Skip to main content
SecurityEnterpriseTools

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

Source: The Decoder (opens in a new tab) · Jonathan Kemper

Intel Summary

Zenity Labs researchers discovered that a single prompt to a publicly accessible AI agent on Amazon Bedrock AgentCore could allow an attacker to compromise every AgentCore agent within the same AWS account and region. The vulnerability exploited an unrestricted internal interface for temporary credentials, which AWS has since patched while tightening default agent permissions.

Why It Matters

The finding exposes lateral movement and privilege escalation risks in multi-agent cloud deployments, where a single compromised agent can jeopardize an entire regional account boundary. While AWS deployed server-side remediation, the incident underscores the necessity of enforcing strict least-privilege access controls across enterprise agentic infrastructure.

Organizations & Entities

Topics