Zenity Labs has disclosed "AgentCorruption", a chain of flaws in Amazon Bedrock AgentCore, AWS's managed platform for running enterprise AI agents with tools, memory and identity management. It was not a single bug.
The chain began with prompt injection against one public-facing agent. Because AgentCore agents ran with overly broad default permissions, the compromised agent could retrieve credentials and secrets, read other agents' private conversations, copy source code and reach agents across the same AWS account and region — "one prompt to take over every agent in a region", as the researchers put it.
AWS has patched the issue. It disputes the severity framing: the company says the default role behaviour is documented and did not override permissions the customer set. Zenity's counter is that a documented default which lets one poisoned input cascade through an entire agent fleet is a design problem, whatever the paperwork says.
In practice, the case is a rehearsal for a wider risk. As agents are handed authority over tickets, code, cloud resources and messaging, prompt injection becomes the new business-email compromise. The mitigations are unglamorous — one role per agent, least privilege, no secrets in agent-reachable stores, treating every external input as hostile, and logging agent-to-agent calls.




