One Chat Prompt Hijacked Every AI Agent in an AWS Account
Researchers at Zenity Labs found a flaw in Amazon Bedrock AgentCore. A single ordinary request in a support chat gave access to every agent in the account and region.
Security researchers at Zenity Labs found a chain of bugs in Amazon Bedrock AgentCore, AWS's platform for running corporate AI agents with tools and memory. One message, sent to one public-facing agent, was enough. The researchers used it to take over every AI agent in the same AWS account and region. The agent handed over its own AWS access credentials to an external server, just because it was asked. With those credentials, the researchers could read the source code of other agents. They could also read private conversations and stored passwords. Zenity reported the issue to AWS on December 25, 2025. A similar bug at OpenAI, the company behind ChatGPT, was fixed in four days. At AWS, the broad default access permissions stayed open for months.
The gap between four days and several months is the real story here. It is not proof that agents are inherently dangerous. It shows that companies hand agents broad access by default, and they do not check who or what can trigger it. If you run AI agents against your company's real systems, not just inside a chat window, treat the default permissions as an audit risk. Do not treat them as a setting you can simply trust.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles