Threat

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

Page published

Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026

Coverage timeline

8 Oct 2026darkreading.com

Single-source incident — one report is available.

Why it matters

'AgentCorruption' shows that a single prompt injection against a deployed AWS Bedrock AgentCore chatbot could cascade into full control of an organization's agent fleet via stolen cloud credentials, making agentic deployments a high-value attack surface for defenders.

Zenity Labs researcher Tamir Ishay Sharbat disclosed 'AgentCorruption', a now-patched flaw in AWS Bedrock AgentCore where a single prompt to a public-facing chatbot let an attacker gain control of the agent and reach the Instance Metadata Service (IMDS), exposing temporary credentials, instance IDs, and configurations. The access could be leveraged to take over all agents in the same AWS account and region.