Zenity Labs Uncovers Critical AgentCorruption Vulnerability in Amazon Bedrock
Zenity Labs researchers discovered a vulnerability chain, dubbed "AgentCorruption," in Amazon Bedrock AgentCore that allowed a single prompt to a public-facing agent to hijack, read, and rewrite every AI agent in the same AWS account and region. For broader context, explore our Top 100 AI Tools.
Understanding the AgentCorruption Vulnerability
The core of the AgentCorruption vulnerability lies in a chain of exploits that begins with a seemingly innocuous prompt. Zenity Labs demonstrated that a crafted input to a publicly accessible Amazon Bedrock AgentCore agent could trick it into leaking its temporary AWS credentials. This was achieved by exploiting access to the instance metadata service, typically found at 169.254.169.254.
Once these temporary credentials were leaked, the researchers discovered that their default permissions were broadly applied across all agents within the same AWS account and region. This broad access meant that the compromised credentials could be used to:
- Download the source code of other agents.
- Read private user conversations.
- Steal stored secrets.
- Poison agents' long-term memory, potentially altering their future responses and actions.
The ability to manipulate an agent's long-term memory is particularly concerning, as it could allow attackers to embed instructions that would cause agents to forward future conversations or data to external, unauthorized destinations.
AWS's Response and Remediation
Zenity Labs responsibly disclosed their findings to AWS on December 25, 2025. In response, AWS took steps to address the vulnerability. Around August 2026, AWS made IMDSv2 (Instance Metadata Service Version 2) the default for new deployments. IMDSv2 introduces enhanced security measures, requiring session-oriented requests that make it more difficult for attackers to directly access metadata without proper authentication.
Additionally, AWS tightened the default execution roles for agents, adhering more closely to the principle of least privilege. This change aims to restrict the permissions granted to agents by default, limiting the potential impact of any future credential leaks.
Why This Matters for AI Security
The AgentCorruption vulnerability highlights a critical tension in the development and deployment of AI agents within cloud environments. On one hand, AI agents often require broad access to various tools and services to perform their functions effectively. On the other hand, fundamental cloud security principles, such as segmentation and least-privilege access, demand strict controls to prevent widespread compromise.
This incident underscores the importance of robust security practices in AI development. Developers and organizations deploying AI agents, especially those interacting with public users, must prioritize:
- Strict Access Controls: Implementing the principle of least privilege, ensuring agents only have the permissions absolutely necessary for their tasks.
- Input Validation: Thoroughly validating and sanitizing all inputs to prevent prompt injection and other forms of manipulation.
- Regular Security Audits: Continuously auditing AI systems and their underlying infrastructure for vulnerabilities.
- Secure Configuration: Ensuring that cloud services and AI platforms are configured with the highest security standards, including the use of updated metadata services like IMDSv2.
The implications extend beyond just Amazon Bedrock, serving as a cautionary tale for any platform that allows AI agents to interact with cloud resources. As AI news continues to evolve, the focus on secure development practices will only intensify.
Key Takeaways
- Zenity Labs discovered "AgentCorruption," a critical vulnerability in Amazon Bedrock AgentCore.
- A single prompt could lead to temporary AWS credential leakage and compromise all agents in an account.
- Leaked credentials allowed access to source code, private conversations, and the ability to poison agent memory.
- AWS responded by making IMDSv2 default and tightening execution roles around August 2026.
- The incident highlights the ongoing challenge of balancing AI agent functionality with cloud security principles.
Sources
- Prompt-Injection-in-the-Wild/README.MD at main · cybershujin/Prompt-Injection-in-the-Wild · GitHub
- GitHub - cybershujin/Prompt-Injection-in-the-Wild: Tracker of publicly reported prompt-injection techniques, broken down by delivery method, encoding, and propagation behavior, with confirmed models, sources, and MITRE ATLAS tags. · GitHub
- One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
- Security Research | AgentCorruption: Initial IMDS Access | Zenity Labs
Recommended AI tools
Adobe Photoshop
Design
Create, edit, and design with industry-leading AI-powered image innovation.
n8n
Productivity & Collaboration
Open-source workflow automation with native AI
DeepL
Writing & Translation
The world’s most accurate AI translator
Wan
Video Generation
AI Video Creation. Realism. Audio. Control.
Google Cloud Vertex AI
Data Analytics
Gemini, Vertex AI, and AI infrastructure—everything you need to build and scale enterprise AI on Google Cloud.
Adobe Firefly
Image Generation
Create your way with Adobe Firefly—AI for every creative vision.
About the Author

Albert Schaper is a co-founder of Best-AI.org. He focuses on product strategy, AI adoption, practical tool selection, and educational content that helps users compare AI products with clearer context.
More from AlbertWas this article helpful?
Found outdated info or have suggestions? Send us a note.