INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AgentCorruption Compromises AWS Environments via Single Prompt Attack
| 2026-10-08 20:39 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
On October 8, 2026, a vulnerability in AWS Bedrock AgentCore was discovered by Tamir Ishay Sharbat, director of security research at Zenity Labs. The issue, dubbed "AgentCorruption," allows an attacker to gain control over all agents on the same AWS account and region with a single prompt to a public-facing chatbot. This occurs because an agent deployed through Bedrock AgentCore runs inside a Firecracker MicroVM without necessary network isolation, allowing it to make HTTP requests to access sensitive data in Instance Metadata Services (IMDS). As a result, attackers can obtain temporary credentials, move laterally across the AWS environment, and engage in memory poisoning attacks. The 2019 Capital One data breach is cited as an example of how this vulnerability could be exploited, highlighting the need for organizations to implement least privilege access controls for metadata services like IMDS.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
2025/10/08
Threat actors exploited a vulnerability in the Bedrock AgentCore, an AWS-managed platform for deploying and operating agents, to put multiple AWS environments at risk on October 8, 2025.
Click on any entity below to view its context and source!
organisation
AWS
Bedrock AgentCore
, which launched last year, is AWS's managed platform for deploying and operating agents.
2026/10/08
Threat actors exploited a vulnerability in AWS Bedrock AgentCore, known as "AgentCorruption," to gain control over public-facing agents and subsequently all agents within the same account and region.
Click on any entity below to view its context and source!
organisation
Capital One
Sharbat told the audience that IMDS has been a weakness for cloud environments "since the beginning," and highlighted the 2019
Capital One data breach
.
organisation
AWS Bedrock
That's according to Tamir Ishay Sharbat, director of security research at AI security vendor Zenity Labs, who detailed a now-patched flaw in AWS Bedrock AgentCore during a session at SecTor 2026 on Wednesday.
However, Sharbat tells Dark Reading that while he's not aware of a way to look up who's running their agents on AWS BedRock, "I'm 100% sure there are ways to do it."
organisation
Bedrock AgentCore
But Sharbat and
Zenity's research team
tested the platform and found that agents deployed through Bedrock AgentCore could access the organization's Instance Metadata Services (IMDS), which contains sensitive data such as temporary credentials, instance IDs, and configurations.
organisation
Instance Metadata Services
But Sharbat and
Zenity's research team
tested the platform and found that agents deployed through Bedrock AgentCore could access the organization's Instance Metadata Services (IMDS), which contains sensitive data such as temporary credentials, instance IDs, and configurations.
organisation
Cloudflare Announces Public Certificate Authority
Related:
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
"Cloud and AI are kind of like fire and ice," Sharbat said.
organisation
AgentCorruption' Jeopardizes AWS Instances
"
'AgentCorruption' Jeopardizes AWS Instances
The core issue for Bedrock AgentCore involves a flaw with IMDS, which Zenity calls "
AgentCorruption
."
organisation
AgentCorruption
The same approach applies with an AgentCorruption attack, except the threat actor is manipulating a public-facing agent to do the work.
organisation
IMDS
Therefore, an attacker can use any agent with the ability to make HTTP requests to issue such a request to the IMDS' endpoint within the instance.
organisation
AgentCore
Zenity initially reported the IMDS flaw to AWS in December, and later followed up with an additional report about AgentCore’s overprivileged default role and the wide blast radius.
organisation
Modern Cybersecurity
Sharbat
Related:
How to Build a SASE Framework for Modern Cybersecurity
Sharbat said Zenity hasn't seen any evidence of the flaw being exploited in the wild prior to AWS's fix because there's "security through obscurity" at work with AgentCore — it's difficult to tell what agents are deployed via the platform, which benefits AWS customers.
Intelligence Sources
Dark Reading
2026-10-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:23
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
Capital One
entity
3x
timeline
Temporal Reference
2019
date
2x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
1 METRICS
general metric
%
100
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.