news.mlab.sh
Back to the feed
threat-intel

AWS AgentCore security undone by prompt requesting credentials

Info
Image: The Register
Summary

A Zenity Labs researcher discovered a vulnerability in Amazon Bedrock AgentCore that allowed an attacker to extract AWS credentials by simply requesting information from an agent. This led to the ability to enumerate other agents, pull container images, and ultimately hijack agent sessions within an AWS account and region.

Read the full article at The Register

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.