoder · the-decoder.com