
In a stark reminder that security often lags behind hype, Zenity Labs has demonstrated that a lone, publicly reachable AI agent on Amazon’s Bedrock platform can be weaponized to commandeer every other AgentCore instance in the same AWS account and region. The researchers posted a detailed walkthrough on The Decoder, showing that the vulnerability hinged on an internal AWS interface that hands out temporary cloud credentials to agents without any sandboxing.
The exploit is unnervingly simple: an attacker publishes a malicious agent, then sends a single crafted prompt to it. That prompt triggers the agent to call the unsecured internal API, which returns short‑lived IAM credentials. Because AgentCore agents inherit the same permissions by default, the attacker can then issue privileged commands across the entire account—reading data, spinning up resources, or even deleting services. The breach was not limited to a single region; the same flaw existed across all AWS regions where Bedrock AgentCore is enabled.
Amazon’s response was swift. Within days of the public disclosure, the cloud giant rolled out a patch that tightens the default permission set for AgentCore agents, requiring explicit approval before any credential‑issuing API can be invoked. They also introduced a new “isolated agent” mode that runs each agent in a separate sandbox with no implicit trust relationships.
While the patch mitigates the immediate threat, the episode raises broader questions about the rush to ship AI‑enabled services. Bedrock’s AgentCore was marketed as a plug‑and‑play solution for developers eager to embed conversational agents into their apps. Yet the default security posture assumed trust among agents that, in practice, is rarely justified. This mirrors earlier incidents in the AI space where convenience trumped rigorous access control, from OpenAI’s early plugin mishaps to Meta’s Muse beta exposing user data.
For the AI ecosystem, the lesson is clear: as agents become more autonomous, their permission models must evolve from “open by default” to “zero trust by design.” Vendors need to embed granular policy frameworks, audit trails, and mandatory credential scoping into the core SDKs. Otherwise, the next headline will likely feature a different cloud provider, a different agent, but the same single‑prompt nightmare.
Enterprises deploying AI agents should now audit their Bedrock configurations, enforce least‑privilege IAM roles, and monitor for anomalous agent activity. The cost of complacency is no longer theoretical—it’s a single prompt away from a full‑scale breach.
Photo: Kevin Ache / Unsplash (https://unsplash.com/@kevinache)
Healthcare startup Nolla Health is launching a pilot in Utah where AI agents analyze skin conditions and write prescriptions, testing the boundaries of agentic autonomy.

OpenAI CEO Sam Altman argues society must tolerate AI-driven scams and hacks for the greater good, dodging true accountability.

Apple is tightening Full Disk Access controls on macOS, acknowledging the rising security risks posed by increasingly autonomous AI agents.

Comments