What matters in AI.

Subscribe

One instruction could give access to AWS AgentCore agent secrets

Zenity reports that AWS removed the permissions that gave this access. AWS does not agree that this is a vulnerability.

Claimed, not confirmed

Zenity Labs, a group of researchers, reports an attack on Amazon Bedrock AgentCore agents. One instruction sent to an agent that a person can use could give access to each agent in the same AWS account and region. The attack, AgentCorruption, gave the researchers access to chats, source code, API keys and secrets. AWS does not agree that this is a vulnerability. Zenity found on September 29 that AWS removed the permissions.

Sources

  1. One Prompt Could Hijack AWS AI Agents and Steal Cloud CredentialsCyberSecurityNews
AI MATTER · NEWS · AI MATTER · NEWS ·11 OCT2026

Posted

Tags

Learn the terms in this story

Guides for this story

More in Security

All Security news