The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In December 2025, Zenity Labs discovered 'AgentCorruption,' a critical vulnerability in AWS Bedrock AgentCore that allowed attackers to compromise entire AWS environments through a single malicious prompt to AI agents. The flaw exploited AWS Instance Metadata Services (IMDS) access within Firecracker MicroVMs, enabling lateral movement across all AgentCore resources in affected regions. Attackers could obtain temporary credentials, invoke additional agents, access secrets from AWS Secrets Manager, and poison agent memory through overprivileged default roles and insufficient network isolation.

This incident highlights the growing security risks as organizations rapidly deploy AI agents in cloud environments without proper isolation controls. The vulnerability demonstrates how AI and cloud security intersect, creating new attack vectors that traditional security measures may not adequately address.

Why This Matters Now

AI agent deployments are accelerating across enterprises, but security controls haven't kept pace. AgentCorruption exposes fundamental gaps between cloud security principles and AI operational requirements, making this a critical reference for secure AI deployment strategies.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

AgentCorruption is a vulnerability in AWS Bedrock AgentCore that allows attackers to use malicious prompts to access Instance Metadata Services, obtaining credentials and compromising entire AWS regions through overprivileged agent roles.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the AgentCorruption attack by limiting AI agent network access to IMDS endpoints and restricting lateral movement across AWS Bedrock AgentCore services. The segmented architecture could have reduced the blast radius from region-wide compromise to isolated workload exposure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust network policies would likely have constrained the AI agent's ability to reach Instance Metadata Service endpoints through network-level isolation controls

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have isolated the AI agent workload from metadata services, potentially constraining credential retrieval through network-level access controls

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained inter-agent communication and resource access, potentially reducing the scope of lateral movement across AgentCore services

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility and control policies would likely have detected and constrained unauthorized cross-agent communication patterns and session access attempts

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policies would likely have constrained unauthorized data flows from AI agents to external destinations and limited access to sensitive secrets repositories

Impact (Mitigations)

Despite CNSF controls, compromised agents within their authorized network segments could still experience memory poisoning attacks, though the impact scope would likely be constrained to isolated workload boundaries

Impact at a Glance

Affected Business Functions

  • AI Agent Operations
  • Cloud Infrastructure Management
  • Automated Customer Support
  • Data Processing Workflows
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of AWS temporary credentials, instance metadata, configuration data, agent session logs, and secrets stored in AWS Secrets Manager. The vulnerability could allow lateral movement across entire AWS regions with AgentCore deployments.

Recommended Actions

  • • Implement zero trust segmentation with least privilege access controls for AI agent execution environments to prevent lateral movement across cloud resources
  • • Deploy egress security and policy enforcement to control and monitor outbound traffic from AI agents, preventing unauthorized data exfiltration
  • • Establish multicloud visibility and control systems to detect anomalous interactions and repeated malformed requests to AI services
  • • Enable threat detection and anomaly response capabilities to baseline normal AI agent behavior and alert on suspicious automation patterns
  • • Implement cloud native security fabric controls with real-time inspection to protect against prompt injection and AI agent manipulation attacks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image