MobbleOpen in Mobble ⇢
Science · Mathematics & computing · published 2026-10-09 · via The Register

Prompt trick exposed AWS agent credentials and customer sessions

Zenity Labs found that an AI agent hosted through Amazon Bedrock AgentCore could be prompted to reveal instance metadata that included temporary credentials. Those credentials let an attacker list other agents, download container images, and reach memory stores containing user conversations. AWS was told about the findings in December 2025; the weaknesses involved an older metadata service, insufficient VM separation, and overly broad permissions.

Expanded Detail

Zenity Labs reported that a chat-exposed agent on Amazon Bedrock AgentCore could be induced to fetch its instance metadata, exposing temporary credentials. With those, an attacker could enumerate other agents in the same AWS account and region, pull container images, and access memory stores holding user conversations. AWS received the disclosure in December 2025.

The researchers attributed the issue to IMDSv1, inadequate network isolation in the Firecracker MicroVM, and a default role granting broad regional AgentCore permissions. AWS later said AgentCore moved exclusively to IMDSv2 on February 14, 2026, and closed the report in April 2026.

Context

This case may affect businesses and users relying on cloud-hosted AI agents, since exposed sessions and memories could reveal private conversations or let attackers alter agent behavior. It could push developers to adopt stricter isolation, narrower permissions, and stronger metadata protections. For customers, trust in agent platforms may depend on clearer safeguards and faster disclosure, while security teams may need to treat chat access as a potential attack path.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Register →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “AWS AgentCore security undone by prompt requesting credentials.” Browse more stories.