Zenity Labs discloses the AgentCorruption flaw chain in Bedrock AgentCore
10/08/2026 — 10/08, 23:21·2 sources (all)·2 reports (all)
Key takeaways
- Zenity Labs disclosed AgentCorruption, a vulnerability chain in Amazon Bedrock AgentCore in which a single publicly reachable AI agent could…
Background & analysis
On October 8, 2026, security firm Zenity Labs disclosed a vulnerability chain affecting Amazon Bedrock AgentCore and named it AgentCorruption. According to The Decoder, the researchers said that a single publicly accessible AI agent in an AWS account and region was enough to take over every AgentCore agent in that same account and region. The attack abused an internal AWS interface for issuing temporary cloud credentials, which agents could reach without restriction. The report said the chain could be triggered with just one prompt and could expose private conversations, source code, and stored credentials. Amazon Bedrock AgentCore is AWS's platform for running enterprise AI agents, offering tools, memory, and access management.
Later the same day, The Next Web reported the same findings: Zenity Labs used a single prompt sent to one public-facing AI agent on Amazon Bedrock AgentCore to take over every AgentCore agent in the same AWS account and region. That report added timing and venue details, saying the research was published on Thursday and presented in a talk at the SecTor 2026 conference in Toronto.
Both reports stated that AWS has since patched the issue and significantly tightened the agents' default permissions. The public record currently stops there: the flaw has been fixed, default permissions have been tightened, and Zenity Labs' research has been published and shared at the conference.
AI-generated from 2 reports · updated 56 minutes ago
Latest turnSecurity researchers at Zenity Labs say a single prompt sent to one public-facing AI agent on Amazon Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The firm published the research on Thursday and presented it at the SecTor 2026 conference in Toronto.
- Heat index
- 186
- All sources
- 2
- All reports
- 2
- First seen
- 3 hours ago
Reports on this story headlines open the original
Security researchers at Zenity Labs say a single prompt sent to one public-facing AI agent on Amazon Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The firm published the research on Thursday and presented it at the SecTor 2026 conference in Toronto.
The Next WebAI score 68Zenity Labs says one publicly accessible AI agent on Amazon Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The AgentCorruption flaw chain required only a single prompt and exposed private conversations, source code and stored credentials; AWS has patched the issue and tightened default agent permissions.
The DecoderAI score 65
Other stories people are talking about
- Heat index 571SurgeManus parent Butterfly Effect raises over $500M7 sources
- Heat index 520RisingAnthropic Launches Claude Haiku 5.5 and Cuts Sonnet 5.5 Cache Pricing8 sources
- Heat index 461NewGoogle Cloud launches Gemini agent for enterprise tasks5 sources
- Heat index 346OpenAI Math Release Draws Backlash; Human Mathematics Society Urges Halt to Collaboration8 sources
- Heat index 270Meta Muse AI Agent Headed to Windows5 sources
How is heat calculated?About the methodHide
Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.
This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source. If you believe a headline or summary infringes your rights, email the contact address in the footer with the page URL and basis of your claim, and we will remove or replace it after review.
- Surge
- Discussion rising fast
- New
- First report within 6 hours
- Rising
- Still gathering discussion
