One Prompt Hijacks All AWS Agents
Zenity Labs discloses AgentCorruption: a single prompt can steal credentials and control all Bedrock AgentCore agents in an AWS region.
ImportanceMaterialEvidenceE3 inspectableWrite-upDeep
Security firm Zenity Labs disclosed "AgentCorruption," a vulnerability chain showing that a single prompt sent to one public-facing Amazon Bedrock AgentCore agent was enough to take control of every agent in the same AWS account and region.
Attackers exploited a lack of network isolation to trick the agent into accessing the Instance Metadata Service (IMDS), stealing temporary AWS credentials. Due to overly broad default permissions, these credentials allowed lateral movement, enabling access to other agents' source code, private conversations, and stored keys, as well as memory manipulation for persistent backdoors.
Zenity reported the issue to AWS in December 2025. AWS subsequently made IMDSv2 the default for new deployments and tightened default execution roles in August, blocking inter-agent invocation and secret retrieval. While partially fixed, researchers recommend enterprises create custom least-privilege roles, noting the inherent conflict between cloud security segmentation and the flexibility AI agents require.