# Zenity Labs warns of AgentCorruption flaw in Amazon Bedrock AgentCore

> Research reveals a chain of bugs that let a single prompt control all AgentCore agents in an AWS account and region.

Oossa · 2026-10-08 · https://oossa.com/en/zenity-labs-warns-of-agentcorruption-flaw-in-amazon-bedrock-agentcore

Zenity Labs announced on October 8, 2026 that it has found a set of security bugs in Amazon Bedrock’s AgentCore platform. The researchers call the issue “AgentCorruption.” A single malicious prompt can hijack every AgentCore agent running in the same AWS account and region. Zenity Labs says the flaw could let an attacker issue commands, read data, or launch further attacks across all agents that use the service.

## What the flaw does

AgentCore agents share a common runtime environment in each AWS region. The discovered chain of flaws lets a crafted prompt corrupt the shared state, then propagate that corruption to every other agent that later starts. Once the state is corrupted, the attacker can issue commands that the platform treats as legitimate. Zenzen Labs has not disclosed a public exploit, but it warns that any organization using AgentCore should treat the risk as serious until Amazon releases a fix.

## The facts

- Zenity Labs disclosed the AgentCorruption research on Oct 8, 2026.
- The flaw affects Amazon Bedrock AgentCore agents across an entire AWS account and region.
- A single malicious prompt can take over all AgentCore agents in that scope.
- Zenity Labs presented the findings at the AI Agent Security Summit.

## Why it matters

If your company runs applications built on Amazon Bedrock AgentCore, a single compromised prompt could give an attacker control over all those applications in the same AWS region. Until Amazon patches the issue, you may need to audit and limit the use of AgentCore or apply additional isolation measures.

## Sources & references

1. [Zenity Labs Discloses AgentCorruption, a Chain of AWS AgentCore Flaws That Allowed One Prompt to Take Over All AgentCore Agents Within an AWS Account and Region](http://www.businesswire.com/news/home/20261008316155/en/Zenity-Labs-Discloses-AgentCorruption-a-Chain-of-AWS-AgentCore-Flaws-That-Allowed-One-Prompt-to-Take-Over-All-AgentCore-Agents-Within-an-AWS-Account-and-Region/?feedref=JjAwJuNHiystnCoBq_hl-WsGkFyUNMTSNrPsg57HLEqqcp-o_pnudlUwsb5apQ1S4gUE65BTfjH3-pSuqdv0gW3cb3F4oTIgUqCPafFkgu5AneicJQDNboWvodvG82E0) – Business Wire, 2026-10-08

Last updated: 2026-10-08
