Vulnerabilities · 6h ago
On September 18, Unit 42 said AWS AgentCore Harness in its default configuration could be steered by prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. The same research team had already flagged a different AgentCore credential path in April, which shows AWS keeps running into the same class of problem in different forms.
The harness’s built-in shell is enabled by default, runs as root, and reaches the same memory space where secrets are resolved into plaintext. Once an attacker gets the agent to run a command, that command inherits the agent’s privileges and can read whatever the agent itself can see.
That pushes the security boundary up to identity, memory, and tool scope rather than one prompt route. For teams using autonomous agents with shared tools and secret access, closing one injection path does not end the underlying exposure if the agent can still read and act with the same privileges.
2 sources covering this story
'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
A now-patched vulnerablity in AWS Bedrock AgentCore could allow attackers to use one AI chatbot to take over an organization's entire fleet of AI agents.
AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Agents have repeatedly been tricked into revealing credentials, and patching one attack path has still left others open.
Part of the PlainSec briefing for 2026-10-08