One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restrictio…
Read the full story at The Decoder ↗
Timeline · 1 report
- 2026-10-08 13:01 · The Decoder
One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region