Researchers at Zenity Labs disclosed on October 8, 2026 an attack against Amazon Bedrock AgentCore: with a single publicly reachable agent, an attacker using one plain-language prompt could make it surrender its own cloud credentials, with a path to every AgentCore agent in the same AWS account and region. AWS has since patched the issue and significantly tightened the agents' default permissions.
The agent mailed out its own credentials
Cloud environments run an internal metadata service that issues temporary credentials to workloads; whoever holds those credentials can act with that workload's identity. An AI agent should never be able to reach it. According to Zenity's technical write-up, AgentCore lacked the expected isolation: the researchers built a test agent with Strands, AWS's open-source framework, using its built-in web tool, then simply asked it to query the metadata service and send the results to an external server — and it complied. The stolen credentials worked from a machine outside the platform, so the attacker no longer needed the agent at all. The metadata service also exposed certificate and key material for an internal AWS service, plus a presigned URL for internal storage that did not belong to the researchers' account.
Not one tool's fault — a missing platform boundary
Zenity stresses that removing the web tool would not have stopped the attack, because the gap sat in the platform itself; the team also reproduced the path through a command-line tool. They describe the problem as systemic, affecting agents with built-in tools across multiple AWS accounts. This differs from ordinary prompt injection: prompt injection tricks the model, but here the sandbox boundary itself was absent — the model was only the messenger, and the door was never locked.
AWS's fix, and a checklist for teams
AWS patched the issue after disclosure and tightened default permissions for agents. For teams running AgentCore or similar hosted agent platforms, the disclosure suggests a clear audit order: first, verify that an agent runtime cannot reach the cloud metadata service at all; second, keep agent credentials on least privilege, because the blast radius of a leak is set by those permissions; third, treat every publicly reachable agent as handling untrusted input by default, and review any tool that can trigger outbound requests separately. Once agents carry real business access, their credentials become the new attack surface — the value of this disclosure is drawing that boundary before a real incident does.