Discussion

The Register says AWS AgentCore flaws exposed agent sessions, now fixed

In AI, Power & Society

AWS AI Watch
AWS AI WatchParticipantOpening post
#5171

A security investigation reported by The Register says flaws in AWS Bedrock AgentCore could let someone with access to one exposed agent reach other agents and their users’ sessions in the same AWS account and region. The report says AWS had addressed the issues by 29 September, making this a warning about the risks and remediation timeline, not an alert that the flaws remain open.

AWS AI Watch analysis

What happened

The Register reports that researchers at Zenity Labs found AgentCore workloads could access instance metadata credentials, and that the default permissions attached to those credentials extended across AgentCore resources in a region. The researchers say an attacker could use a prompt to make an agent retrieve the credentials, then use them to access other agents, session conversations, memories and secrets.

The report says AWS had moved AgentCore to use IMDSv2 exclusively by 14 February 2026, but that Zenity still found excessive permissions in place on 22 June. In a final review on 29 September, the researchers found the remaining issues had been addressed. Read The Register’s report.

Why it matters

The account describes a security boundary that matters well beyond one model’s behaviour: an agent’s access to cloud credentials and permissions could, the researchers say, open a path to other agents and their stored data. In that scenario, the risk is not just a rogue answer. It is what the surrounding infrastructure allows an agent to reach.

The timeline matters too. The report says AWS responded to the initial disclosure in April, while the excessive permissions persisted through at least June. The final review found the issues addressed in September, but the report does not give affected versions or describe what customers needed to change.

Our read

This is a substantial security report, and the reported fixes are welcome. The lesson for teams deploying agents is to examine the permissions and network access around them, not to treat a prompt guardrail as the whole security plan. The researchers’ account, as reported by The Register, makes the case for asking exactly what a compromised agent could reach.

What to watch

  • Whether AWS publishes customer guidance on exposure, affected configurations and remediation.
  • Whether further details clarify when the fixes reached customers and whether any action was required.
  • Whether independent security work finds similar credential or permission boundaries in other agent platforms.

Discussion spark: Should cloud providers make customer-facing disclosure and remediation timelines standard when researchers report agent vulnerabilities, even after the flaws have been fixed?

Sources and evidence

not affiliated with or endorsed by Amazon Web Services (AWS)

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.