Back
Zenity Researchers Hijack All AI Agents in AWS Account With Single Prompt
SiTech AI Team3 min read

Zenity Researchers Hijack All AI Agents in AWS Account With Single Prompt

Security researchers at Zenity Labs found a chain of vulnerabilities in Amazon's Bedrock AgentCore platform that let them take over every AI agent in an AWS account and region through a single chat message to one public agent.

Single Prompt Compromised All Agents in an AWS Region

Researchers at Zenity Labs have uncovered a chain of vulnerabilities in Amazon's Bedrock AgentCore platform that allowed them to take over every AI agent in the same AWS account and region through a single chat message sent to one publicly accessible agent. The researchers call the flaw "AgentCorruption."

Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. According to Zenity, the problem was systemic and affected agents with built-in tools across multiple AWS accounts.

Agents Handed Over Their Own Credentials

AWS runs an Instance Metadata Service at the internal address 169.254.169.254 that provides temporary credentials for instances to authenticate with AWS. Zenity says AgentCore lacked proper isolation, allowing agents to reach that service. The researchers built a test agent using Strands, an open-source AWS framework that ships with a web tool, and a single prompt in a customer support chat window was enough to make the agent send its own AWS credentials to an external server.

The stolen credentials worked outside the platform, and the metadata service also exposed certificate and key material for an internal AWS service plus a presigned URL for internal S3 storage. Zenity notes that removing the web tool would not have helped, because the flaw was in the platform itself; the attack also worked through a command-line tool.

Broad Default Permissions Enabled Region-Wide Access

The takeover was possible because AgentCore's default permissions were not limited to the agent receiving them. They applied to every agent in the same account and region, granting read, write, and delete access. With those permissions, the researchers could list every agent, download code packages containing source code, forgotten passwords, and API keys within seconds, and invoke each agent.

The stolen credentials also let them read private conversations between users and any AgentCore agent in the region. For agents with long-term memory enabled, the researchers altered that memory to influence future behavior, planting instructions that made agents forward future conversations to an external destination.

AWS Tightens Metadata Access and Default Roles

Zenity reported the findings to AWS on December 25, 2025. AWS subsequently made IMDSv2, a more secure version of the metadata service, the default for new AgentCore deployments, and changed the default execution role around August. The updated role no longer allows agents to invoke other agents, read private conversations, or retrieve credentials from AWS Secrets Manager.

Zenity still recommends that companies create custom roles with narrower access. Zenity CTO Michael Bargury described a conflict between cloud security and the flexibility agents need to work, noting that when public-facing and internal agents share an environment, a single vulnerability can compromise security boundaries across the entire system.

Sources: The Decoder

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.