One prompt steals cloud creds: AWS AgentCore chain exposes agents and secrets

Haunting_Ganache_850 · reddit · 2026-10-10

Zenity disclosed an AWS AgentCore attack chain two days ago: an exposed AI agent can be prompted to query its own AWS metadata service and return its temporary credentials — which reportedly had enough permissions to reach other agents, conversations, container images, secrets, and even write long-term agent memories.

The poster argues the real issue isn't the SSRF — metadata services and IAM have been mishandled for years — but putting an AI agent in front of them: everyone works on making models recognize malicious instructions while the agent underneath still holds network access, cloud credentials, and tools with a spectacular blast radius. Detection is hard too: the first interesting connection is to the metadata IP, and afterwards everything accessed is AWS itself, so DNS and IP reputation are useless. The better question: why could an untrusted conversation exercise these capabilities at all? The model should never be part of the security boundary.

Original post →

More from coding & agent

coding & agent channel →