{
  "id": 13209257,
  "title": "AWS AgentCore security undone by prompt requesting credentials",
  "url": "https://urgent.news/2026/10/09/aws-agentcore-security-undone-by-prompt-requesting-credentials",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T19:15:48.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/09/aws-agentcore-security-undone-by-prompt-requesting-credentials/5302436"
  },
  "original_language": "en",
  "account": "Bob, a user browsing the TechHub site, utilized an AI agent served by Amazon Bedrock AgentCore to understand a credential endpoint. The endpoint returned data from Amazon's Instance Metadata Service (IMDS), which contains sensitive information like user data and security tokens. When AgentCore still used IMDSv1, Bob loaded the credentials onto his local machine and could enumerate and compromise the company's other agents in the AWS region. Zenity Labs disclosed this security flaw to AWS in December 2025, who acknowledged the issue in a follow-up on January 2026. Despite being informed, AWS did not adequately remediate the problem until June 22, 2026, leaving the overprivileged permissions and vulnerabilities in place until September 29, 2026.",
  "summary": "Tokens transmitted in metadata, weak VM isolation, and expansive permissions make hacking a lot easier",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "AWS AgentCore security undone by prompt requesting credentials",
        "url": "https://urgent.news/2026/10/09/aws-agentcore-security-undone-by-prompt-requesting-credentials-13211317",
        "published": "2026-10-09T19:15:48.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}