🔍 AWS Bedrock AgentCore credential exposure widened lateral access
Researchers demonstrated an AgentCore attack chain in AWS Bedrock where prompt injection pushed exposed agents with HTTP or shell tools to query the metadata endpoint and return temporary execution-role credentials. The documented AgentCorruption path then used valid AWS API access to enumerate logs, inspect other agents’ container images, reach internal agents, read stored conversations, and access connected service secrets.
The key issue was not metadata access alone but the breadth of the attached execution role. In this case, one compromised agent became a pivot across AgentCore resources in the same account and region, showing how over-permissioned AI runtimes can convert prompt injection into cloud-level compromise.
🛰️ Open sources - closed narratives
@sitreports
Post #39559
268
