Security researchers at Zenity Labs sent a single message to an AI agent that faces the public on Amazon's AgentCore platform, and came away with access to every other agent in that company's account and region. Amazon has narrowed what its agents can do by default since, but the way the attack worked shows how agents need to be set up.
The agent did what it was built to do
The agent had a common tool: it could make outbound web requests. The message asked it to call the internal address that cloud machines use to learn who they are and what they may do. That address hands out temporary credentials to whatever machine asks. A machine should be allowed to ask. A stranger steering the machine from a chat window should not, but the platform let the request through, and the agent handed back a full set of working credentials.
Those credentials belonged to a default role shared by all AgentCore agents in the account and region, not to the one agent that was talking. With them, the researchers could list the other agents and call the internal ones. They read private conversations and long-term memories, downloaded the agents' container images to read their source code, and pulled API keys and login tokens from the account's secrets store. Taking away the web tool would not have helped, because the researchers got the same result through other tools that can send traffic out.
A planted memory keeps working after the attacker leaves
The researchers also wrote false memories into agents, including an instruction to send every future conversation to an address they controlled. After that, users kept talking to what looked like their normal company assistant, and each conversation was copied out. Reading data is a one-time loss. A planted instruction is a leak that runs until somebody finds the memory.
For example, a clinic group might run a public appointment-booking agent and an internal billing agent in the same account. The billing agent's conversations contain patient names and invoice amounts. Under the old default, a stranger who got the booking agent to fetch its credentials could read every billing conversation and leave a memory that forwards the next ones. The stranger never breaks into the clinic's systems; they chat with the front desk.
What to do about it
After the problem was reported in December 2025, Amazon made the safer setting for that internal address the default. Zenity's testing then showed that the default role no longer allowed agents to call other agents, read private conversations or open stored secrets. Amazon's own position is that the agents behaved as documented, which means safe setup is partly the customer's job. Other researchers have found different routes to the same kind of credentials on this platform in 2026, so closing one route does not settle the matter.
The lasting defence is the one that would have limited the Capital One breach: give every agent its own role with only the access its job needs, and keep agents that talk to the public apart from agents that hold private data, ideally in separate accounts. A booking agent needs the calendar. It has no reason to open the billing agent's secrets. Check which role each of your agents runs under rather than trusting the new default to have reached them.