AgentCorruption tests expose cloud credentials through one AI agent
Zenity researchers disclosed how an agent they deployed on Amazon Bedrock AgentCore relayed temporary cloud credentials from an internal metadata service. Those credentials let them act under the agent’s execution role and reach further resources. The disclosure describes controlled research tests and earlier AWS changes, including a stricter metadata protocol for new deployments.
Artificial Intelligence··Night
A test agent relayed temporary cloud credentials
Zenity Labs, the research arm of an AI-agent security company, disclosed AgentCorruption on 8 October. Its researchers deployed their own agent on Amazon Bedrock AgentCore, an AWS service for running AI agents. They report that the agent followed a prompt and retrieved an internal metadata response containing temporary cloud credentials. Those credentials let the researchers act under the agent’s execution role and reach other agents in the same account and region.[1], [2]
Network access and role permissions extended the test
The metadata response included an access key, secret key and session token. It also exposed a container-image address and configuration. Registry-read permissions let researchers download the image and inspect its source code. They reproduced initial access with both a web tool and a shell tool. Their account describes private-conversation access, changes to long-term memory and retrieval of stored credentials as later research steps. These were controlled tests, rather than a confirmed intrusion into customer systems.[1]
AWS changed defaults before the public disclosure
The technical timeline places notification to AWS in December 2025. An AWS response reproduced in the disclosure says new agents have used only version two of the instance metadata service, IMDSv2, since 14 February. The default execution role was also narrowed around August. Public disclosure of the research is the new development; those platform changes happened earlier. The researchers continue to recommend application-specific roles with narrower permissions.[1]