« All posts

AWS AgentCore flaw let single prompt steal agent credentials

A single chat prompt exposed IMDS credentials in AWS Bedrock AgentCore, letting attackers hijack other agents via an overpermissioned IAM role.

Researchers at Zenity Labs found that AI agents hosted on Amazon Bedrock AgentCore could be tricked by a single chat prompt into fetching data from the Instance Metadata Service (IMDS), leaking temporary AWS credentials. Because AgentCore still used IMDSv1 and its Firecracker MicroVMs lacked sufficient network isolation, an attacker needed nothing more than chat access to perform an SSRF attack and harvest IAM credentials. The impact was amplified by AgentCore's default IAM role, which was scoped to all agents in an AWS region rather than a single workload. With stolen credentials, an attacker could enumerate other agents, pull and inspect their container images, read memory resources and user session data, and even write persistent memories to hijack agents' future behavior. Zenity disclosed the issue to AWS in December 2025; AWS moved to IMDSv2 by February 2026, but the overpermissioned role wasn't fully fixed until September 2026. The case underscores how critical least-privilege IAM scoping and network isolation are in multi-tenant agentic cloud platforms.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work