Zenity discloses AgentCore attack chain after AWS permission changes
Researchers say one exposed agent once provided a path to other AgentCore agents in the same account and region; AWS changed relevant defaults before disclosure.
What the researchers reproduced
Zenity Labs disclosed AgentCorruption on October 8, describing an attack chain it tested against AWS Bedrock AgentCore. The researchers say a prompt to one public-facing agent made it expose temporary credentials for its cloud execution role. At the time of their tests, they say that role had broad permissions across AgentCore resources in the same AWS account and region. In their controlled environment, those permissions allowed access to other agents’ code and conversations, and to stored credentials and long-term memory. These are Zenity’s findings, not evidence that an outside attacker used the chain against a customer.
Changes before publication
Zenity says it reported the metadata-access issue to AWS in December 2025 and the broad default role in January 2026. Its disclosure timeline says AWS made a stronger metadata-service mode the default for newly deployed agents in February. During a September 29 review, Zenity observed substantial restrictions to the default role, including removal of permissions it had used to read conversations, invoke other agents and reach secrets. The Decoder also reported those changes. The public research does not establish that every existing deployment has been updated or that all agent-security risks are resolved. Operators still need to check the permissions assigned to their own agents.