The first AWS patch for AgentCore agents did not remove the risk
AWS corrected the default permissions of the agents between June 22 and September 29, Zenity wrote.
Claimed, not confirmed
Zenity and Unit 42 found that AI agents on AWS AgentCore gave credentials to an attacker who told the agent to give them. Zenity told AWS about the problem on December 25. AWS made a patch on February 14, 2026. Zenity wrote that the patch stopped only the first path that the attacker could use. On June 22, Zenity did a check of the default role and found the same permissions.
The Zenity test
Zenity made an agent give a full set of temporary credentials. Zenity used them on a machine that was not part of AgentCore, and they gave access.
The default role had read, write and erase permissions in the AWS region. Zenity wrote that this let it read all private conversations and all agent source code in the region.
The patches
AWS changed AgentCore on February 14. Zenity wrote that this stopped the first path.
On June 22, Zenity did a check of the default role. The permissions did not change. Zenity then found that AWS set them correctly before September 29.
The Unit 42 report
Unit 42 found a different problem and wrote about it on September 18. In AgentCore Harness, the shell tool is on by default and operates as root.
AWS closed the report as informative. AWS referred to its shared responsibility model.
AWS and Zenity
AWS wrote by email that the agents did the tasks they must do.
Michael Bargury of Zenity wrote in an email that agents must have autonomy and connectivity to do their tasks. Bargury wrote that these two things do not agree with strong isolation of agents.
Sources
Posted