Photo by Mikhail Pushkarev on Unsplash. Source: https://unsplash.com/photos/person-looking-at-phone-in-front-of-multiple-computer-monitors-VhhlVXFaJXs (Unsplash License).

One prompt to a single agent returned the credentials for every agent in the same AWS account and region.

Zenity Labs published the chain on October 8 and named it AgentCorruption. Here is the short version.

  • The agent ran in a Firecracker MicroVM that did not block the instance metadata endpoint at 169.254.169.254.
  • Any agent tool that could fetch a URL could fetch the agent’s own temporary credentials.
  • The default execution role spanned every agent in the region, so those credentials unlocked all of them.
  • The researchers read private conversations, wrote long-term memories to hijack later runs, and read secrets.
  • AWS says the behavior is documented and expected. It narrowed the default role on September 29.

Read the full analysis of the AgentCore prompt injection chain, and what to check on your own agents this week.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.