Research · curated 18 Sep 2026
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
First reported paloaltonetworks.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AWS AgentCore is a widely deployed agentic-AI runtime, and weaknesses in how harness credentials intersect with agent identity could let an attacker who influences the agent exfiltrate cloud credentials and escalate access.
Unit 42 (Niv Rabin) examines the security gap between AWS Bedrock AgentCore Harness and AgentCore Identity, showing how the agent's shell tool and sandbox execution environment can expose or exfiltrate harness credentials and IAM permissions. The research details how the space between the agent runtime harness and its identity/credential handling creates opportunities for credential access and data exfiltration within agentic AI deployments.