Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

AWS AgentCore Security Vulnerability: A Cautionary Tale of Token Transmission, Weak VM Isolation, and Expansive Permissions


A critical security vulnerability has been identified in AWS AgentCore, which can be exploited by attackers to gain unauthorized access to sensitive information and manipulate the behavior of agents. The vulnerability arises from the transmission of tokens in metadata, weak virtual machine isolation, and expansive permissions granted to the AgentCore role. Despite AWS's efforts to address the issue, the vulnerability remained in place until recently, highlighting the importance of proper security measures and the need for vigilance and caution when working with cloud-based services.

  • The AWS AgentCore has a security vulnerability that can be exploited to gain unauthorized access to sensitive information and manipulate agent behavior.
  • The vulnerability arises from the transmission of tokens in metadata, weak VM isolation, and expansive permissions granted to the AgentCore role.
  • A malicious actor was able to obtain temporary credentials of an AWS agent and use them to access the Instance Metadata Service, retrieving sensitive information and manipulating agent behavior.
  • The vulnerability can be exploited through server-side request forgery (SSRF) attacks due to insufficient network isolation.
  • The default AgentCore role was overpermissioned, allowing an attacker to launch other agents and access sensitive information.
  • AWS has updated its AgentCore to use IMDSv2 exclusively to address some of the risks, but the issue remained until the researcher's final review.



  • AWS AgentCore, a critical component of the Amazon Web Services (AWS) ecosystem, has been found to possess a security vulnerability that can be exploited by attackers to gain unauthorized access to sensitive information and manipulate the behavior of agents. The vulnerability, which was identified by researchers at Zenity Labs, arises from the transmission of tokens in metadata, weak virtual machine (VM) isolation, and expansive permissions granted to the AgentCore role.

    According to a recent report, a malicious actor, posing as Bob, was able to obtain the temporary credentials of an AWS agent through a prompt requesting credentials. This allowed him to access the Instance Metadata Service (IMDS), which provides metadata about cloud instances and VMs, including sensitive information such as user data and security tokens. The researcher, who is believed to be Thomas Claburn, notes that the metadata provided to Bob by the helpful agent contained the agent's temporary credentials, which he then used to remotely enumerate the company's other agents in the same AWS region.

    The researcher further explains that the stolen credentials also enabled Bob to discover the memory resources available in that AWS region, including those used by agents. From these resources, he was able to extract the users and their agent sessions, which are essentially the conversations between the user and the agent. The researcher highlights that the basic problem is that the Firecracker MicroVM used by AgentCore failed to provide sufficient network isolation, making it easier for an attacker to carry out a server-side request forgery (SSRF) attack.

    Furthermore, the researcher notes that the default AgentCore role was overpermissioned, meaning it was scoped to all AgentCore resources in the region rather than a single agent. This allowed anyone in possession of the temporary IAM credentials to launch other agents, read sessions, write agent memories, and fetch secrets from AWS Secrets Manager. The researcher attributes this to the tokens transmitted in metadata, which are used to authenticate and authorize access to AWS resources. However, the researcher warns that these tokens can be easily obtained by an attacker if the metadata is not properly secured.

    In response to the researcher's findings, AWS has updated its AgentCore to use IMDSv2 exclusively, which addresses some of the risks associated with the previous version. However, the researcher notes that the issue remained in place until June 22, 2026, when Zenity checked in and found that the problems had not been remediated. It was only after a final review by Zenity that AWS was able to address the extant issues, clearing the way for the hypothetical adventure of Bob's hacking attempt to finally come to an end.

    In conclusion, the security vulnerability of AWS AgentCore highlights the importance of proper security measures and the need for careful consideration of the permissions and isolation of cloud-based services. The vulnerability, which can be exploited by attackers to gain unauthorized access to sensitive information and manipulate the behavior of agents, serves as a reminder of the need for vigilance and caution when working with cloud-based services. As the technology landscape continues to evolve, it is essential that cloud service providers prioritize security and take proactive steps to address vulnerabilities and ensure the integrity of their services.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/AWS-AgentCore-Security-Vulnerability-A-Cautionary-Tale-of-Token-Transmission-Weak-VM-Isolation-and-Expansive-Permissions-ehn.shtml

  • https://www.theregister.com/security/2026/10/09/aws-agentcore-security-undone-by-prompt-requesting-credentials/5302436

  • https://cybernews.com/security/aws-agentcore-platform-credential-leak/

  • https://www.explainx.ai/blog/agentcorruption-zenity-aws-bedrock-agentcore-hijack-every-agent-2026

  • https://en.wikipedia.org/wiki/Pegasus_(spyware)

  • https://www.socinvestigation.com/comprehensive-list-of-apt-threat-groups-motives-and-attack-methods/

  • https://www.huntress.com/threat-library/threat-actors/fancy-bear

  • https://en.wikipedia.org/wiki/Fancy_Bear

  • https://en.wikipedia.org/wiki/Lazarus_Group

  • https://www.picussecurity.com/resource/blog/lazarus-group-apt38-explained-timeline-ttps-and-major-attacks

  • https://www.threatclaw.ai/actors/apt10

  • https://www.fbi.gov/wanted/cyber/apt-10-group


  • Published: Fri Oct 9 14:33:58 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us