Zenity AgentCorruption disclosure
Zenity disclosed a historical attack chain against AWS Bedrock AgentCore and described changes AWS made to metadata access and default permissions before publication.
What happened lately
Zenity AgentCorruption disclosure timeline
Zenity Labs publicly described AgentCorruption on October 8, an attack chain its researchers tested against AWS Bedrock AgentCore. They say a public-facing agent could be induced to expose its temporary cloud identity, and a formerly broad default role then permitted access to other agents in the same account and region. Zenity says it disclosed the issues to AWS in late 2025 and early 2026. Its publication says AWS moved new agents to a stronger metadata-service mode in February and substantially narrowed default permissions by late September. The research describes a controlled demonstration, not a confirmed breach of an outside customer.