AWS Bedrock AgentCore Flaw: One Prompt Hijacked All Agents

One chat message to one public-facing AI agent was all it took. Security researchers at Zenity Labs say they used that single entry point to take control of every agent running on Amazon Bedrock AgentCore within the same AWS account and region.

AgentCore is the AWS platform companies use to run enterprise AI agents with tools, memory, and access management. Zenity calls the chain of vulnerabilities it found there "AgentCorruption." According to the researchers, this was not a quirk of one setup. The problem was systemic and affected agents with built-in tools across multiple AWS accounts.

How the attack worked

AWS operates an Instance Metadata Service at the internal address 169.254.169.254. It hands out temporary credentials so instances and workloads can authenticate with AWS. Anyone who captures those credentials can impersonate the instance.

An AI agent should not be able to reach that service. On AgentCore, Zenity says, nothing stopped it. The researchers built a test agent with Strands, an open-source AWS framework that includes a web tool. They then asked it, in plain language, to query the metadata service and send the output to an external server. The agent complied. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write.

From there, the agent was no longer needed. The stolen credentials worked on the researchers' own machine, outside the platform. The metadata service also exposed certificate and key material for an internal AWS service, plus a presigned URL for internal S3 storage that belonged to another account.

Removing the web tool would not have fixed anything, Zenity says, because the flaw sat in the platform itself. The team repeated the attack through a command-line tool.

Why one agent meant all agents

The real damage came from AgentCore's default permissions. They were not scoped to the agent that received them. Instead, they covered every agent in the same account and region, with read, write, and delete access.

With those rights, the researchers could:

  • list every agent and download its code package in seconds
  • invoke any agent, for example moving from a public customer service bot to an internal finance agent
  • read all private conversations between users and agents
  • pull stored credentials, including keys for services outside AWS
  • rewrite the long-term memory of agents that had it enabled

That last point matters. In a separate post on memory poisoning, Zenity describes planting instructions that made agents forward future conversations to an outside destination. Users would keep talking to what looked like a trusted agent.

AWS advises keeping passwords and API keys away from agents in secure storage. Code packages often contain forgotten secrets anyway, and the default role let agents reach the secure storage too.

The fix, and its pace

Zenity reported the findings to AWS on December 25, 2025. AWS then made IMDSv2, a more secure version of the metadata service, the default for new AgentCore deployments. Around August, according to Zenity's updated account, AWS also tightened the default execution role. Agents can no longer invoke other agents, read private conversations, or pull credentials from AWS Secrets Manager by default.

Zenity still recommends custom roles with narrower access. It is worth noting that the company sells a security platform for AI agents, so it has a business interest in findings like these.

Zenity CTO Michael Bargury framed the core tension: "Cloud security is about segmentation and least-privilege access. But AI agents need creative freedom to be useful."

The contrast with other vendors is notable. In Zenity's AgentForger research, OpenAI fixed a vulnerability within four days. AgentCore's broad defaults stayed in place for months. AWS has opened AgentCore to all enterprises, and Amazon names Sony and Ericsson among its users.

Our Take

The model did nothing clever here. It followed a plain instruction, and the platform around it had no wall to stop it. This suggests that the biggest agent risks may sit in cloud plumbing and default settings, not in jailbreak tricks.

It fits a wider pattern. Zenity's earlier work hit Salesforce Einstein, Copilot Studio, and Cursor, and Google DeepMind lists memory manipulation as its own attack class. Platform makers are starting to react, as Apple did when it tightened Full Disk Access over agent risks, and vendors are building controls for agent workloads.

For teams running agents on AWS, the practical step is to check whether older deployments still use the old defaults. It is also worth watching whether cases like this shape how insurers price agent liability.