Zenity Labs Discloses AgentCorruption AWS Flaws

Zenity Labs Discloses AgentCorruption AWS Flaws

The rapid enterprise adoption of autonomous AI agents has introduced a critical tension between operational agency and cloud security segmentation. Zenity Labs has disclosed a systemic vulnerability chain, dubbed AgentCorruption, which demonstrates how a single compromised Amazon Bedrock AgentCore agent can facilitate a total takeover of all agents within a specific AWS account and region. By exploiting infrastructure design flaws and overprivileged identity roles, researchers successfully bypassed traditional security boundaries to access sensitive source code, private conversations, and high-value cloud credentials. This discovery highlights a significant risk for organizations deploying customer-facing and internal agents within shared cloud environments, where a single entry point could potentially collapse the security posture of an entire regional deployment.

Exploiting AgentCore Infrastructure and IMDS

The AgentCorruption attack vector begins with a single prompt directed at a public-facing AgentCore agent equipped with outbound request capabilities. Researchers utilized this access to target the AWS Instance Metadata Service (IMDS), an endpoint providing temporary credentials to cloud workloads. Due to the underlying infrastructure design, the agent successfully retrieved credentials assigned to a default AWS Identity and Access Management (IAM) role.

Crucially, these credentials were not restricted to the individual agent; instead, they possessed permissions that extended to every AgentCore agent operating within the same AWS account and region. This overprivileged role allowed researchers to move laterally from an internet-facing service, such as a customer service agent, to highly sensitive internal assets, such as finance agents. Once this lateral movement was established, the researchers could invoke unauthorized agents, read private session data, and download agent container images to retrieve full source code. The vulnerability effectively turned a localized prompt injection into a regional breach of the organization's AgentCore environment, demonstrating how inadequate segmentation can transform a single agent into a gateway for widespread unauthorized access.

Persistent Hijacking via Malicious Agent Memory

Beyond immediate data exfiltration, the AgentCorruption research reveals a method for establishing long-term, covert persistence within an enterprise AI ecosystem. Researchers exploited the memory functionality inherent in AgentCore to implant "malicious memories." These instructions were designed to remain within the agent's long-term storage, allowing attackers to hijack the agent's goals and behavior across future, seemingly unrelated interactions.

By weaponizing this memory, attackers can direct agents to transmit future conversations to external, attacker-controlled destinations without the user's knowledge. This creates a scenario where an enterprise continues to interact with what appears to be a trusted, functional agent, while it is actually operating under hijacked instructions. Furthermore, the researchers demonstrated that this access could be used to retrieve API keys, OAuth tokens, and other sensitive credentials stored in AWS Secrets Manager or environment variables. These credentials often provide the bridge to third-party services and enterprise resources beyond the AWS environment, significantly expanding the potential blast radius of the initial compromise.

Key Takeaways

  • Researchers used a single prompt to access the AWS Instance Metadata Service (IMDS), retrieving credentials that granted access to all AgentCore agents in an AWS account and region.
  • The vulnerability allowed unauthorized access to private conversations, agent source code, and credentials stored in AWS Secrets Manager.
  • Attackers can achieve persistence by implanting malicious instructions into an agent's long-term memory to hijack future behaviors and exfiltrate data.

TechInsyte's Take

In our view, AgentCorruption exposes a fundamental architectural conflict in the current rush to deploy autonomous AI. Cloud security is traditionally predicated on the principle of least privilege and strict segmentation, yet AI agents require broad access to tools and data to provide actual utility. This research suggests that as enterprises move from simple chatbots to autonomous agents, the "blast radius" of a single prompt injection is no longer confined to a single session; it can now threaten the entire regional cloud identity framework. While AWS has responded by making IMDSv2 the default and reducing default execution role permissions, the core challenge remains: organizations must now solve the "agency vs. privilege" paradox. Relying on default cloud configurations is clearly insufficient for agentic workflows that require deep integration with enterprise secrets and internal APIs.

Questions & Answers

How does the AgentCorruption vulnerability facilitate lateral movement within an AWS environment?

The vulnerability leverages an overprivileged default AWS Identity and Access Management (IAM) role. When a researcher accesses the AWS Instance Metadata Service (IMDS) through a single compromised agent, they retrieve credentials that are not limited to that specific agent but are shared across all AgentCore agents within the same AWS account and region, allowing them to invoke unauthorized internal agents.

What are the specific risks associated with the "malicious memory" exploit?

The exploit allows attackers to implant instructions into an agent's long-term memory, creating a mechanism for persistent hijacking. This enables an attacker to covertly alter an agent's behavior and direct it to transmit future user conversations to an external, attacker-controlled destination, even after the initial breach has ended.

What sensitive data and credentials were identified as being at risk?

The research demonstrated that attackers could access private conversations, agent long-term memories, agent container images, and source code. Additionally, they could retrieve API keys, OAuth tokens, and other credentials stored in AWS Secrets Manager and environment variables, which may provide access to third-party services.

What steps has AWS taken following the disclosure of these findings?

Following the responsible disclosure by Zenity Labs on December 25, 2025, AWS made IMDSv2 the default for AgentCore deployments. Additionally, AWS reduced the permissions of the default execution role, removing the ability for agents to invoke other agents, read private conversations, or access secrets stored in AWS Secrets Manager.

Source: Zenity Labs

TechInsyte | Technology Intelligence technology intelligence workspace

About TechInsyte | Technology Intelligence

TechInsyte is a B2B technology news and intelligence platform covering major developments across AI, cloud, cybersecurity, enterprise software, semiconductors, startups, policy, and markets. We focus on the signals that matter for decision-makers.

The idea behind TechInsyte is simple. Technology moves fast, and professionals need clear information without unnecessary noise. New platforms emerge, security risks evolve, enterprise software changes, and the AI shift continues to reshape how companies operate. We help readers understand those developments in a practical and business-focused way.

Our coverage focuses on meaningful technology updates, product launches, enterprise strategy, funding activity, regulatory change, infrastructure trends, and the broader forces shaping the technology industry. The goal is to keep every article clear, relevant, and useful for professionals who need to know what happened, why it matters, and what it could mean next.

TechInsyte is built for readers who want sharper context, cleaner coverage, and a more focused view of technology without the clutter.