Executive Summary

Unit 42 researchers discovered a critical security vulnerability in AWS AgentCore Harness where default configurations allow attackers to exploit prompt injection techniques to exfiltrate plaintext credentials from AgentCore Identity vaults. The research demonstrated how the built-in shell tool, enabled by default and running with root privileges, can access the same memory space where credentials are resolved to plaintext. Through indirect prompt injection, attackers can execute arbitrary commands, scan process memory, and extract JWT tokens and service account credentials that provide unauthorized access to downstream MCP servers containing sensitive customer data including PII. AWS classified this as informative under their shared responsibility model, emphasizing that operators must implement proper allowedTools scoping and egress filtering controls.

This incident highlights the emerging security challenges as AI agents become more autonomous and powerful, particularly around prompt injection attacks that can now leverage programmatic tool access to bypass traditional security boundaries and access privileged credentials in managed runtime environments.

Why This Matters Now

As organizations rapidly adopt AI agents with expanded autonomy and tool access, the attack surface for prompt injection has evolved from simple text manipulation to credential theft and privilege escalation, requiring immediate reassessment of AI security controls.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The built-in shell tool runs with root privileges in the same memory space where Identity vault credentials are resolved to plaintext, allowing attackers to use prompt injection to execute memory scanning commands and extract JWT tokens.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this AgentCore Harness exploitation by limiting lateral movement paths and controlling egress communications. The segmented architecture could have reduced the attacker's ability to access downstream MCP servers and exfiltrate customer PII.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust fabric monitoring could have flagged unusual execution patterns from the AgentCore Harness agent, potentially limiting the scope of arbitrary command execution through behavioral analysis

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload isolation policies would likely constrain the blast radius of root-level access, limiting what system resources and network paths the compromised harness could reach

Lateral Movement

Control: East-West Traffic Security

Mitigation: Micro-segmentation controls could have limited the harness's ability to communicate with identity services and downstream systems, constraining credential discovery and usage pathways

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Enhanced visibility into cross-cloud communications may have detected unusual curl patterns and memory scanning activities, reducing the attacker's ability to maintain persistent reconnaissance unnoticed

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering policies would likely have blocked unauthorized HTTP POST transmissions to external webhook endpoints, constraining the attacker's ability to exfiltrate JWT credentials and MCP server information

Impact (Mitigations)

Despite segmentation controls, residual risk would remain for any credentials successfully exfiltrated before egress blocking, though the scope of accessible MCP servers would likely be constrained

Impact at a Glance

Affected Business Functions

  • Customer Support Operations
  • AI Agent Services
  • Cloud Identity Management
  • Downstream Service Integration
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of AWS AgentCore Identity vault credentials including JWT tokens for service accounts, MCP server authentication tokens, and access to downstream services containing PII such as customer names, phone numbers, and partial Social Security numbers. The research demonstrated successful exfiltration of service account credentials with replay capabilities from external networks.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate AI agent runtime environments from credential stores and downstream services using identity-based policies
  • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections from agent containers to external webhook endpoints
  • Enable Multicloud Visibility & Control to monitor anomalous interactions between AI agents and detect suspicious automation patterns in real-time
  • Apply East-West Traffic Security controls to prevent lateral movement between agent runtime processes and credential vault services
  • Establish Cloud Native Security Fabric (CNSF) inline enforcement to detect and block prompt injection attempts targeting agentic AI systems

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image