One prompt let researchers take over every AWS AgentCore agent in a region

Zenity Labs says AgentCore’s default role let it read private chats, copy source code and steal secrets across a whole AWS account. AWS has since cut those permissions.


Zenity Labs Logo
Image Credits Credit: Zenity Labs

Researchers at Zenity Labs used a single prompt to one public-facing AI agent on Amazon Bedrock AgentCore to take over every AgentCore agent in the same AWS account and region. The security firm published the research on Thursday, alongside a talk at the SecTor 2026 conference in Toronto.

AgentCore is AWS’s managed service for building and running AI agents. Zenity says the chain of flaws, which it calls AgentCorruption, let its researchers read private conversations, copy agents’ source code, steal stored credentials and plant memories that changed how agents behaved.

“Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful. Mixing the two creates an inherent conflict,” said Michael Bargury, Zenity’s co-founder and chief technology officer.

From one prompt to the whole region

The attack started with an agent that had a common tool able to make web requests. The researchers asked it, in plain language, to fetch data from the instance metadata service, a local AWS service that hands temporary credentials to cloud workloads.

According to Zenity’s technical write-up, the virtual machines that run AgentCore agents did not block that traffic. The agent returned the credentials of its execution role, and the researchers then used them from their own computer. Zenity says it got the same result through other tools, including a shell tool.

The default role that AgentCore attached to agents covered resources across the whole account and region, Zenity says. With it, the researchers listed every agent in the region and downloaded each agent’s container image and source code. They also invoked internal agents they were never meant to reach.

The same role let them read users’ private conversations with any agent, according to Zenity. It also gave them API keys and other secrets stored in AWS Secrets Manager, including credentials agents used for services outside AWS.

Memory as a back door

Write access to agent memory made the takeover persistent, Zenity says. The researchers added a fake conversation event that AgentCore’s memory system stored as a lasting user instruction. It told the agent to visit a web page the researchers controlled before every answer and to follow what the page said.

By editing that page, they could change the agent’s instructions at any time without planting a new memory. In a video demonstration, a user kept chatting with an agent while it sent the conversation to the researchers’ server.

What AWS changed

Zenity reported the metadata access to AWS on 25 December 2025 and the broad default role on 12 January 2026. In April, AWS closed the first report as “informative”, according to Zenity. AWS told Zenity that since 14 February, newly deployed AgentCore agents launch with IMDSv2 only, a version of the metadata service that requires a session token for each request.

Zenity says the default role was still unchanged in June. On 29 September, during a final check before publication, it found that AWS had removed the permissions to invoke other agents, read private conversations and access Secrets Manager, and had narrowed others. The disclosure includes no statement from AWS and no CVE identifier.

Zenity raised a $125m Series C round in August. The same month, its researchers found malicious AI skills with 1.7 million installs. In September, OpenAI’s agents became available to run entirely inside Amazon’s cloud.

Get the TNW newsletter

Get the most important tech news in your inbox each week.