LIVE · cybersecurity feed
Live wire
cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

ZeroDay News ·

Source: The Register — Security

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

The vulnerability stems from AgentCore's use of Firecracker MicroVMs, which, at the time of discovery, did not adequately isolate the agent's network access. This allowed an attacker to perform a server-side request forgery (SSRF) attack by prompting an agent to fetch data from its Instance Metadata Service (IMDS) endpoint. The IMDS, which provides metadata about cloud instances, could return sensitive details, including temporary security tokens.

Zenity Labs researchers Tamir Ishay Sharbat and Lana Salameh demonstrated that an attacker with only chat access to an exposed agent could send a prompt requesting the content of a credential endpoint in JSON format. This request would return data from the IMDS, including the agent's temporary credentials. These credentials, once obtained, could then be used to enumerate other agents, pull container images from Amazon Elastic Container Registry (ECR), and inspect their source code by running them as root.

Further exploitation was possible due to the default AgentCore IAM role being overpermissioned. Instead of being scoped to a single agent, the role was configured to access all AgentCore resources within the same AWS region. This broad access meant that the stolen temporary IAM credentials could be used to launch new agents, read agent sessions, write to agent memories, and fetch secrets from AWS Secrets Manager. The researchers noted that this could allow an attacker to persistently alter agent behavior and hijack agent goals across future sessions.

Zenity Labs first reported their findings to AWS in December 2025, specifically detailing the IMDS access issue. In January 2026, they provided additional information regarding the overprivileged nature of AgentCore's default IAM roles.

AWS responded on April 12, 2026, acknowledging the report as "informative" and closing it. The company stated that as of February 14, 2026, AgentCore had been updated to exclusively use IMDSv2, which offers enhanced security against such credential extraction.

However, Zenity Labs observed that the issue of excessive permissions in AgentCore remained unaddressed as of June 22, 2026. A final review conducted by the researchers on September 29, 2026, confirmed that AWS had subsequently remediated the remaining problems, including the overly permissive IAM roles.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…