One prompt to a single agent returned the credentials for every agent in the same AWS account and region.
Zenity Labs published the chain on October 8 and named it AgentCorruption. Here is the short version.
- The agent ran in a Firecracker MicroVM that did not block the instance metadata endpoint at 169.254.169.254.
- Any agent tool that could fetch a URL could fetch the agent’s own temporary credentials.
- The default execution role spanned every agent in the region, so those credentials unlocked all of them.
- The researchers read private conversations, wrote long-term memories to hijack later runs, and read secrets.
- AWS says the behavior is documented and expected. It narrowed the default role on September 29.
Read the full analysis of the AgentCore prompt injection chain, and what to check on your own agents this week.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
