What happened
Zenity Labs researchers identified a critical security flaw in Amazon's Bedrock AgentCore service. According to the finding, a single internet-exposed AI agent was enough to take over every other AgentCore agent in the same AWS account and region.
How the attack worked
The attack targeted an internal AWS interface that issues temporary cloud credentials. Agents could reach this interface without any restrictions, meaning a single malicious prompt could cascade to other agents.
What AWS did
AWS said it patched the flaw and significantly tightened the agents' default permissions. The finding is a direct security warning for organizations running cloud-based AI agents in production.
Why it matters
Agents are increasingly embedded in enterprise workflows and operate with broad permissions. The fact that compromising one agent could spread across an entire account shows that agent security is not just a model issue but a matter of infrastructure and permission management.



