kapynBig Tech

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

A single prompt can hijack all Bedrock AgentCore agents in an AWS account. Zenity Labs discovered that an exposed internal AWS interface for temporary cloud credentials lets an attacker take over every agent in the same region. AWS has patched the flaw and tightened default permissions.

The Decoder·Oct 8, 2026

Opening Kapyn…