Security researchers at Zenity Labs have identified a critical vulnerability in Amazon Bedrock AgentCore, AWS's platform for running enterprise SI agents, demonstrating that a single malicious prompt could compromise every agent within the same AWS account and region. The flaw, dubbed "AgentCorruption," allowed attackers to exfiltrate private conversations, source code, and stored credentials by exploiting insufficient isolation between agents and the underlying cloud infrastructure.

What Happened

According to Zenity Labs, the attack chain began with basic chat access to a single publicly accessible SI agent. The researchers found that AgentCore lacked proper isolation from the AWS Instance Metadata Service (IMDS) at the internal address 169.254.169.254. By instructing a test agent built with the open-source Strands framework to query this service and send the results to an external server, the agent inadvertently handed over its own temporary AWS credentials. "The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers wrote in their technical blog post. Once captured, these credentials allowed the attackers to impersonate the instance outside the platform, granting them read, write, and delete access to every agent in the region. The researchers were able to download container images, copy source code, and read private user-agent interactions. For agents with long-term memory enabled, the attackers could also poison the memory, planting instructions that forced the SI agents to forward future conversations to external destinations without user detection.

Why It Matters

The findings highlight a systemic conflict between cloud security principles, such as segmentation and least-privilege access, and the operational flexibility required for agentic SI to be useful. Zenity CTO Michael Bargury noted that while cloud security relies on strict boundaries, SI agents need creative freedom to perform tasks, a tradeoff that becomes dangerous when public-facing and internal agents share an environment. The incident underscores the risks of default permissions in enterprise SI platforms; Zenity reported the issue to AWS on December 25, 2025, and noted that overly broad default permissions persisted for months, contrasting with OpenAI's four-day fix for a similar vulnerability in its Workspace Agents. The study serves as a warning for organizations deploying SI agents in the cloud, particularly those using Amazon Bedrock AgentCore, which Amazon says is used by major enterprises including Sony and Ericsson. The researchers emphasized that removing specific tools like web browsers did not mitigate the flaw, as the vulnerability resided in the platform's core permission structure.

The Bottom Line

AWS has since updated AgentCore to make IMDSv2 the default for new deployments and restricted default execution roles around August 2026, preventing agents from invoking other agents or retrieving credentials from AWS Secrets Manager by default. Despite these patches, Zenity Labs recommends that companies create custom roles with narrower access to ensure SI agents operate under the principle of least privilege.