AIToday
Large Language ModelsAI Safety & AlignmentTHE DECODERPublished: Oct 8, 2026, 22:01 JST

One prompt hijacked every AI agent in an AWS account, Zenity finds

One prompt hijacked every AI agent in an AWS account, Zenity finds

3 Key Points

  1. What happened

    Zenity Labs reported that one publicly reachable agent on Amazon's Bedrock AgentCore let researchers take over all AgentCore agents in the same AWS account and region, reading private chats and sourcing code.

  2. Why it matters

    The default permissions, not a single agent, were the weak point, so one exposed customer-service agent may expose internal finance agents to the same attacker.

WHO IT HITSEnterprise teams running AI agents on AWS now need to check the permissions those agents were created with, because Zenity's findings suggest a public-facing agent may not be isolated from internal ones.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Zenity Labs reported its AgentCore findings to AWS on December 25, 2025, and says AWS responded by making IMDSv2 the default for newly deployed agents and by tightening the default execution role around August. The researchers still recommend that companies create narrower roles for their agents.

The AgentCore flaw fits a series of Zenity findings in which a harmless-looking input turns an agent against its own organization. Under the name AgentFlayer, the researchers used zero-click attacks to make Salesforce Einstein, Copilot Studio, and Cursor redirect customer data or leak credentials. With AgentForger, a single manipulated ChatGPT link created an autonomous agent inside OpenAI's Workspace Agents with approval requirements turned off.

Zenity CTO Michael Bargury said cloud security is about segmentation and least-privilege access, while AI agents need freedom to be useful. The comparison may not look great for AWS, the article says: OpenAI closed its vulnerability within four days, while AgentCore's overblown default permissions persisted for months after Zenity's report.

FAQ
What is AgentCore?
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management.
How did the attack work?
The attacker used chat access to one publicly reachable agent. That agent was asked to query the Instance Metadata Service at 169.254.169.254 and send the credentials to an external server. Those credentials then worked outside the platform.
What did AWS change after the report?
AWS made IMDSv2 the default for AgentCore deployments and changed the overly broad default execution role around August, removing permissions that let agents invoke other agents or read private conversations.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleSequoia backs Catalyst with $30 million for AI trading agents