Zenity Labs, a security firm, says its researchers took over every AI agent in one AWS account and region, starting from one exposed Amazon Bedrock AgentCore agent. Zenity says the agent needed any tool that can send outbound traffic, such as an HTTP or shell tool. Its test agent, built with AWS's Strands toolkit, was asked to fetch an internal metadata address. This trick is called server-side request forgery (SSRF). Zenity says the agent returned temporary cloud credentials that also worked from the researchers' own machine. Zenity says removing the web tool would not have helped, as the flaw is in the platform.
Zenity says the role's default permissions reached all agents in the account and region, so the researchers could pull other agents' code images. Zenity says AWS closed the report as "informative" on April 12, 2026, and that new agents have used the stricter IMDSv2 since February 14, 2026. The sources do not say whether older agents remain exposed or whether the default permissions changed. The Decoder noted that Zenity sells AI agent security tools.
WebPulse analysis, not a Zenity claim: if one role spans a whole region, a per-agent sandbox protects little, because one weak agent opens the rest. Teams running agents could ask: Which role does each agent run under? Do any roles use wildcard registry or log permissions?