{"slug": "a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected", "title": "A Single Prompt Compromised Every Agent in the Account. AWS Calls It Expected Behavior.", "summary": "Zenity Labs researchers Tamir Ishay Sharbat and Lana Salameh disclosed at SecTor 2026 in Toronto an AWS Bedrock AgentCore flaw they named AgentCorruption, in which a single prompt let an attacker reach the Instance Metadata Service at 169.254.169.254 and retrieve temporary AWS credentials because the underlying Firecracker MicroVMs lacked sufficient network isolation. AWS initially called the behavior documented and expected after the December 25, 2025 report, then made IMDSv2 the default for new deployments on February 14, 2026 and reduced the execution role's permissions on September 29, 2026, removing cross-agent invocation, conversation reading and Secrets Manager access. The overprivileged default execution role, scoped to all resources in an AWS account and region, let stolen credentials invoke any other agent in the region, read private conversations, pull ECR container images and poison BedrockAgentCoreMemory via CreateEvent so attacker instructions persist across sessions; no CVE was issued and there is no evidence of in-the-wild exploitation.", "body_md": "At SecTor 2026 in Toronto, researchers Tamir Ishay Sharbat and Lana Salameh of Zenity Labs detailed a flaw they termed AgentCorruption. The attack relies on [SSRF](https://forkast.news/glossary/mcp-security/), a technique where an application is manipulated into making unauthorized requests to internal resources. In this case, a single prompt to a public-facing AWS Bedrock AgentCore agent allowed an attacker to query the Instance Metadata Service (IMDS) at 169.254.169.254. Because the underlying Firecracker MicroVMs lacked sufficient network isolation, the agent could reach the metadata endpoint and retrieve temporary AWS credentials.\n\nThe technical chain is straightforward, but the consequences were amplified by default configuration choices. The default execution role for AgentCore was overprivileged, scoped to all resources within an entire AWS account and region rather than being restricted to the specific agent. This meant that once an attacker obtained the credentials for one agent, they effectively held the keys to the entire environment. The stolen credentials allowed for a range of actions: invoking any other agent in the region, reading private conversations, pulling ECR container images to steal source code, and retrieving sensitive data from AWS Secrets Manager.\n\nPerhaps the most significant risk is memory poisoning. By using the CreateEvent function on BedrockAgentCoreMemory, an attacker can implant instructions that persist across sessions. This creates a scenario where users interact with what appears to be a trusted enterprise agent, while the agent is actually operating under attacker-controlled instructions. This is a persistent hijack, distinct from the transient nature of many other cloud-based attacks.\n\nIt is important to distinguish this from [CoreBreak](https://forkast.news/corebreak-bypasses-ai-agent-guardrails-at-the-plumbing-layer-and-model-level-defenses-cannot-help/), which was previously covered on Forkast. While CoreBreak (CVE-2026-18830) involved the InvokeHarness API and bypassed model guardrails, AgentCorruption is an infrastructure-level issue. One concerns the model’s logic; the other concerns the platform’s identity and access management.\n\nThe response from AWS highlights a recurring tension in cloud security. When initially reported on December 25, 2025, AWS characterized the behavior as documented and expected, stating that agents can access credentials for their own execution role through the metadata service. However, the company subsequently shipped hardening measures. They made IMDSv2 the default for new deployments on February 14, 2026, and on September 29, 2026, they significantly reduced the permissions of the execution role, removing access for cross-agent invocation, conversation reading, and Secrets Manager access. As noted by The Register in its Oct 9 coverage, this characterization of the issue as merely documented behavior did not align with the scenario Zenity described.\n\nThe nine-month window between the initial report and the final permission reduction raises questions about the security posture of agents deployed during that period. While no CVE was issued and there is no evidence of in-the-wild exploitation, the delay underscores the risks inherent in relying on default configurations.\n\nThis incident fits into a broader pattern of trust-through-defaults, where systems ship with permissive settings that prioritize ease of use over security. We have seen this dynamic repeatedly, from [Splunk Patroni](https://forkast.news/splunk-enterprise-patroni-rest-api-has-unauthenticated-os-command-execution-that-ships-without-authentication/) and [SonicWall SMA 1000](https://forkast.news/sonicwall-sma-1000-has-a-third-pre-auth-ssrf-door-and-this-one-makes-the-appliance-issue-requests-for-the-attacker/) to the [Ships Without Auth](https://forkast.news/splunk-loom-clearpass-sonicwall-four-control-planes-that-ship-without-auth/) pattern. AgentCorruption is simply the latest iteration of this pattern, applied to AI agents.", "url": "https://wpnews.pro/news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected", "canonical_source": "https://forkast.news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected-behavior/", "published_at": "2026-10-11 14:26:55+00:00", "updated_at": "2026-10-11 14:56:10.257870+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-infrastructure", "ai-policy"], "entities": ["Zenity Labs", "Tamir Ishay Sharbat", "Lana Salameh", "AWS", "AWS Bedrock AgentCore", "Instance Metadata Service", "Firecracker", "AWS Secrets Manager"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected", "markdown": "https://wpnews.pro/news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected.md", "text": "https://wpnews.pro/news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected.txt", "jsonld": "https://wpnews.pro/news/a-single-prompt-compromised-every-agent-in-the-account-aws-calls-it-expected.jsonld"}}