Zenity 发现一个提示词即可劫持 AWS 账户内全部 Bedrock 智能体
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
安全团队 Zenity 演示了一条提示词就能拿下整个 AWS 账户里的所有 Bedrock 智能体,靠的是临时凭证接口权限失控,AWS 已打补丁。
Zenity Labs 研究人员发现,Amazon Bedrock AgentCore 上一个公开可访问的智能体,可被单条提示词利用,进而控制同一 AWS 账户和区域内所有 AgentCore 智能体。攻击路径是智能体可无限制访问 AWS 内部的临时云凭证接口。AWS 已修复该问题,并大幅收紧了智能体的默认权限。
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Zenity Labs researchers say a single publicly accessible AI agent on Amazon's Bedrock AgentCore was enough to take over every AgentCore agent in the same AWS account and region. The attack exploited an internal AWS interface for temporary cloud credentials that agents could reach without restriction. AWS has since patched the issue and significantly tightened the agents' default permissions. The article A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found appeared first on The Decoder .