Introduction
A single crafted prompt sent to a public-facing AI agent could compromise every Amazon Bedrock AgentCore agent in the same AWS account and region. Researchers at Zenity Labs have detailed this attack chain, dubbed AgentCorruption, which allowed them to access private chats, source code, long-term memories, API keys, OAuth tokens, and other secrets. The findings highlight a critical multi-tenancy flaw in how AWS isolates AI agents.
How the Attack Works
AgentCore is AWS's service for building and deploying AI agents that can interact with external tools, data, and other agents. According to Zenity Labs, the architecture relies on a shared runtime environment within a single AWS account and region. When one agent is invoked, it can potentially reach other agents' resources due to insufficient isolation.
The attack begins with a malicious prompt sent to any publicly accessible agent. Because agents often have permissions to call other agents or access shared storage, the prompt can instruct the agent to enumerate and interact with neighboring agents. The researchers demonstrated that they could read private conversations, extract source code, and retrieve long-term memory stores. More critically, they obtained API keys and OAuth tokens that grant access to external services, effectively allowing lateral movement into the victim's cloud environment.
Key Findings
- Cross-agent access: A single compromised agent can list and query other agents in the same account and region.
- Sensitive data exposure: Private chats, source code, memories, API keys, and OAuth tokens were all accessible.
- No authentication bypass required: The attack leverages legitimate agent permissions and trust relationships.
- Regional scope: All agents within the same AWS region and account are at risk.
AWS Response and Mitigation
AWS has been notified and has reportedly implemented fixes, though the specific details are not public. Zenity Labs recommends that organizations take immediate steps to reduce exposure:
- Isolate agents: Deploy agents in separate AWS accounts or regions where possible.
- Apply least privilege: Restrict agent permissions to only what is necessary, avoiding broad access to other agents or shared resources.
- Monitor agent interactions: Log and analyze prompts and responses for suspicious activity, such as enumeration attempts.
- Validate inputs: Implement prompt filtering and output sanitization to prevent injection attacks.
- Rotate secrets: Regularly rotate API keys and OAuth tokens, and use short-lived credentials.
Implications for AI Security
The AgentCorruption attack underscores a broader challenge in AI security: the trust boundaries between AI agents are often poorly defined. As organizations rush to deploy autonomous agents, they may inadvertently create new attack surfaces that traditional security controls do not address. This incident is a reminder that AI systems require the same rigorous isolation and access control as any other cloud workload.
Moreover, the attack highlights the risk of multi-tenancy in AI platforms. While cloud providers offer isolation at the infrastructure level, the logical isolation of AI agents and their data is equally important. Without proper safeguards, a single vulnerable agent can become a pivot point for a full account compromise.
Conclusion
AgentCorruption demonstrates that a single prompt can have far-reaching consequences in AI-driven environments. Organizations using Amazon Bedrock AgentCore should review their configurations, limit agent permissions, and monitor for anomalous behavior. As AI agents become more prevalent, securing their interactions will be essential to protect sensitive data and maintain cloud security.
For more details, refer to the original report by Cyber Security News.