What matters in AI.

Subscribe

One chat message gave Zenity control of all AgentCore agents

AWS made changes for part of the problem, and Zenity tells companies to give each agent a role with only the access it must have.

Claimed, not confirmed

Zenity used one chat message to a public agent on Amazon Bedrock AgentCore. With it, Zenity got control of each AgentCore agent in the same AWS account and region. Zenity gave the problems the name AgentCorruption. The agent gave its credentials when it received the message. This gave access to private conversations, source code and the credentials that agents keep. AWS changed AgentCore, and new agents have less access to internal metadata. AWS also changed the default execution role to give less access.

Sources

  1. A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers foundthe-decoder.com
  2. A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers foundThe Decoder
AI MATTER · NEWS · AI MATTER · NEWS ·8 OCT2026

Posted

Tags

Learn the terms in this story

Guides for this story

More in Security

All Security news