Urgent.News

What's breaking now, across thousands of outlets.

Tech

AWS AgentCore security undone by prompt requesting credentials

Tokens transmitted in metadata, weak VM isolation, and expansive permissions make hacking a lot easier

AWS AgentCore security undone by prompt requesting credentials

Bob, likely the same individual who frequently converses with Alice and draws the attention of a lurking Eve, was exploring a website known as TechHub. This platform hosts an AI agent powered by Amazon Bedrock's AgentCore. During his exploration, Bob inquired of the agent about the content of a URL, which happened to be a credential endpoint.

The agent returned data from the Instance Metadata Service (IMDS), a service that provides metadata about cloud instances and virtual machines from AWS, Azure, and Google Cloud Platform providers. This metadata includes information such as region and availability zone, subnets, system images, security groups, public keys, and potentially sensitive data like user data and security tokens.

At the time of Bob's inquiry, Bedrock AgentCore was still utilizing IMDSv1, which did not offer the same level of security as IMDSv2. Consequently, the metadata transmitted by the helpful agent included the agent's temporary credentials. Bob then downloaded these credentials onto his local machine and used them to enumerate the company's other agents in the same AWS region.

With these stolen credentials, Bob gained access to Amazon Elastic Container Registry (ECR), pulled the agent container images, and executed each as root to review the source code. Utilizing the temporary credentials, Bob was also able to discover the memory resources available in that AWS region, including those used by agents.

By analyzing this information, he was able to extract users and their agent sessions, which included their conversations. Researchers at Zenity Labs brought this issue to AWS's attention in December 2025. In their disclosure, they revealed that agents deployed through AgentCore could access their instance's IMDS endpoints. This meant that an external attacker, armed with only chat access to a single exposed agent, could request a single prompt, extract the agent's IMDS credentials, and exploit them to take control of all AgentCore agents within the same AWS account and region.

The researchers explained that the issue stemmed from the Firecracker MicroVM used by AgentCore failing to provide adequate network isolation. This allowed an attacker, in this case identified as Bob, to orchestrate a server-side request forgery (SSRF) attack. By doing so, Bob could obtain temporary AWS credentials linked to the IAM role assigned to the workload.

Given that the default AgentCore role was overly permissive, granting access to all AgentCore resources in the region instead of a single agent, any individual possessing these temporary IAM credentials could launch additional agents, read session data, modify agent memories, and retrieve secrets from AWS Secrets Manager. Leveraging these IMDS credentials, Bob was able to send direct API requests to create new memories across different agents and users.

These manipulated memories would persistently alter the agents' behavior and hijack their goals in future sessions. The Zenity Labs researchers relayed Bob's account of events to AWS in December 2025. Following this, they provided more detailed information about AgentCore's overprivileged status in January 2026. AWS acknowledged the researchers' report as "informative" and closed the security report on April 12, 2026.

However, it was noted that as of February 14, 2026, AgentCore had been updated to exclusively use IMDSv2. Despite this update, AgentCore's excessive permissions remained in place until June 22, 2026, when Zenity Labs confirmed the issue had not yet been remediated. A final review conducted by Zenity on September 29, 2026, revealed that AWS had addressed the identified problems, resolving the security concerns that had jeopardized the integrity of AgentCore agents.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Friday 9 October →