The Anatomy of an AgentCore Breach
Recent disclosures from security researchers at Zenity Labs have shed light on a significant vulnerability that existed within Amazon’s Bedrock AgentCore framework. The flaw allowed a user to bypass security protocols simply by interacting with an AI agent through a standard chat interface. By crafting specific prompts requesting raw JSON data from internal endpoints, researchers demonstrated that it was possible to trick an agent into exposing its temporary AWS credentials.
The vulnerability stemmed from the interaction between the AI agent and the Instance Metadata Service (IMDS). In earlier versions of AgentCore, the system relied on the older IMDSv1 protocol, which lacked the robust protective measures found in newer iterations. When an agent was prompted to retrieve data from a sensitive URL, it inadvertently returned credentials intended for the virtual machine’s underlying infrastructure, handing over the keys to the kingdom to anyone capable of initiating a conversation.
The Chain Reaction: From Chat to Full Account Takeover
Once these temporary credentials were acquired, the scope of the potential damage was substantial. Because the IAM roles assigned to these agents were initially over-provisioned, possessing the credentials did not just grant access to a single agent; it provided the ability to enumerate and control other agents within the same AWS region. This allowed for a lateral movement strategy where an attacker could pull container images from the Amazon Elastic Container Registry (ECR), inspect sensitive source code, and even manipulate the memory resources of other agent sessions.
Furthermore, the lack of sufficient network isolation within the Firecracker MicroVM environment meant that an attacker could execute Server-Side Request Forgery (SSRF) attacks. This allowed the injection of persistent changes into an agent’s behavior, effectively hijacking its goals across future interactions and enabling the unauthorized extraction of secrets stored in the AWS Secrets Manager.
Why it Matters
- Credential Exposure: The reliance on IMDSv1 made cloud instances vulnerable to simple prompt-injection attacks that bypass traditional perimeter security.
- Over-Permissioned Roles: The framework initially assigned overly broad IAM roles to agents, meaning a single compromised node could lead to the exposure of entire regional deployments.
- Remediation Timeline: While the researchers disclosed these findings in late 2025, the transition to the more secure IMDSv2 was not fully enforced until early 2026, with persistent concerns regarding over-privilege lingering for months afterward.
- AI-Specific Risks: This incident highlights the unique intersection of AI safety and cloud security, where the "intelligence" of a system can be weaponized against its own infrastructure via standard natural language prompts.
The Path to Resolution
Following a period of investigation and disclosure, AWS has implemented necessary updates to its AgentCore architecture. As of mid-February 2026, the service shifted to mandate IMDSv2, which significantly hardens the environment against the types of credential theft described in the initial reports. Additionally, broader security refinements were finalized throughout 2026 to address the issues of excessive permissions, effectively closing the window on the specific attack vector identified by Zenity researchers.
Amazon has noted that the configuration of these agents often relies on developer implementation, suggesting that secure practices remain a shared responsibility. Nevertheless, the resolution of these vulnerabilities marks a critical step forward in stabilizing the deployment of enterprise-grade AI agents within high-stakes cloud environments.











