MediumNews
AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
- Published
- Record updated
Summary
Palo Alto Networks' Unit 42 and Zenity Labs researchers report that AWS has repeatedly patched autonomous agent security holes in AgentCore, and that the flaws have reappeared in slightly different forms. On September 18, 2026, Unit 42 reported that default configurations in AWS AgentCore Harness let attackers use prompt injection to steer the agent into exfiltrating plaintext credentials managed by AgentCore Identity, since the built-in shell tool, enabled by default, runs as root inside the harness. AWS closed that report as informative under its shared responsibility model.
Topics
Related items
- InfoHow to keep AI agents within their permissionsSame vendor · BleepingComputer
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSame vendor · Dark Reading
- InfoSpaceXAI backs Omarchy, the controversial Linux distro, with $1.5 million in computeSame vendor · The Verge (AI)
- InfoAWS takes aim at runaway AI agent behavior with Strands BoxSame vendor · CSO Online
- MediumTop MCP security resources — October 2026Same vendor · Adversa AI Blog