TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39554 219
🔍 AWS AgentCore exposed credentials via agent prompt

Researchers from Zenity Labs found that a single prompt to an internet-exposed Bedrock AgentCore agent could retrieve IMDS credentials. The reported chain involved IMDSv1 exposure, weak Firecracker MicroVM isolation, and overly broad default IAM permissions, enabling access to other agents, ECR images, sessions, memory writes, and secrets. AWS later shifted AgentCore to IMDSv2 and says remaining issues were fixed by late September 2026.

The case shows how LLM agent surfaces can break cloud trust boundaries when metadata access, SSRF paths, and overprivileged regional roles overlap. Temporary credentials could reportedly pivot across agents, users, and stored conversations within the same account and region.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 10, 2026🔍 FBI makes another ShinyHunters-linked arrest after agency breach FBI Director Kash Pate…
  2. Oct 10, 2026🔍 GoBalance flaw exposes Tor-format keys behind .onion services A vulnerability in GoBala…
  3. Oct 10, 2026🔫 Germany arrests alleged core Qilin member after extradition Germany has arrested a Russ…
  4. Oct 10, 2026🔍 US disrupts China-linked Integrity Tech cyber toolset The US Justice Department and FBI…
  5. Oct 10, 2026🔍 Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks Threat actors…
  6. Oct 10, 2026🔍 Credential-stealing workflows seeded across GitHub repos Malicious GitHub Actions workf…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →