A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Source: The Decoder (opens in a new tab) · Jonathan Kemper
Intel Summary
Zenity Labs researchers discovered that a single prompt to a publicly accessible AI agent on Amazon Bedrock AgentCore could allow an attacker to compromise every AgentCore agent within the same AWS account and region. The vulnerability exploited an unrestricted internal interface for temporary credentials, which AWS has since patched while tightening default agent permissions.
Why It Matters
The finding exposes lateral movement and privilege escalation risks in multi-agent cloud deployments, where a single compromised agent can jeopardize an entire regional account boundary. While AWS deployed server-side remediation, the incident underscores the necessity of enforcing strict least-privilege access controls across enterprise agentic infrastructure.
Organizations & Entities
Topics
Related Intelligence
- DevelopmentNewAlso involving Amazon Bedrock AgentCore
Zenity Labs researchers discovered vulnerability in Amazon Bedrock AgentCore
Zenity Labs researchers discovered that a single prompt to a publicly accessible AI agent on Amazon Bedrock AgentCore could allow an attacker to compromise every AgentCore agent within the same AWS account and region. The vulnerability exploited an unrestricted internal interface for temporary credentials, which AWS has since patched while tightening default agent permissions. Claims are as reported; this summary makes no determination about accuracy or significance.
- ReportAlso involving Amazon Web Services
Introducing Claude Haiku 5.5 on AWS
AWS announced that Claude Haiku 5.5 is now available on Amazon Bedrock and the Claude Platform on AWS. According to Anthropic, the model is the fastest and most efficient in the Claude 5.5 tier, designed specifically for subagents and cost-sensitive, high-volume operations, and reportedly costs roughly 75% less than Claude Haiku 4.5 for most workloads.
AWS Machine Learning - DevelopmentNewAlso involving Amazon Web Services
AWS makes GLM 5.3 available on Amazon Bedrock
AWS announced that Z.ai's GLM 5.3, a 753-billion-parameter mixture-of-experts model designed for coding and long-horizon agentic tasks, is now available on Amazon Bedrock. The model supports OpenAI-compatible API invocation, prompt caching to lower latency and cost, and authorized security testing with the open-source Strix agent. Claims are as reported; this summary makes no determination about accuracy or significance.
- DevelopmentNewAlso involving Amazon Web Services
AWS expands Claude model availability to in-country inferencing in India on Amazon Bedrock
Amazon Web Services has expanded Amazon Bedrock availability in India by adding Anthropic's Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5 through geographic cross-Region inference. The service allows users to process data within AWS India Regions using the Bedrock console or the Messages, InvokeModel, and Converse APIs. Claims are as reported; this summary makes no determination about accuracy or significance.