
What happened
Zenity Labs reported that one publicly reachable agent on Amazon's Bedrock AgentCore let researchers take over all AgentCore agents in the same AWS account and region, reading private chats and sourcing code.
Why it matters
The default permissions, not a single agent, were the weak point, so one exposed customer-service agent may expose internal finance agents to the same attacker.
WHO IT HITSEnterprise teams running AI agents on AWS now need to check the permissions those agents were created with, because Zenity's findings suggest a public-facing agent may not be isolated from internal ones.
Summaries like this, in your inbox every morning.
Zenity Labs reported its AgentCore findings to AWS on December 25, 2025, and says AWS responded by making IMDSv2 the default for newly deployed agents and by tightening the default execution role around August. The researchers still recommend that companies create narrower roles for their agents.
The AgentCore flaw fits a series of Zenity findings in which a harmless-looking input turns an agent against its own organization. Under the name AgentFlayer, the researchers used zero-click attacks to make Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a single manipulated ChatGPT link created an autonomous agent inside OpenAI's Workspace Agents with approval requirements turned off.
Zenity CTO Michael Bargury said cloud security is about segmentation and least-privilege access, while AI agents need freedom to be useful. The comparison may not look great for AWS, the article says: OpenAI closed its vulnerability within four days, while AgentCore's overblown default permissions persisted for months after Zenity's report.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Valuence's "Generative AI User Trends Survey" (June 2024–May 2026) tracked six services including ChatGPT, Gem…

OpenAI began offering a ChatGPT feature that accepts uploaded audio files and can transcribe them, summarize t…

On a self-built 76-question Jev-format set, six trained 3B–9B open-weight models (Imajev-4B, Clef-Flash 9B, Je…

At Gemini at Work, Google introduced the Gemini agent, built into Gemini Enterprise, which gathers information…

Google released Google AI Edge Foresight, a free macOS Labs app that uses EmbeddingGemma 2 and Gemma 4 to tran…

The Association for Human Mathematics said OpenAI's release of 722 AI-generated "mathematical results" is not…
