A single chat message to a public-facing AI agent reportedly gave Zenity Labs researchers a path to other agents running in the same AWS account and region. The findings highlight how a weakness in one agent can become a wider cloud security problem when agents share permissions and infrastructure.
How one agent exposed its credentials
Amazon Bedrock AgentCore is AWS' platform for running enterprise AI agents with tools, memory, and access management. Zenity Labs called the chain of vulnerabilities it found “AgentCorruption.” According to the researchers, an attacker needed chat access to one public agent to start the attack.
AWS workloads can use an internal Instance Metadata Service at 169.254.169.254 to obtain temporary credentials. Zenity says AgentCore did not properly isolate agents from that service. In a test, researchers built an agent with Strands, an open-source framework from AWS that includes a web tool, and asked it in plain language to query the metadata service and send the result externally. The agent complied.
The credentials the agent revealed worked outside the platform, so the researchers could continue without relying on the agent. They also say the metadata service exposed certificate and key material for an internal AWS service, as well as a presigned URL for internal S3 storage that did not belong to their account. Zenity found the same underlying platform weakness could be reached through a command-line tool, so removing the web tool alone would not have addressed it.
Broad permissions expanded the impact
The stolen credentials mattered because AgentCore's default permissions extended beyond the individual agent. Zenity says they applied to every agent in the same account and region, with read, write, and delete access. That scope let the researchers list agents, download their code packages, and invoke them.
Code packages may include source code alongside forgotten passwords or API keys. If a public customer service agent and an internal finance agent share the same environment, access to the first could potentially open a route to the second. Zenity also reports that the researchers could read private conversations between users and agents.
Where long-term memory was enabled, the researchers say they could change what an agent remembered and affect its later behavior. In a separate account of memory poisoning, Zenity describes planting instructions that caused agents to forward future conversations to an external destination. A user might continue talking to an agent that appeared normal while its behavior had been altered.
Zenity also says the default permissions could undermine the practice of storing passwords and API keys separately from agents in secure storage. The permissions reportedly allowed agents to retrieve stored credentials, including keys for services outside AWS.
AWS changed defaults, but Zenity urges narrower roles
Zenity says it reported the findings to AWS on December 25, 2025. AWS then made IMDSv2 the default for new AgentCore deployments. IMDSv2 is a more secure version of the metadata service used as the attack's entry point.
According to Zenity's updated account, AWS also changed AgentCore's default execution role around August. The updated role no longer allowed agents to invoke other agents, read private conversations, or retrieve credentials from AWS Secrets Manager. Zenity says AWS significantly restricted other permissions too, but still recommends companies create custom roles that give agents only the access they need.
That advice reflects a tension in deploying AI agents. Zenity CTO Michael Bargury described cloud security as relying on segmentation and least-privilege access, while useful agents need room to act. When public-facing and internal agents share an environment, a single weakness can cut across those boundaries.
Agent security depends on boundaries and memory
Zenity's findings fit a wider pattern in its research: an input that appears harmless can redirect an agent or expose organizational data. Its AgentFlayer research described zero-click attacks involving Salesforce Einstein, Copilot Studio, and Cursor. Its AgentForger research reported that a tampered ChatGPT link could create an autonomous agent in OpenAI's Workspace Agents with approval requirements disabled.
Other cited research has focused on memory as an attack surface. Google DeepMind's taxonomy of “AI Agent Traps” identifies long-term memory manipulation as an attack class, while the “Agents of Chaos” red-teaming study described remote control through an externally editable document linked in an agent's memory file.
For companies deploying agents, the practical lesson from the AgentCore report is to review both what an agent can reach and what it can retain. Restricting roles, separating public and internal workloads, and protecting credentials can limit how far a compromise spreads. The platform changes address parts of the reported chain, but Zenity says organizations should still set narrower permissions themselves.