cd /news/ai-agents/a-single-prompt-was-enough-to-hijack… · home › topics › ai-agents › article
[ARTICLE · art-147575] src=the-decoder.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

Zenity Labs researchers found that a single prompt to one publicly accessible AI agent on Amazon Bedrock AgentCore could hijack every AgentCore agent in the same AWS account and region, exploiting an internal AWS interface for temporary cloud credentials that agents could reach without restriction. AWS has since patched the issue and significantly tightened the agents' default permissions.

by read1 min views1 publishedOct 8, 2026

Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction. AWS has since patched the issue and significantly tightened the agents' default permissions.

The article A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found appeared first on The Decoder.

── more in #ai-agents 4 stories · sorted by recency
── more on @zenity labs 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-single-prompt-was-…] indexed:0 read:1min 2026-10-08 · —