Threat · curated 24 Sep 2026

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Coverage timeline

discovered paloaltonetworks.com primary 21 Sep 2026cybernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

AWS AgentCore's encrypted vault does not prevent a prompt-injected agent from handing secrets to attackers, meaning defenders deploying agentic AI on AWS must lock down agent tools, scope key permissions, and monitor outbound traffic rather than trusting the vault alone.

Palo Alto Networks' Unit 42 demonstrated that AWS AgentCore AI agents can be tricked via prompt injection into exfiltrating credentials in plaintext, despite the platform's encrypted secrets vault. In the demonstration, a malicious support ticket caused an AI agent to run code and send an authentication token to a test attacker; AWS reviewed the disclosure and closed it as informative, saying customers must restrict agent tools and access.