The Decoder· Jonathan Kemper·· 3 小时前精选AI 评分78
Zenity Labs 发现单个提示词即可劫持 AWS 账号内全部 AgentCore 智能体
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
AI 导读
安全公司 Zenity Labs 发现 AWS Bedrock AgentCore 存在名为 AgentCorruption 的漏洞链,攻击者只需对一个公开智能体拥有聊天权限,用一条提示词就能接管同一 AWS 账号和区域内所有 AgentCore 智能体,读取私密对话、源代码和存储的凭证。
推荐理由
Zenity Labs 披露的 AgentCore 漏洞链条显示,默认权限过宽会让单个公开智能体波及同账号全部智能体。
来源:The Decoder · the-decoder.com