During the SecTor 2026 conference in Toronto, a significant security flaw in AWS's Bedrock AgentCore platform was revealed by Tamir Ishay Sharbat from Zenity Labs. This vulnerability, known as 'AgentCorruption,' was found to allow a single malicious prompt to compromise all agents within the same AWS account and region. The root of the issue lies in the Instance Metadata Services (IMDS), which provide sensitive data like temporary credentials. The flaw permitted attackers to send requests to IMDS via a public-facing chatbot, gaining unauthorized access to all agents. This vulnerability highlighted a critical gap in network isolation and the lack of the principle of least privilege for the agents.

The flaw has since been patched by AWS. After Zenity reported the issue, AWS updated the Bedrock AgentCore platform to require authentication for IMDSv2 and altered default roles to reduce permissions, limiting the potential blast radius of an attack. Although no evidence of the flaw being exploited was found before the fix, Sharbat emphasized the importance of applying strict access controls and isolation in cloud environments. The vulnerability underscores a broader security challenge posed by agentic AI, which often requires broad permissions. Zenity Labs continues to investigate other cloud platforms for similar vulnerabilities, emphasizing the necessity for cloud security teams to ensure role-specific privilege limitations.