Zenity披露Bedrock AgentCore提示词漏洞
Get the story
Zenity Labs 研究人员披露 Amazon Bedrock AgentCore 存在安全漏洞。2026年10月8日,The Decoder 报道,Zenity 称攻击者只需访问一个公开智能体,即可接管同一 AWS 账户和区域内的全部 AgentCore 智能体,读取私有对话、源代码和存储凭据。随后 The Next Web 报道,Zenity 将该漏洞命名为 AgentCorruption,称研究人员利用一条提示词,通过一个面向公网的智能体接管同一 AWS 账户和区域内的所有 AgentCore 智能体。两篇报道在影响范围上一致,均未提及 AWS 官方回应、修复状态或受影响版本。
Generated from reports · updated 2 hr ago
Timeline
Follow the coverage from different angles.
- The Next Web · AIZenity 披露 AgentCorruption:一条提示词接管 AWS AgentCore 区域内智能体
Zenity Labs 研究人员利用一条提示词,通过 Amazon Bedrock AgentCore 上一个面向公网的智能体接管同一 AWS 账户和区域内的所有 AgentCore 智能体。
- The Decoder精选Zenity 称单个提示词可接管 AWS 账户内所有 AgentCore 智能体
Zenity Labs 研究人员称,在 Amazon Bedrock AgentCore 上只需访问一个公开智能体,就能接管同一 AWS 账户和区域内的全部 AgentCore 智能体,读取私有对话、源代码和存储凭据。
Heat trend
Current heat 19·Comparable peak 19(Oct 8)·Comparable change over 24 hours –
The trend compares only the same participants observed continuously; its range may be smaller than the current heat count. Move or click on the chart to inspect hourly heat; use the left and right arrow keys to switch.