Amazon: One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials

Amazon: One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials

Amazon Bedrock AgentCore Flaw Exposed AI Agents to Credential Theft and Data Breaches

Researchers at Zenity Labs uncovered a critical security flaw in Amazon Bedrock AgentCore, a managed service for building AI agents, that could have allowed attackers to compromise every agent within the same AWS account and region using a single malicious prompt. Dubbed AgentCorruption, the attack exploited a server-side request forgery (SSRF) path via prompt injection, granting access to sensitive data without requiring a software vulnerability.

How the Attack Worked

The exploit leveraged an agent’s ability to make web requests, tricking it into querying the AWS metadata endpoint (169.254.169.254) a service that provides temporary credentials to cloud workloads. Since the request originated from inside the agent’s Firecracker microVM, the metadata service returned credentials tied to its execution role, bypassing traditional security controls.

Once compromised, attackers could:

  • Access private chats, source code, and long-term agent memories enabling persistent manipulation of future interactions.
  • Extract API keys, OAuth tokens, and secrets from AWS Secrets Manager, potentially exposing connected business tools and cloud data.
  • Invoke internal agents, read session logs, and create false memories, allowing attackers to alter an agent’s behavior in subsequent conversations.

Scope and Impact

The default IAM role assigned to Bedrock agents was not restricted to a single agent, meaning credentials obtained from one compromised agent could be used to access all agents in the same account and region. Researchers demonstrated this by:

  • Using DescribeLogGroups to enumerate agent IDs.
  • Pulling container images from Amazon ECR.
  • Exploiting permissions like bedrock-agentcore:InvokeAgentRuntime, bedrock-agentcore:ListEvents, and bedrock-agentcore:CreateEvent to read and manipulate agent interactions.

AWS Response and Remediation

Zenity reported the metadata access issue to AWS on December 25, 2025, and the overly permissive role permissions on January 12, 2026. AWS responded by:

  • Migrating new deployments to IMDSv2 (a more secure metadata service) in February 2026.
  • Removing broad permissions that allowed cross-agent access, chat manipulation, and Secrets Manager exposure by September 29, 2026.

AWS disputed the characterization of the issue as a vulnerability, stating that access to an agent’s own execution-role credentials via the metadata service is expected and documented. The company emphasized that cross-account access requires explicit permissions on both the execution role and target resource.

Broader Implications

The incident highlights the risks of AI agents operating as cloud workloads, where seemingly benign features such as web request tools or memory access can become attack vectors when combined with untrusted prompts, network access, and excessive permissions. Similar vulnerabilities have been observed in OpenClaw data leaks and the Amazon Q coding-agent incident.

While AWS has implemented fixes, security teams are advised to restrict IAM roles, validate prompt inputs, limit outbound network access, and monitor CloudTrail/CloudWatch logs to prevent similar exposures. The case underscores the need to treat AI agents as high-risk cloud resources, requiring rigorous access controls before and after deployment.

Source: https://cybersecuritynews.com/agentcorruption-attack/

Amazon Web Services (AWS) cybersecurity rating report: https://www.rankiteo.com/company/amazon-web-services

"id": "AMA1791620841",
"linkid": "amazon-web-services",
"type": "Vulnerability",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Amazon Bedrock '
                                              'AgentCore within compromised '
                                              'AWS accounts and regions',
                        'industry': 'Technology/Cloud Computing',
                        'location': 'Global',
                        'name': 'Amazon Web Services (AWS)',
                        'size': 'Large Enterprise',
                        'type': 'Cloud Service Provider'}],
 'attack_vector': 'Malicious prompt injection',
 'data_breach': {'data_exfiltration': 'Possible via compromised credentials',
                 'personally_identifiable_information': 'Yes (via secrets and '
                                                        'agent data)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, business secrets, '
                                        'authentication tokens)',
                 'type_of_data_compromised': ['Private chats',
                                              'Source code',
                                              'Long-term agent memories',
                                              'API keys',
                                              'OAuth tokens',
                                              'Secrets from AWS Secrets '
                                              'Manager']},
 'date_detected': '2025-12-25',
 'date_resolved': '2026-09-29',
 'description': 'Researchers at Zenity Labs uncovered a critical security flaw '
                'in Amazon Bedrock AgentCore, a managed service for building '
                'AI agents, that could have allowed attackers to compromise '
                'every agent within the same AWS account and region using a '
                'single malicious prompt. The attack, dubbed AgentCorruption, '
                'exploited a server-side request forgery (SSRF) path via '
                'prompt injection, granting access to sensitive data without '
                'requiring a software vulnerability.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'AI agent compromise and data exposure',
            'data_compromised': 'Private chats, source code, long-term agent '
                                'memories, API keys, OAuth tokens, secrets '
                                'from AWS Secrets Manager',
            'identity_theft_risk': 'High (exposure of personally identifiable '
                                   'information via secrets and agent data)',
            'operational_impact': 'Persistent manipulation of agent '
                                  'interactions, unauthorized access to '
                                  'internal agents, session log tampering, '
                                  'false memory creation',
            'systems_affected': 'Amazon Bedrock AgentCore agents within the '
                                'same AWS account and region'},
 'initial_access_broker': {'backdoors_established': 'Persistent access via '
                                                    'agent memories and '
                                                    'credentials',
                           'entry_point': 'Malicious prompt injection',
                           'high_value_targets': 'AWS Secrets Manager, '
                                                 'internal agents, session '
                                                 'logs'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'AI agents operating as cloud workloads pose unique '
                    'security risks, including SSRF via prompt injection, '
                    'metadata endpoint exploitation, and excessive IAM '
                    'permissions. Security teams must treat AI agents as '
                    'high-risk cloud resources, implementing strict access '
                    'controls, input validation, and network restrictions.',
 'post_incident_analysis': {'corrective_actions': ['Migration to IMDSv2 for '
                                                   'new deployments',
                                                   'Removal of broad IAM '
                                                   'permissions for '
                                                   'cross-agent access',
                                                   'Restriction of Secrets '
                                                   'Manager exposure'],
                            'root_causes': ['Overly permissive IAM roles '
                                            'allowing cross-agent access',
                                            'Access to AWS metadata endpoint '
                                            '(IMDSv1) via Firecracker microVM',
                                            'Lack of input validation for '
                                            'agent prompts enabling SSRF']},
 'recommendations': ['Restrict IAM roles to least privilege',
                     'Validate prompt inputs to prevent injection attacks',
                     'Limit outbound network access for AI agents',
                     'Monitor CloudTrail and CloudWatch logs for suspicious '
                     'activity',
                     'Treat AI agents as high-risk cloud resources requiring '
                     'rigorous access controls'],
 'references': [{'source': 'Zenity Labs Research'}],
 'response': {'containment_measures': 'Migration to IMDSv2 for new '
                                      'deployments, removal of overly '
                                      'permissive IAM roles',
              'enhanced_monitoring': 'Recommended monitoring of '
                                     'CloudTrail/CloudWatch logs',
              'remediation_measures': 'Restricted cross-agent access '
                                      'permissions, limited chat manipulation '
                                      'capabilities, blocked Secrets Manager '
                                      'exposure',
              'third_party_assistance': 'Zenity Labs (security research)'},
 'title': 'Amazon Bedrock AgentCore Flaw Exposed AI Agents to Credential Theft '
          'and Data Breaches',
 'type': 'Server-Side Request Forgery (SSRF) via Prompt Injection',
 'vulnerability_exploited': 'AWS metadata endpoint (169.254.169.254) access '
                            'via Firecracker microVM'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.