One chat message gave Zenity control of all AgentCore agents
AWS made changes for part of the problem, and Zenity tells companies to give each agent a role with only the access it must have.
Claimed, not confirmed
Zenity used one chat message to a public agent on Amazon Bedrock AgentCore. With it, Zenity got control of each AgentCore agent in the same AWS account and region. Zenity gave the problems the name AgentCorruption. The agent gave its credentials when it received the message. This gave access to private conversations, source code and the credentials that agents keep. AWS changed AgentCore, and new agents have less access to internal metadata. AWS also changed the default execution role to give less access.
Sources
Posted