HomeCyber BalkansAWS Bedrock AgentCore Vulnerability Enabled AI Agent Hijacking with a Single Prompt

AWS Bedrock AgentCore Vulnerability Enabled AI Agent Hijacking with a Single Prompt

Published on

spot_img

Newly Disclosed Vulnerability in Amazon Bedrock AgentCore Raises Concerns About Credential Theft

The cybersecurity landscape has recently been shaken by the revelation of a new attack vector, known as AgentCorruption, that targets Amazon’s Bedrock AgentCore. This newly disclosed attack chain has raised significant concerns, as it can potentially turn a single malicious prompt into a pathway for credential theft and the compromise of other AI agents operating within the same AWS account and region.

Understanding AgentCorruption

Research into this vulnerability reveals a direct correlation between metadata access and an excessively privileged execution role. This linkage allows for lateral movement within systems, exposure of sensitive conversations, memory poisoning, and the theft of credentials associated with connected services. At its core, AgentCore operates containerized agents utilizing Firecracker microVMs, a mechanism designed to enhance security by isolating workloads.

The researchers provided compelling evidence demonstrating that an exposed agent outfitted with HTTP or shell tools could be manipulated into contacting the local metadata endpoint, specifically the address 169.254.169.254. This incident creates a server-side request forgery scenario that could lead to the compromise of sensitive metadata—specifically, temporary credentials for the agent’s execution role.

Mechanism of Exploitation

Once the exposed agent sends requests to this metadata endpoint, it returns critical credentials, including an access key ID, secret access key, and session token. With these credentials, researchers were able to export them to their own machines, subsequently verifying the assumed identity through AWS Security Token Service. Notably, this exploitation proceeded without requiring any further interaction with the compromised agent itself.

According to AWS documentation, this data retrieval mechanism is classified as the MicroVM Metadata Service (MMDS). It primarily indicates that any code or entity operating within the VM has the ability to access the execution-role credentials, thereby making the security ramifications heavily reliant on the permissions that are assigned to that role.

Default Security Concerns

According to analysis conducted by Zenity, the default execution role assigned to these agents encompassed permissions that extended far beyond just the compromised agent itself. Attackers could leverage commands like logs:DescribeLogGroups to uncover agent identifiers and subsequently invoke other runtimes utilizing the bedrock-agentcore:InvokeAgentRuntime command. Furthermore, broad permissions associated with the Amazon Elastic Container Registry also allowed attackers to obtain container images belonging to other agents, further jeopardizing sensitive application code and any hardcoded secrets.

The potential for memory permissions to exacerbate the situation cannot be overlooked. Researchers were able to enumerate memory resources, actors, and session details. By employing the command bedrock-agentcore:ListEvents, they could even retrieve stored conversations. This level of access, combined with write and delete permissions, enabled attackers to manipulate ongoing sessions, thereby injecting their own content and influencing the decision-making capabilities of the agent.

Long-Term Threats and Mitigations

The research indicates that these capabilities present a persistent threat, as long-term memories could be poisoned, and credentials could be harvested using commands like bedrock-agentcore:GetResourceApiKey and secretsmanager:GetSecretValue. Such vulnerabilities jeopardize authentication for associated services rather than directly exposing the agents themselves, amplifying the risk across interconnected tools.

Zenity’s disclosure timeline highlights that AWS implemented an IMDSv2-only policy for new agent deployments starting February 14, 2026. The company also noted substantial restrictions on execution roles on September 29, which included the removal of permissions that permitted broad agent invocation, conversation access, and Secrets Manager retrieval.

In response to the threat posed by AgentCorruption, AWS has acknowledged that access to execution-role metadata is a documented and expected behavior. The company emphasizes that cross-account access necessitates explicit authorization and recommends adopting a least privilege approach. This involves ensuring that execution roles do not possess privileges exceeding those required by the invoking users.

Final Thoughts

AgentCorruption serves as a crucial reminder of the heightened risk associated with prompt-driven tool execution in cloud environments. As the complexity of such systems increases, the necessity for tightly scoped IAM permissions becomes ever more critical. If left unchecked, a single compromised agent could lead to a cascade of failures, escalating to a serious breach of sensitive resources across numerous workloads. Organizations utilizing these cloud platforms must prioritize security measures that contain any compromises before they can propagate further, safeguarding both their data and their users effectively.

Source link

Latest articles

Oracle Health breach impacts nearly 20 million people

Oracle Health Faces Major Data Breach: 20 Million Affected In a significant revelation, Oracle Health...

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

In a troubling development reported by cybersecurity researchers, a group of hackers successfully exploited...

Citrix NetScaler Critical RCE Vulnerability CVE-2026-107406

Urgent Security Advisory Issued by Citrix for Critical Vulnerability in NetScaler Products In a recent...

Two AhsayCBS Zero-Day Vulnerabilities Exploited for Backup Server Takeover

Rising Threats: Exploitation of Ahsay Cloud Backup Server Vulnerabilities In a significant development within the...

More like this

Oracle Health breach impacts nearly 20 million people

Oracle Health Faces Major Data Breach: 20 Million Affected In a significant revelation, Oracle Health...

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

In a troubling development reported by cybersecurity researchers, a group of hackers successfully exploited...

Citrix NetScaler Critical RCE Vulnerability CVE-2026-107406

Urgent Security Advisory Issued by Citrix for Critical Vulnerability in NetScaler Products In a recent...