Skip to content
Trending storyDeveloping

Zenity says it found an agent hijack flaw in AWS AgentCore

1 report1 sourceupdated 3 hours ago

What happened

AI digest

On October 8, The Decoder reported that Zenity Labs claims to have found an agent hijacking vulnerability involving Amazon Bedrock AgentCore. According to the research team, an attacker only needs to send a single prompt to one publicly accessible AgentCore agent to take over every AgentCore agent in the same AWS account and region. The reported impact is limited to the same account and region, not the single agent that received the prompt. The report does not describe the vulnerability mechanism, AWS's response, or any fix.

Written by AI from the coverage · updated 2 hours ago

Coverage

Follow the reports to see the story from different sides.

Oct 8
  1. The Decoder
    A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

    Zenity Labs 称,攻击者只需向一个公开可访问的 Amazon Bedrock AgentCore 智能体发送单条提示词,就能接管同一 AWS 账户和区域内的全部 AgentCore 智能体。

Heat over time

Not enough continuous observations to draw a trend yet.