AI Cloud Vulnerabilities and the AgentCorruption Threat in AWS Bedrock AgentCore
Most traditional cloud security alerts begin with a misconfigured S3 bucket, an overprivileged role, or an exposed port. However, as organizations transition from static compute instances to autonomous Large Language Models (LLMs) and agentic workflows, the attack surface shifts dramatically. Researchers at Zenity Labs — specifically Gal Nagli and Omer Mayraz — recently disclosed AgentCorruption, a critical chain of security flaws in Amazon Bedrock AgentCore. By leveraging a single malicious prompt delivered to a public-facing chatbot, attackers could orchestrate account-wide regional takeovers, accessing private conversations, source code, and enterprise credentials.
Understanding these sophisticated threats requires examining the evolving nature of cloud infrastructure security, the mechanics of agentic orchestration, and the fundamental question: what is cloud vulnerability in the age of generative artificial intelligence?
What Is Cloud Vulnerability in Modern Architectures?
To understand how modern infrastructure flaws emerge, it is essential to answer a foundational question: what is cloud vulnerability?
In cloud computing, a cloud vulnerability is a weakness, flaw, or misconfiguration in cloud-based hardware, software, services, or architecture that can be exploited by an adversary to gain unauthorized access, exfiltrate data, disrupt services, or compromise underlying workloads. Traditionally, these vulnerabilities manifested as insecure APIs, lax Identity and Access Management (IAM) configurations, unpatched server operating systems, or excessive permissions on object storage.
However, as enterprises integrate generative AI and multi-agent frameworks like Amazon Bedrock AgentCore into their cloud environments, the definition of a cloud vulnerability expands significantly. It now encompasses architectural collisions between autonomous AI logic and deterministic cloud access controls. When an LLM is equipped with tools, memory, and outbound connectivity, prompt injection or logic manipulation can transform an AI chatbot into an active attack vector capable of traversing cloud boundaries, bypassing network segmentation, and escalating privileges across accounts.
The Mechanics of AgentCorruption in AWS Bedrock AgentCore
Disclosed at the SecTor 2026 conference in Toronto, the AgentCorruption vulnerability chain demonstrated how systemic design oversights in AWS Bedrock AgentCore allowed a single prompt to compromise every agent within an AWS account and region.
The attack vector unfolded across several distinct phases:
- Initial Public-Facing Entry Point: The attacker sent a crafted prompt to a customer-facing AI agent equipped with standard tool use capabilities (specifically, the ability to make outbound network requests).
- Metadata Service Access: The prompt instructed the agent to query the AWS Instance Metadata Service (IMDS), which is designed to provide temporary credentials to cloud workloads.
- Privilege Escalation and Lateral Movement: Because of overly permissive default settings in the underlying execution role, the credentials retrieved from the IMDS endpoint were not scoped strictly to the single compromised agent. Instead, they extended across all AgentCore agents deployed within the same AWS account and region.
- Internal Enumeration and Exfiltration: Using these broad credentials, researchers could discover, invoke, and inspect internal agents that were never meant to be publicly accessible. They retrieved sensitive source code from container images, read long-term memories and private conversations, and extracted API keys, OAuth tokens, and database credentials stored securely in AWS Secrets Manager.
- Persistent Hijacking via Agent Memory: Crucially, the researchers demonstrated that attackers could implant persistent malicious memories into the agents. This ensured that even after initial interactions ended, the hijacked agents would continue to follow attacker-defined instructions behind the scenes—covertly transmitting sensitive enterprise conversations to external destinations while maintaining the facade of trusted corporate assistants.
Managing AI Cloud Vulnerabilities and Securing Agentic Workflows
The discovery of AgentCorruption highlights a core dilemma for modern enterprise architecture: cloud security relies on strict least-privilege access and rigid segmentation, whereas autonomous AI agents require broad operational flexibility and creative context to be effective.
According to Michael Bargury, co-founder and CTO of Zenity, every enterprise deploying agents in the cloud must navigate this fundamental tension between agency and least privilege. When organizations deploy customer-facing chatbots and internal finance or engineering agents side by side in the same shared cloud environment without robust isolation, a single weak point can collapse the boundaries of the entire deployment.
Best Practices for Mitigation
Following responsible disclosure by Zenity Labs on December 25, 2025, Amazon Web Services (AWS) implemented critical security updates. AWS made IMDSv2 the default for AgentCore deployments and tightened default execution role permissions, removing overly broad capabilities that previously permitted cross-agent invocation, secret retrieval, and private conversation access.
To protect cloud environments against similar AI cloud vulnerabilities, security teams should implement the following architectural safeguards:
- Enforce Strict Scoping and Least Privilege: Ensure that every individual AI agent operates under a tightly scoped IAM role restricted exclusively to its necessary functions, preventing lateral movement to other agents or regions.
- Adopt IMDSv2 and Restrict Metadata Access: Mandate the use of IMDSv2 across all cloud workloads and AI containers to mitigate metadata-based credential theft and server-side request forgery (SSRF) vectors.
- Isolate Public and Internal Workflows: Separate customer-facing, public-facing generative AI applications from sensitive internal databases, internal agent networks, and administrative tools through strict network segmentation and API gateways.
- Audit Agent Memory and Tooling: Regularly inspect long-term memories, tool definitions, and retrieval-augmented generation (RAG) pipelines for unauthorized persistence mechanisms, prompt injection vulnerabilities, and unintended data access paths.
By addressing these architectural intersections between cloud infrastructure and artificial intelligence, organizations can harness the transformative power of generative AI while maintaining robust defense-in-depth across their cloud environments.
Related reading: AI Cloud Vulnerabilities in Collaboration Tools: Custom File Blocking in Microsoft Teams and AI Cloud Vulnerabilities: ConfigConfusion and Why Your Kubernetes Operator Owns Your GCP Estate.