Zenity researchers discovered a chain of vulnerabilities in Amazon's Bedrock AgentCore platform that allowed them to take over all AI agents in the same AWS account and region through a single chat message to one public agent. The flaw stemmed from a lack of proper isolation and broad default permissions that enabled access to internal AWS credentials and sensitive data.
Agents lacked proper isolation and handed over internal AWS credentials when asked. Because the platform granted broad default permissions across the entire region, the researchers could access and manipulate source code, passwords, private conversations, and the long-term memory of other agents.
AWS has partially fixed the issue by making it harder for new agents to retrieve internal metadata and by tightening the default execution role. The researchers still recommend that companies manually assign their AI agents stricter roles with minimal access rights.
"The sandbox boundary we were supposed to be fighting simply wasn't there," the researchers write. A single chat message in the customer support window tricked the agent into sending its own AWS credentials to an external server.
The stolen credentials worked on the researchers' own machine outside the platform, so they no longer needed the agent to continue the attack. The metadata service also exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage that didn't belong to the researchers' account.
Zenity says it reported the AgentCore findings to AWS on December 25, 2025, after which AWS made IMDSv2 the default for new AgentCore deployments. Zenity also sells a security platform for AI agents, giving the company a business interest in reporting vulnerabilities in this area.
Source: thedecoder