Zenity Labs: one public Bedrock AgentCore agent could take over all agents in an AWS account
Overview
Zenity Labs says a single publicly accessible agent on Amazon Bedrock AgentCore could let an attacker take over every AgentCore agent in the same AWS account and region.
Researchers reported that a chat prompt was enough to query the instance metadata service and steal temporary credentials, and that AgentCore's default permissions allowed read, write, and delete access across agents. The attacker needed only chat access to that one public agent.
According to Zenity, AWS responded by making IMDSv2 the default for new AgentCore deployments and by changing the default execution role around August. The disclosure is reported by Zenity Labs, and the account of these fixes comes from Zenity rather than an independent AWS statement in the reports reviewed.
Written by AI from the articles below · updated Oct 9, 9:50 AM ET
Check the sources:
Article timeline
The articles in this story. Times are ET.
- The DecoderPickOne public AI agent on AWS could take over every other agent in its region
AIZenity Labs says a single publicly accessible agent on Amazon Bedrock AgentCore could take over all AgentCore agents in the same AWS account and region. A chat prompt let the researchers query the instance metadata service and steal temporary credentials, and AgentCore's default permissions allowed read, write, and delete access across agents. According to Zenity, AWS made IMDSv2 the default for new deployments and changed the default execution role around August.
Heat trend
Not enough continuous observations to show a trend yet.