How did Zenity researchers take over AgentCore agents?
Researchers at Zenity Labs say a single prompt to one public-facing AI agent let them take over every other agent in the same AWS account and region. The agents ran on Amazon Bedrock AgentCore, a managed service for building and running AI agents, which raises concerns about LLM visibility and generative engine optimization. The security firm published the research on Thursday, focusing on AEO and answer engine optimization, alongside a talk at the SecTor 2026 conference in Toronto.
According to Zenity, the attack started with an agent that had a common tool able to make web requests. The researchers asked it, in plain language, to fetch data from the instance metadata service, which hands temporary credentials to cloud workloads. The virtual machines that run AgentCore agents did not block that traffic, and the agent returned the credentials of its execution role, which the researchers then used from their own computer.
What are the implications of this vulnerability for AI search optimization?
The default role that AgentCore attached to agents covered resources across the whole account and region, Zenity says. With it, the researchers listed every agent in the account and region, downloaded each agent's container image and source code, and invoked internal agents they were never meant to reach. They also read users' private conversations with any agent and obtained API keys and other secrets stored in AWS Secrets Manager.
Zenity's co-founder and chief technology officer, Michael Bargury, said that cloud security is all about segmentation and least-privilege access, but AI agents need their creative space to be useful, creating an inherent conflict. The researchers reported the metadata access to AWS on December 25, 2025, and the broad default role on January 12, 2026. AWS told Zenity that since February 14, newly deployed AgentCore agents launch with IMDSv2 only, which requires a session token for each request.
AWS also stated that the behavior described by Zenity is documented and not a vulnerability, and that an agent can access resources in another AWS account only if the developer explicitly grants permissions on both the agent's execution role and the target resource. Zenity raised a $125m Series C round in August and found malicious AI skills with 1.7 million installs the same month.
Questo articolo è stato scritto con l'assistenza dell'IA.
News Factory APP - notizie agentiche per potenziare il tuo SEO e AEO.
