Zenity Labs announced on October 8, 2026 that it has found a set of security bugs in Amazon Bedrock’s AgentCore platform. The researchers call the issue “AgentCorruption.” A single malicious prompt can hijack every AgentCore agent running in the same AWS account and region. Zenity Labs says the flaw could let an attacker issue commands, read data, or launch further attacks across all agents that use the service.
What the flaw does
AgentCore agents share a common runtime environment in each AWS region. The discovered chain of flaws lets a crafted prompt corrupt the shared state, then propagate that corruption to every other agent that later starts. Once the state is corrupted, the attacker can issue commands that the platform treats as legitimate. Zenzen Labs has not disclosed a public exploit, but it warns that any organization using AgentCore should treat the risk as serious until Amazon releases a fix.
Why it matters
If your company runs applications built on Amazon Bedrock AgentCore, a single compromised prompt could give an attacker control over all those applications in the same AWS region. Until Amazon patches the issue, you may need to audit and limit the use of AgentCore or apply additional isolation measures.