Security firm Zenity, through its research unit Zenity Labs, publicly disclosed a multi-step vulnerability chain in Amazon Bedrock AgentCore on October 8 and gave it the name AgentCorruption. According to the disclosure, researchers sent a single, carefully crafted prompt to one AgentCore agent that was reachable from the public internet — and from that one prompt alone, they eventually gained control over every AgentCore agent sitting in the same AWS account and the same region.
AWS has since patched the underlying issue and substantially tightened the permissions that agents receive by default.
How the attack chain actually worked, step by step
In the first step, the researchers got that public-facing agent to reach out to AWS's Instance Metadata Service, or IMDS — an internal interface that cloud compute instances normally use to fetch their own short-lived credentials. At the time of testing, the agent was able to call this interface with no restriction placed on it at all.
In the second step, the credentials the agent handed back turned out to belong to a default IAM execution role. Critically, Zenity says, that role's permissions were never scoped down to just the one agent that happened to make the request — instead, those permissions covered every single AgentCore agent running under the same AWS account and the same region, regardless of which agent the credentials were originally meant for.
The third step was lateral movement across that whole fleet. Armed with those account-wide credentials, the researchers went on to discover and invoke other agents, including sensitive agents that were only ever meant to be reachable internally. From there they were able to read private conversation histories and long-term memory stores, download container images to pull out full source code, and reach into AWS Secrets Manager to extract live API keys and OAuth tokens.
The final step was establishing persistence: the researchers wrote malicious content directly into an agent's memory, so that the compromised agent would keep quietly forwarding future conversations to an address under the attacker's control, long after the initial prompt had been forgotten.
The fix took nine months to land
Zenity first reported the issue to AWS on December 25, 2025. According to public reporting, AWS began requiring newly deployed agents to use only IMDSv2 starting February 14, 2026, and by September 29 it had stripped the default execution role of its ability to invoke other agents, read private conversations, or reach Secrets Manager at all. Public materials released so far do not mention an assigned CVE number, and they do not say whether AWS paid out a bug bounty for the finding.
Zenity co-founder and CTO Michael Bargury summed up the underlying tension this way:
"Cloud security is all about segmentation and least-privilege access. AI agents, however, need their creative space to be useful. Mixing the two creates an inherent conflict."
What teams in China should check against this case
Instance metadata services are a near-universal design across cloud providers, not something specific to AWS. Alibaba Cloud's own instance metadata address is 100.100.100.200, and Tencent Cloud and other providers expose equivalent internal interfaces of their own. Any agent that runs inside an environment able to reach that kind of address, and that also carries tools for executing code or firing off network requests, already satisfies the precondition needed for this attack's very first step.
Teams already running AgentCore in production should check two things first: whether agents deployed before February 14 have actually been switched over to IMDSv2 by now, and whether any custom execution roles they built themselves still carry the original, overly broad permissions from before the fix. Public materials do not make clear whether AWS's permission tightening also extends to roles that users created on their own, so that gap is worth checking directly rather than assuming.
Whether agent platforms run by Chinese cloud vendors carry a similar exposure is something no public research or vendor statement has addressed so far. What made this entire vulnerability chain possible, start to finish, was placing a customer-facing, internet-exposed service agent and an internally used data agent under the exact same account and the exact same execution role. Splitting those two kinds of deployments apart remains the cheapest line of defense available.
Sources: Zenity Labs disclosure (attack chain steps and fix timeline), The Decoder, CocoLoop, Dark Reading; Zenity press release used to cross-check the disclosure and fix timeline.