Amazon patches AWS AgentCore flaws reported by Zenity Labs
A single prompt could let an attacker take over all agents in an account and region.
Cybersecurity firm Zenity Labs disclosed on October 8, 2026, research identifying systemic security vulnerabilities in
Amazon Bedrock AgentCore. Dubbed AgentCorruption, the flaw chain allowed researchers to take over all AgentCore agents within the same AWS account and region using a single prompt sent to a public-facing agent.
The exploit took advantage of an overprivileged default AWS Identity and Access Management role alongside access to the AWS Instance Metadata Service. By issuing outbound requests from a customer-facing agent, researchers retrieved temporary credentials that granted access to internal agents, private conversations, source code container images, and credentials such as API keys and OAuth tokens stored in AWS Secrets Manager.
Researchers also manipulated agent memory, planting instructions that persistently redirected future conversations to an outside destination without alerting users.
Zenity Labs responsibly disclosed the vulnerabilities to AWS on December 25, 2025. Following the report, AWS made IMDSv2 the default configuration for AgentCore deployments and reduced the default execution role's permissions, removing the abilities to invoke other agents, read private chats, and access secrets.
Newsletter
Markets in your inbox, weekly
LATAM-focused analysis, investing ideas, and the week in finance.
Keep reading


