‘AgentCorruption’ Could Have Hijacked an AWS Region With One Prompt
Want more insights like this?
A now-patched vulnerability in AWS Bedrock AgentCore could have allowed attackers to take over every agent in an AWS account and region with a single chatbot prompt. Tamir Ishay Sharbat of Zenity Labs, an AI security vendor, revealed the flaw — dubbed “AgentCorruption” — at SecTor 2026 in Toronto.
The issue stemmed from agents running inside Firecracker MicroVMs without proper network isolation, letting attackers query AWS’s Instance Metadata Service (IMDS) for temporary credentials. From there, broad default permissions meant attackers could invoke other agents, read sessions, and raid AWS Secrets Manager.
AWS patched the flaw in February, enforcing IMDSv2 on all new agents and stripping permissions from default roles — but disputes Zenity’s framing, telling Dark Reading the research recasts documented, intended behavior as a vulnerability. Zenity is now investigating whether similar weaknesses exist on other cloud platforms, and Sharbat says the IMDS problem isn’t specific to AWS. Keep each agent’s role narrow, he says, and anyone who reaches IMDS finds a smaller blast radius.
Source: Dark Reading