threat-intel
AWS AgentCore security undone by prompt requesting credentials
Info
Summary
A Zenity Labs researcher discovered a vulnerability in Amazon Bedrock AgentCore that allowed an attacker to extract AWS credentials by simply requesting information from an agent. This led to the ability to enumerate other agents, pull container images, and ultimately hijack agent sessions within an AWS account and region.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data