Zenity Labs Uncovers Critical AWS AgentCore Flaws Allowing Full Account Takeover

  • Zenity Labs disclosed 'AgentCorruption', a chain of security flaws in AWS AgentCore that allowed a single prompt to compromise all agents within an AWS account and region.
  • Researchers accessed private conversations, cloud credentials, and source code, and implanted malicious memories to persistently manipulate agent behavior.
  • The vulnerabilities stemmed from overprivileged AWS IAM roles and AgentCore's infrastructure design, enabling lateral movement across agents.
  • AWS addressed the issues by making IMDSv2 the default and reducing default execution role permissions following Zenity Labs' responsible disclosure on December 25, 2025.

The AgentCorruption findings highlight the inherent tension between AI agent functionality and cloud security principles. As enterprises rapidly adopt AI agents, the balance between agent autonomy and least-privilege access will be a critical strategic challenge. This disclosure underscores the need for specialized security solutions as AI agents gain more autonomy and access to sensitive enterprise resources.

Cloud Security Dynamics
How AWS's remediation efforts will affect enterprise trust in AgentCore deployments and whether similar vulnerabilities exist in other cloud AI agent platforms.
AI Agent Governance
The pace at which enterprises will adopt stricter segmentation and least-privilege access controls for AI agents following this disclosure.
Market Impact
Whether Zenity Labs' research will position it as a leading authority in AI agent security, potentially attracting more enterprise clients.