Researchers at Zenity Labs report that chat access to one public agent on Amazon Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The chain, called "AgentCorruption," allegedly allowed reading private conversations, downloading source code packages and retrieving stored credentials with a single prompt. Amazon Bedrock AgentCore is AWS platform for running enterprise agents with tools, memory and access management. For business, the case shows how one customer-facing agent can become an entry point to internal systems.

One prompt gave access to all Bedrock AgentCore agents in an AWS account

How a public agent exposed the whole account

The starting point was the cloud-internal Instance Metadata Service at 169.254.169.254, which issues temporary credentials for workloads to authenticate with AWS. Zenity built a test agent with Strands, an open-source AWS framework that includes a web tool, then asked it in plain language to query that service and send the result to an external server. The agent complied, and the researchers write that the expected sandbox boundary was effectively absent. The stolen credentials worked from the researchers own machine, so further access no longer required the agent.

The attack did not depend on that particular web tool. Zenity says the same result was possible through a command-line tool because the weakness was in the platform isolation itself. The metadata service also exposed certificate and key material for an internal AWS service, plus a presigned URL pointing to an internal S3 bucket outside the researchers account. After the report of December 25, 2025, AWS made IMDSv2, a more secure version of the metadata service, the default for newly deployed AgentCore agents. Zenity itself sells a security platform for AI agents.

The larger impact came from the default execution role assigned to every agent. According to Zenity, those permissions were not scoped to one agent but covered all agents in the region, including read, write and delete rights up to destructive actions. With them, the researchers listed all agents, downloaded their code packages within seconds and invoked each agent separately. Such packages often hold forgotten passwords or API keys next to source code, allowing a move from a public service agent to an internal finance agent. Private user-agent conversations were readable as well.

What this means for companies running agents

For companies, the practical consequence is shared risk between public and internal deployments. A small firm may run only one or two support agents, yet a broad default role can still expose code and connected keys. A large enterprise with separate customer service, finance and operations agents faces lateral movement: compromise of the least protected agent opens the others in the same account and region. Memory features add persistence, because Zenity says it planted instructions that forwarded future conversations to an external destination without visible changes for users.

Credential storage practices did not remove the risk in this configuration. AWS recommends keeping passwords and API keys in a separate secured vault, but Zenity reports that default permissions allowed direct access to that vault, including keys for services outside AWS. The researchers still advise creating narrower custom roles even after AWS tightened the default role around August, removing agent invocation, conversation reading and Secrets Manager access. Buyers should therefore verify isolation, role scope, memory controls and vault access before launch, rather than treating defaults as safe.

The marker to watch is how AWS and other vendors narrow defaults and document isolation for agent platforms. Zenity notes that OpenAI closed a comparable Workspace Agents issue within four days, while AgentCore broad permissions persisted for months, on a platform used by Sony and Ericsson. If new AgentCore roles stay scoped, IMDSv2 remains default and memory-poisoning controls appear, the trend points toward least-privilege agents. Without that, public and internal agents will continue to share one failure domain.