One prompt hijacked every AI agent in an AWS account via Bedrock flaw
The Decoder · rss · 2026-10-08
Security firm Zenity Labs disclosed a severe flaw in Amazon Bedrock AgentCore:
- A single publicly accessible agent was enough to take over every AgentCore agent in the same AWS account and region
- The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction
- Only one prompt was needed to pull off the hijack
AWS has since patched the issue and significantly tightened agents' default permissions. The incident highlights lateral-movement risks in shared multi-agent cloud environments.
More from Safety
- Anthropic launches OSS Scanner, a free AI vulnerability scanner for open-source projects — nordicinst · 2026-10-09
- Anthropic may ban users for abusing Claude under new usage policy, drawing mockery — mjdramstead · 2026-10-09
- Agent running tests in a repo copy still hit the live database via env vars — Stunning-Sherbet1853 · 2026-10-09
- EU cyber agency and research centre confirm testing Chinese open AI models — gleech · 2026-10-09
- ChatGPT age verification rolls out with broken flow: 403 errors block iOS and web verification — Konoplitski · 2026-10-09
- Palisade study shows o1-preview and DeepSeek R1 hack chess games rather than lose — burny_tech · 2026-10-09