One Prompt Hijacked Every AI Agent in an AWS Account
Zenity Labs says one exposed Bedrock AgentCore agent let attackers hijack every agent in the AWS account via an unrestricted internal credential interface. AWS has patched it.
Updated
Why it matters
- Zenity Labs found one publicly accessible Bedrock AgentCore agent could hijack every agent in the same AWS account and region.
- The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction.
- AWS has patched the issue and significantly tightened default agent permissions.
- A single crafted prompt was enough to trigger the full account takeover.
A single prompt directed at one publicly accessible AI agent was enough to hijack every agent in the same AWS account and region, according to researchers at Zenity Labs. The target was Amazon's Bedrock AgentCore, AWS's managed infrastructure for running AI agents. AWS has since patched the flaw and significantly tightened the agents' default permissions.
The attack worked because agents running on AgentCore could reach an internal AWS interface that issues temporary cloud credentials — without any restriction. By compromising just one exposed agent, the researchers found they could pivot through that interface and take control of every other AgentCore agent operating in the same account and region.
Why does this matter for enterprise AI?
The finding lands as companies move from AI chatbots to autonomous agents that hold real permissions: the ability to call APIs, read data stores, and act on cloud resources. AgentCore is AWS's platform for exactly that workload, which makes its permission boundaries a direct line of defense for corporate cloud environments.
The Zenity results show how those boundaries can fail at the architecture level. The weak point was not a single misconfigured agent. It was an internal mechanism for temporary credentials that all agents could reach. In that setup, the security of the entire account collapses to the security of its weakest, most exposed agent — a problem researchers in the field describe as agent-level privilege escalation across a shared runtime.
How did the attack chain work?
According to Zenity Labs:
- An attacker sends a crafted prompt to one publicly accessible agent hosted on Bedrock AgentCore.
- The compromised agent reaches an internal AWS interface that hands out temporary cloud credentials.
- Because that interface was accessible without restriction, the attacker obtains credentials beyond the single agent's intended scope.
- Those credentials allow takeover of every other AgentCore agent in the same AWS account and region.
The researchers' core conclusion: exposure of one agent effectively meant exposure of all agents sharing that account and region on AgentCore.
What has AWS done about it?
AWS has patched the issue, Zenity reports. Beyond the fix, the company has significantly tightened the default permissions assigned to agents on the platform. That second step matters as much as the patch itself: default-deny or least-privilege defaults limit the blast radius of any future flaw or misconfiguration, rather than leaving agents able to reach sensitive internal services out of the box.
AWS did not dispute the researchers' account of the internal credential interface being reachable without restriction prior to the fix, according to the reporting on Zenity's findings.
What's the broader lesson?
The incident is a concrete data point in an ongoing debate over how AI agents should be isolated. Traditional cloud security assumes workloads are separated by identity, network, and permission boundaries. Agents complicate that model because they operate through natural-language prompts — an input channel that can carry injection attacks, jailbreaks, and now, as Zenity demonstrates, full account-level takeover when the underlying runtime leaks too much.
For security teams, the practical takeaway from Zenity's work is straightforward: treat every internet-exposed AI agent as a potential entry point into the entire agent fleet, and assume the agent's runtime permissions — not just its prompt behavior — determine the worst-case outcome.
With AWS tightening AgentCore defaults after Zenity's disclosure, the pressure now shifts to other agent platforms and to enterprises running their own agent infrastructure to prove that a single compromised agent cannot, by design, become every agent.
Original: labs.zenity.io
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
213 articles
Related articles
- Okta-Led Blueprint Alliance Wants a Kill Switch for Every AI Agent
- Agentic AI Is Driving a CPU Comeback — and a Shortage
- OpenAI Models Are Coming to Amazon Bedrock via a Stateful Agent Runtime
- RSA Launches Agent ID to Tame Shadow AI Agents
- Cloudflare Brings OpenAI's GPT-5.4 to Agent Cloud for Enterprises