Executive Summary
In December 2025, Zenity Labs discovered 'AgentCorruption,' a critical vulnerability in AWS Bedrock AgentCore that allowed attackers to compromise entire AWS environments through a single malicious prompt to AI agents. The flaw exploited AWS Instance Metadata Services (IMDS) access within Firecracker MicroVMs, enabling lateral movement across all AgentCore resources in affected regions. Attackers could obtain temporary credentials, invoke additional agents, access secrets from AWS Secrets Manager, and poison agent memory through overprivileged default roles and insufficient network isolation.
This incident highlights the growing security risks as organizations rapidly deploy AI agents in cloud environments without proper isolation controls. The vulnerability demonstrates how AI and cloud security intersect, creating new attack vectors that traditional security measures may not adequately address.
Why This Matters Now
AI agent deployments are accelerating across enterprises, but security controls haven't kept pace. AgentCorruption exposes fundamental gaps between cloud security principles and AI operational requirements, making this a critical reference for secure AI deployment strategies.
Attack Path Analysis
The AgentCorruption attack exploited AWS Bedrock AgentCore's lack of proper IMDS isolation, allowing attackers to send malicious prompts to public-facing AI agents to retrieve temporary credentials from Instance Metadata Services. Once credentials were obtained, attackers leveraged overprivileged default roles to invoke additional agents, access secrets, and conduct memory poisoning attacks across the entire AgentCore region.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker identifies public-facing AI chatbot running on AWS Bedrock AgentCore and crafts malicious prompt to request IMDS credentials via HTTP request
MITRE ATT&CK® Techniques
Unsecured Credentials: Container API
Permission Groups Discovery: Cloud Groups
Domain Policy Modification: Trust Modification
Abuse Elevation Control Mechanism: Elevated Execution with Prompt
Exploitation for Privilege Escalation
Remote Services: Cloud Services
Data from Cloud Storage
Container and Resource Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Establish Access Control Systems
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Network Micro-Segmentation
Control ID: CD.AM-3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001:2022 – Access Control Policy
Control ID: A.9.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI agent platforms vulnerable to prompt injection attacks enabling IMDS access, credential theft, and lateral movement across cloud environments.
Financial Services
AgentCorruption threatens customer-facing AI chatbots, potentially exposing sensitive financial data and enabling unauthorized access to cloud infrastructure.
Information Technology/IT
Cloud misconfiguration risks amplified by AI agents accessing metadata services, compromising entire AWS regions through single malicious prompts.
Health Care / Life Sciences
Healthcare AI systems at risk of HIPAA violations through compromised agents accessing patient data via overprivileged cloud roles.
Sources
- 'AgentCorruption' Puts AWS Environments At Risk With Single Prompthttps://www.darkreading.com/cloud-security/agentcorruption-aws-environments-at-risk-single-promptVerified
- AWS Bedrock AgentCore Documentation - Security Best Practiceshttps://docs.aws.amazon.com/bedrock/latest/userguide/security-best-practices.htmlVerified
- IAM permissions for AgentCore Runtime - AWS Documentationhttps://docs.aws.amazon.com/bedrock/latest/userguide/iam-permissions.htmlVerified
- Zenity Labs Security Research - AgentCorruption Disclosurehttps://zenity.io/research/agentcorruptionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the AgentCorruption attack by limiting AI agent network access to IMDS endpoints and restricting lateral movement across AWS Bedrock AgentCore services. The segmented architecture could have reduced the blast radius from region-wide compromise to isolated workload exposure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust network policies would likely have constrained the AI agent's ability to reach Instance Metadata Service endpoints through network-level isolation controls
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have isolated the AI agent workload from metadata services, potentially constraining credential retrieval through network-level access controls
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained inter-agent communication and resource access, potentially reducing the scope of lateral movement across AgentCore services
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and control policies would likely have detected and constrained unauthorized cross-agent communication patterns and session access attempts
Control: Egress Security & Policy Enforcement
Mitigation: Egress policies would likely have constrained unauthorized data flows from AI agents to external destinations and limited access to sensitive secrets repositories
Despite CNSF controls, compromised agents within their authorized network segments could still experience memory poisoning attacks, though the impact scope would likely be constrained to isolated workload boundaries
Impact at a Glance
Affected Business Functions
- AI Agent Operations
- Cloud Infrastructure Management
- Automated Customer Support
- Data Processing Workflows
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of AWS temporary credentials, instance metadata, configuration data, agent session logs, and secrets stored in AWS Secrets Manager. The vulnerability could allow lateral movement across entire AWS regions with AgentCore deployments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation with least privilege access controls for AI agent execution environments to prevent lateral movement across cloud resources
- • Deploy egress security and policy enforcement to control and monitor outbound traffic from AI agents, preventing unauthorized data exfiltration
- • Establish multicloud visibility and control systems to detect anomalous interactions and repeated malformed requests to AI services
- • Enable threat detection and anomaly response capabilities to baseline normal AI agent behavior and alert on suspicious automation patterns
- • Implement cloud native security fabric controls with real-time inspection to protect against prompt injection and AI agent manipulation attacks



