# Zenity claims AgentCore attack reached agents across one AWS account

_Published Thursday, October 8, 2026 at 12:14 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![Zenity claims AgentCore attack reached agents across one AWS account — Primary](https://media.thenextweb.com/2026/08/zenity-ai.jpg)

Zenity Labs disclosed research on Thursday claiming that one prompt to a public-facing Amazon Bedrock AgentCore agent enabled access to other agents within the same AWS account and region. AWS disputes the characterization as a vulnerability, saying the behavior is expected and documented.

The researchers used an agent's web-request tool to retrieve temporary execution-role credentials from AWS's instance metadata service. Zenity says broad role permissions then allowed access to agent code, private conversations and stored secrets, while planted memories enabled persistent instructions.

On 29 September, Zenity found AWS had narrowed the role, removing permissions to invoke other agents, read private conversations and access Secrets Manager.

## Sources

- [The Next Web](https://thenextweb.com/news/aws-agentcore-zenity-agentcorruption-one-prompt-agents)

---
Canonical: https://techandbusiness.org/newswire/eSoN9w_Z7rn0PAdaPnk42B
Published: 2026-10-08T16:14:18.919Z
Story chronology: 2026-10-08T14:14:15.000Z
Retrieved: 2026-10-08T19:35:09.540Z
Publisher: Tech & Business (techandbusiness.org)
