Lotu Radar About

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

The Decoder AI Score 7/10
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

Summary

Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction. AWS has since patched the issue and significantly tightened the agents' default permissions. The article A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found appeared first on The Decoder .

AIResearch

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.