Zenity Labs Uncovers Critical AgentCorruption Vulnerability in Amazon Bedrock

·
·
3 min read
·
AI-assisted
Author Profile
by Albert Schaper
Share
Zenity Labs Uncovers Critical AgentCorruption Vulnerability in Amazon Bedrock

Zenity Labs researchers discovered a vulnerability chain, dubbed "AgentCorruption," in Amazon Bedrock AgentCore that allowed a single prompt to a public-facing agent to hijack, read, and rewrite every AI agent in the same AWS account and region. For broader context, explore our Top 100 AI Tools.

Understanding the AgentCorruption Vulnerability

The core of the AgentCorruption vulnerability lies in a chain of exploits that begins with a seemingly innocuous prompt. Zenity Labs demonstrated that a crafted input to a publicly accessible Amazon Bedrock AgentCore agent could trick it into leaking its temporary AWS credentials. This was achieved by exploiting access to the instance metadata service, typically found at 169.254.169.254.

Once these temporary credentials were leaked, the researchers discovered that their default permissions were broadly applied across all agents within the same AWS account and region. This broad access meant that the compromised credentials could be used to:

  • Download the source code of other agents.
  • Read private user conversations.
  • Steal stored secrets.
  • Poison agents' long-term memory, potentially altering their future responses and actions.

The ability to manipulate an agent's long-term memory is particularly concerning, as it could allow attackers to embed instructions that would cause agents to forward future conversations or data to external, unauthorized destinations.

AWS's Response and Remediation

Zenity Labs responsibly disclosed their findings to AWS on December 25, 2025. In response, AWS took steps to address the vulnerability. Around August 2026, AWS made IMDSv2 (Instance Metadata Service Version 2) the default for new deployments. IMDSv2 introduces enhanced security measures, requiring session-oriented requests that make it more difficult for attackers to directly access metadata without proper authentication.

Additionally, AWS tightened the default execution roles for agents, adhering more closely to the principle of least privilege. This change aims to restrict the permissions granted to agents by default, limiting the potential impact of any future credential leaks.

Why This Matters for AI Security

The AgentCorruption vulnerability highlights a critical tension in the development and deployment of AI agents within cloud environments. On one hand, AI agents often require broad access to various tools and services to perform their functions effectively. On the other hand, fundamental cloud security principles, such as segmentation and least-privilege access, demand strict controls to prevent widespread compromise.

This incident underscores the importance of robust security practices in AI development. Developers and organizations deploying AI agents, especially those interacting with public users, must prioritize:

  • Strict Access Controls: Implementing the principle of least privilege, ensuring agents only have the permissions absolutely necessary for their tasks.
  • Input Validation: Thoroughly validating and sanitizing all inputs to prevent prompt injection and other forms of manipulation.
  • Regular Security Audits: Continuously auditing AI systems and their underlying infrastructure for vulnerabilities.
  • Secure Configuration: Ensuring that cloud services and AI platforms are configured with the highest security standards, including the use of updated metadata services like IMDSv2.

The implications extend beyond just Amazon Bedrock, serving as a cautionary tale for any platform that allows AI agents to interact with cloud resources. As AI news continues to evolve, the focus on secure development practices will only intensify.

Key Takeaways

  • Zenity Labs discovered "AgentCorruption," a critical vulnerability in Amazon Bedrock AgentCore.
  • A single prompt could lead to temporary AWS credential leakage and compromise all agents in an account.
  • Leaked credentials allowed access to source code, private conversations, and the ability to poison agent memory.
  • AWS responded by making IMDSv2 default and tightening execution roles around August 2026.
  • The incident highlights the ongoing challenge of balancing AI agent functionality with cloud security principles.

Sources

About the Author

Albert Schaper avatar

Written by

Albert Schaper

Albert Schaper is a co-founder of Best-AI.org. He focuses on product strategy, AI adoption, practical tool selection, and educational content that helps users compare AI products with clearer context.

More from Albert

Was this article helpful?

Found outdated info or have suggestions? Send us a note.

Discover more insights and stay updated with related articles

Discover AI Tools

Find your perfect AI solution from our curated directory of top-rated tools

Less noise. More results.

One monthly email with the ai research tools that matter - and why.

No spam. Unsubscribe anytime. We never sell your data. See our Privacy Policy.

What's Next?

Continue your AI journey with our tools and resources. Whether you're looking to compare AI tools, learn about artificial intelligence fundamentals, or stay updated with the latest AI news and trends, see what fits your needs. Explore our curated content to find the right AI tools for your workflow.