Security News

One Chat Prompt Could Expose AWS AI Agent Credentials, Researchers Find

The Register · 10 Oct 2026
Key Takeaway If you deploy AI agents on cloud platforms, give each agent only the minimum permissions it needs and treat anything a public-facing agent can reach as exposed to your whole account.

Researchers at Zenity Labs have detailed a weakness in Amazon Bedrock AgentCore, the service used to host AI agents. In their scenario, a user chatting with an agent on a website asks it to fetch a credential endpoint. The agent obliges, and returns data from the Instance Metadata Service (IMDS), which describes the cloud virtual machine it runs on and can include security tokens. At the time of the research in late 2025, AgentCore still used the older IMDSv1, which offers fewer protections than IMDSv2.

The data returned included the agent's temporary credentials. Using them from his own machine, the attacker in the researchers' example listed other agents in the same AWS region, pulled their container images from Amazon Elastic Container Registry and inspected the source code. The credentials also revealed memory resources used by agents, which allowed users and their conversations to be extracted.

Zenity Labs researchers Tamir Ishay Sharbat and Lana Salameh say an outsider with only chat access to one exposed agent could send a single prompt, extract the credentials and take over all AgentCore agents in the same AWS account and region. They attribute the problem to the Firecracker MicroVM used by AgentCore, which did not provide sufficient network isolation, letting the agent be steered into a server-side request forgery (SSRF) attack. The findings were disclosed to AWS in December 2025.

This article covers only the opening of the original report.

AWS AI agents SSRF cloud security credentials
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.