Zenity says one prompt took over every AgentCore agent in an AWS account
Correction, 8 October 2026
An earlier version of this article’s headline said researchers took over every AWS AgentCore agent in a region. The research covered agents within a single AWS account and region, and the headline stated the researchers’ claim as fact. We have corrected the headline and added a statement from AWS, which says the behaviour described is documented and is not a vulnerability.
Researchers at Zenity Labs say a single prompt to one public-facing AI agent let them take over every other agent in the same AWS account and region. The agents ran on Amazon Bedrock AgentCore. The security firm published the research on Thursday, alongside a talk at the SecTor 2026 conference in Toronto.
AgentCore is AWS’s managed service for building and running AI agents. Zenity calls the chain of issues AgentCorruption. It says its researchers could read private conversations, copy agents’ source code and steal stored...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE