Thursday, October 8, 2026
Privacy-First Edition
Back to NNN
Business

Zenity Labs Discloses AgentCorruption, a Chain of AWS AgentCore Flaws That Allowed One Prompt to Take Over All AgentCore Agents Within an AWS Account and Region

Via Business Wire

Zenity Labs Discloses AgentCorruption, a Chain of AWS AgentCore Flaws That Allowed One Prompt to Take Over All AgentCore Agents Within an AWS Account and Region Business Wire Thu, October 8, 2026 at 9:01 AM EDT 5 min read AMZN +1.42% Trade AMZN on Coinbase Trading disclosure Trading disclosure The above button links to Coinbase. Yahoo Finance is not a broker-dealer or investment adviser and does not offer securities or cryptocurrencies for sale or facilitate trading. Coinbase pays us for certain activity generated through this link. Prices displayed are informational.

Vulnerabilities gave researchers access to internal agents, private conversations, source code and cloud credentials; they also enabled persistent manipulation of agent behavior

TORONTO, October 08, 2026--(BUSINESS WIRE)--Zenity Labs today disclosed AgentCorruption, new research identifying a chain of security flaws in Amazon Bedrock AgentCore. Using a single prompt to one public-facing agent, researchers took over all AgentCore agents within the same AWS account and region, accessed private conversations and cloud credentials and persistently manipulated agent behavior. The underlying vulnerabilities discovered by Zenity Labs were systemic to AgentCore and affected any agent equipped with built-in tooling across AWS accounts.

The vulnerabilities gave researchers access to internal agents they were not authorized to use, along with source code, long-term memories, API keys, OAuth tokens and other credentials stored in AWS Secrets Manager. Researchers also implanted malicious memories that directed agents to transmit future conversations to an attacker-controlled destination.

Zenity Labs disclosed the findings in conjunction with the presentation of AgentCorruption at SecTor 2026 in Toronto.

"Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful. Mixing the two creates an inherent conflict," said Michael Bargury, co-founder and CTO of Zenity. "Every company deploying agents in the cloud will run into the same fundamental choices to be made between agency and least privilege. Our research shows the difficulties in getting those just right."

A Single Agent Could Expose All Agents Across the Entire Region

The attack began when researchers sent a prompt to a public-facing AgentCore agent equipped with a commonly used tool capable of making outbound requests. The prompt instructed the agent to access the AWS Instance Metadata Service (IMDS), which provides temporary credentials to cloud workloads.

AgentCore's infrastructure allowed the agent to reach the IMDS endpoint and retrieve the credentials assigned to its underlying machine. Those credentials belonged to a default AWS Identity and Access Management role whose permissions were not limited to the original agent but instead extended to all AgentCore agents within the same AWS account and region. Researchers could therefore use the credentials obtained from one public-facing agent to access other AgentCore agents throughout the same AWS account and region.

Together, the infrastructure design flaw and overprivileged role turned access to a single agent into an entry point to the organization's wider AgentCore environment. For example, an attacker entering through an internet-facing customer service agent could move laterally to an internal finance agent deployed in the same region, invoke it, and access its data and tools, related credentials and private conversations.

Further Vulnerabilities and Impact

From this initial public-facing entry point, the researchers continued by exploiting multiple vulnerabilities, combining enumerability weaknesses and internal APIs to achieve devastating impacts:

Discover and invoke all AgentCore agents within the same AWS account and region, including internal and sensitive agents they were not authorized to access

Read all private conversations and long-term memories across agents, users and sessions

Download agent container images, read them in full and retrieve agents' source code

Retrieve API keys, OAuth tokens and other credentials stored in AWS Secrets Manager and environment variables. This includes credentials used by AgentCore agents to connect to enterprise resources and third party services beyond AWS

The researchers also abused the agents' memory functionality to create malicious memories that altered agent behavior and directed all future conversations to an attacker-controlled destination

Persistent Access Through Agent Memory

The ability to modify agent memory extended the attack beyond one-time access. By planting instructions that remained in memory, researchers demonstrated how an attacker could establish persistence and covertly hijack an agent's goals and behavior across future interactions. Users would continue interacting with what appeared to be a trusted enterprise agent while it operated under attacker-controlled instructions behind the scenes and transmitted conversations to outside destinations.

Enterprises are rapidly adopting AI agents, with cloud platforms becoming the default deployment environment. This creates a fundamental security challenge: agents need their creative space to be useful, while cloud security is built around limiting access as much as possible.

AgentCorruption shows what can happen when that balance breaks. A single agent can become an entry point to a much larger environment, allowing attackers to access resources far beyond the agent they initially compromised.

This matters well beyond AgentCore. Enterprises routinely run customer-facing and internal agents side by side in the same cloud environments. These agents often handle sensitive employee and customer data and are connected to powerful tools, business applications and more. As agents gain more autonomy and more access, a single unexpected weakness in one agent could collapse the boundaries of an entire environment, and open paths to data and resources that were never meant to be exposed.

Zenity Labs responsibly disclosed the AgentCore findings to AWS on Dec. 25, 2025. Following the disclosure, AWS made IMDSv2 the default for AgentCore deployments. Zenity Labs' testing confirmed that AWS had reduced the default execution role's permissions. This included the removal of the permissions that allowed agents to invoke other agents, read private conversations or access secrets stored in AWS Secrets Manager. Zenity Labs thanks AWS for its collaboration throughout the process.

Zenity Labs published technical research and video demonstrations detailing the findings:

AgentCorruption: How A Single Prompt Collapsed The Entire Cloud Security Model

AgentCorruption: Weaponizing Agent Memory for Persistent Hijacking

About Zenity Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security. Learn more at www.zenity.io.

View source version on businesswire.com: https://www.businesswire.com/news/home/20261008316155/en/

For Media Inquiries Elyse FamilantResults PRElysef@resultspr.net

Read original at Yahoo Finance News

The Perspectives

0 verified voices · Three viewpoints · Real discourse

Left
0
Be the first to share a left perspective
Center
0
Be the first to share a center perspective
Right
0
Be the first to share a right perspective

Related Stories