Skip to content
Trending storyMonitoring

Zenity Labs: one public Bedrock AgentCore agent could take over all agents in an AWS account

1 article1 sourcesince Oct 8Last article

Overview

AISummary of 1 article

Zenity Labs says a single publicly accessible agent on Amazon Bedrock AgentCore could let an attacker take over every AgentCore agent in the same AWS account and region.

Researchers reported that a chat prompt was enough to query the instance metadata service and steal temporary credentials, and that AgentCore's default permissions allowed read, write, and delete access across agents. The attacker needed only chat access to that one public agent.

According to Zenity, AWS responded by making IMDSv2 the default for new AgentCore deployments and by changing the default execution role around August. The disclosure is reported by Zenity Labs, and the account of these fixes comes from Zenity rather than an independent AWS statement in the reports reviewed.

Written by AI from the articles below · updated Oct 9, 9:50 AM ET

Check the sources:

Article timeline

The articles in this story. Times are ET.

Oct 8
  1. The DecoderPick
    One public AI agent on AWS could take over every other agent in its region

    AIZenity Labs says a single publicly accessible agent on Amazon Bedrock AgentCore could take over all AgentCore agents in the same AWS account and region. A chat prompt let the researchers query the instance metadata service and steal temporary credentials, and AgentCore's default permissions allowed read, write, and delete access across agents. According to Zenity, AWS made IMDSv2 the default for new deployments and changed the default execution role around August.

Heat trend

Not enough continuous observations to show a trend yet.