AWS Environments Left Exposed by AI-Driven Vulnerability
A recently patched vulnerability in Amazon Web Services’ (AWS) Bedrock AgentCore has left organizations using the platform at risk of a full-scale takeover. Researchers from Zenity Labs discovered that an attacker could use a single prompt to a public-facing chatbot to gain control over an entire fleet of agents, compromising sensitive data and potentially leading to memory poisoning attacks.
The issue, dubbed “AgentCorruption,” stems from a flaw in the Instance Metadata Services (IMDS) that allows agents deployed through Bedrock AgentCore to access sensitive information. IMDS contains temporary credentials, instance IDs, and configurations, which are normally isolated and protected. However, researchers found that these agents can bypass this isolation by making HTTP requests to the IMDS endpoint within the instance.
This vulnerability is not new; Zenity’s research team highlighted a similar weakness in 2019 when they discovered that attackers had used an SSRF flaw to access the EC2 instance of Capital One, leading to a major data breach. In both cases, the problem lies with the lack of least privilege implementation for the metadata service.
Zenity researchers demonstrated how easy it was to exploit this vulnerability by sending a request to the IMDS via a support agent and obtaining temporary credentials. With these credentials, they could then move laterally across an AWS environment, obtain privileged accounts, and even access secrets stored in AWS Secrets Manager. The researchers also showed that a single prompt to an over-privileged public-facing agent could lead to a full compromise of an entire AgentCore region.
The discovery of AgentCorruption is particularly concerning given the increasing reliance on cloud computing and AI-powered services. As Tamir Ishay Sharbat, director of security research at Zenity Labs, noted, “Cloud and AI are like fire and ice – they mix well, but can also lead to catastrophic consequences.”
AWS has since patched the vulnerability by updating AgentCore to use IMDSv2, which requires authentication, and altering the default role to remove overprivileged permissions. Organizations using Bedrock AgentCore should review their configurations and ensure that their agents are running with the latest security patches.
While this vulnerability is now patched, it serves as a stark reminder of the importance of implementing robust access controls and isolation in cloud environments. As we continue to integrate AI-powered services into our infrastructure, it’s essential to be aware of the potential risks and take proactive steps to mitigate them. By doing so, we can minimize the blast radius of an AgentCorruption attack and protect our sensitive data from falling victim to such exploits.
Practically speaking, organizations should prioritize implementing least privilege policies across their cloud environments and ensure that all agents are running with restricted permissions. Regularly reviewing and updating security configurations is also crucial in preventing similar vulnerabilities from arising in the future. By staying vigilant and proactive, we can safeguard our cloud infrastructure against AI-driven attacks like AgentCorruption.
Source: Dark Reading — 2026-10-08