'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
Source: Dark Reading (opens in a new tab) · Rob Wright
Intel Summary
Dark Reading reports on a resolved vulnerability named 'AgentCorruption' in AWS Bedrock AgentCore. The flaw could allow an attacker submitting a single prompt to one AI chatbot to take over an organization's entire fleet.
Why It Matters
The incident demonstrates critical lateral movement risks in enterprise agentic deployments, showing that a prompt-based compromise of one conversational interface can escalate into broader infrastructure takeover across connected systems.
Organizations & Entities
Topics
Related Intelligence
- ReportAlso involving Amazon Bedrock AgentCore
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Zenity Labs researchers discovered that a single prompt to a publicly accessible AI agent on Amazon Bedrock AgentCore could allow an attacker to compromise every AgentCore agent within the same AWS account and region. The vulnerability exploited an unrestricted internal interface for temporary credentials, which AWS has since patched while tightening default agent permissions.
The Decoder - DevelopmentNewAlso involving Amazon Bedrock AgentCore
Zenity Labs researchers discovered vulnerability in Amazon Bedrock AgentCore
Zenity Labs researchers discovered that a single prompt to a publicly accessible AI agent on Amazon Bedrock AgentCore could allow an attacker to compromise every AgentCore agent within the same AWS account and region. The vulnerability exploited an unrestricted internal interface for temporary credentials, which AWS has since patched while tightening default agent permissions. Claims are as reported; this summary makes no determination about accuracy or significance.
- ReportAlso involving Amazon Web Services
Introducing Claude Haiku 5.5 on AWS
AWS announced that Claude Haiku 5.5 is now available on Amazon Bedrock and the Claude Platform on AWS. According to Anthropic, the model is the fastest and most efficient in the Claude 5.5 tier, designed specifically for subagents and cost-sensitive, high-volume operations, and reportedly costs roughly 75% less than Claude Haiku 4.5 for most workloads.
AWS Machine Learning - DevelopmentNewAlso involving Amazon Web Services
AWS makes GLM 5.3 available on Amazon Bedrock
AWS announced that Z.ai's GLM 5.3, a 753-billion-parameter mixture-of-experts model designed for coding and long-horizon agentic tasks, is now available on Amazon Bedrock. The model supports OpenAI-compatible API invocation, prompt caching to lower latency and cost, and authorized security testing with the open-source Strix agent. Claims are as reported; this summary makes no determination about accuracy or significance.