AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Unit 42 and Zenity say AWS AgentCore defaults let prompt injection steal credentials and move across agents.
Palo Alto Networks Unit 42 and Zenity Labs describe repeated AWS AgentCore security failures that reappeared after fixes. In September 2026, Unit 42 reported that default Harness settings let prompt injection use a built-in root shell to exfiltrate plaintext credentials from AgentCore Identity; AWS closed that report as informative. An earlier flaw left the microVM metadata service without session-token enforcement, which could have allowed SSRF credential theft. Zenity showed an agent returning live STS credentials that worked outside the sandbox, enabling image pulls, access to other agents' code and conversations, and regional lateral movement, and said that specific path was fixed as of October 8.