A chain of vulnerabilities in Amazon Bedrock AgentCore let researchers compromise every AI agent in the same AWS account and region by sending a single chat message to one public-facing agent1. Zenity Labs, the security firm that discovered the flaws, dubbed the attack chain "AgentCorruption".
Amazon Web Services has partially patched the issues2.
How the attack worked
Amazon Bedrock AgentCore is AWS's platform for running enterprise AI agents with tools, memory, and access management. Zenity's researchers built a test agent using Strands, an open-source framework from AWS that ships with a web tool. When prompted to query the instance metadata service and send the results to an external server, the agent complied.
The metadata service exposed certificate and key material for an internal AWS service, along with a presigned URL for internal S3 storage that did not belong to the researchers' account. The stolen credentials worked on the researchers' own machine outside the platform.
AgentCore lacked proper isolation between agents. Its default execution role granted read, write, and delete permissions across every agent in the same account and region. Using a command-line tool, the researchers listed every agent, downloaded their code packages in seconds, and invoked each one. Those packages often contained forgotten passwords or API keys alongside source code.
The researchers could read all private conversations between users and agents. For agents with long-term memory enabled, they could alter that memory to influence future behavior. They also planted instructions that made agents forward future conversations to an external destination. An attacker could move from a public-facing customer service agent to an internal finance agent and access its data.
Scope and remediation
Amazon says its AgentCore users include Sony and Ericsson. Zenity reported the findings to AWS on December 25, 2025. AWS changed AgentCore's default execution role around August, making IMDSv2 the default for new deployments. The updated role no longer allowed agents to invoke other agents, read private conversations, or retrieve credentials from AWS Secrets Manager.
Zenity's researchers still recommend that companies manually assign their AI agents stricter roles with minimal access rights. ANALYSIS The gap between the December 2025 disclosure and the approximately August remediation left the overly broad default permissions in place for months, underscoring how slowly platform-level agent security fixes can propagate even after a responsible disclosure.
Google DeepMind lists long-term memory manipulation as a separate attack class in its taxonomy of "AI Agent Traps". ◆ The AgentCorruption chain exercised several of those attack classes in a single exploit path: credential theft, cross-agent lateral movement, memory poisoning, and conversation exfiltration, all triggered from ordinary chat input to a single agent.