AWS AgentCore security undone by prompt requesting credentials
Bob, possibly the same Bob whose conversations with Alice draw so much interest from eavesdropping Eve, was browsing a site we'll call TechHub.
The site hosts an AI agent served by Amazon Bedrock AgentCore.
Bob asked the agent for help understanding the content of a URL, a credential endpoint – in raw JSON, if you don't mind.
The endpoint returned data from the Instance Metadata Service (IMDS), which provides metadata about cloud instances and VMs at providers like AWS, Azure, and Google Cloud Platform.
The metadata includes details like region and availability zone, subnets, system images, security groups, public keys injected during spawning, but also potentially more sensitive details like user data and security tokens.
IMDSv2 addresses some of these risks, but back when Bob was browsing late last year, Bedrock AgentCore still used IMDSv1.
The metadata provided to Bob by the helpful agent contained the agent's temporary credentials.
So Bob loaded them onto his local machine, and remotely enumerated the company's other agents in that AWS region.
He then logged into the Amazon Elastic Container Registry (ECR), pulled the agent container images, and ran each as root to inspect the source code.
The stolen credentials also allowed Bob to discover the memory resources available in that AWS region, including the ones used by agents.
From these, he's able to extract the users and their agent sessions – their conversations.
Researchers at Zenity Labs disclosed their findings to AWS in December 2025.
"We discovered that agents deployed through AgentCore could access their instance's IMDS endpoints," said Tamir Ishay Sharbat and Lana Salameh in a blog post.
"This meant that an external attacker with nothing more than chat access to a single exposed agent could send a single prompt, extract its IMDS credentials, and use them to take over all AgentCore agents in the same AWS account and region." The basic problem, they explain, is that the Firecracker MicroVM used by AgentCore failed to provide sufficient network isolation.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.