The Decoder· Jonathan Kemper·· 2 天前精选AI 评分80
Zenity Labs:一个公开 AI 智能体可接管 AWS 账户内全部 AgentCore 智能体
One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
AI 导读
安全公司 Zenity Labs 发现 Amazon Bedrock AgentCore 存在一串被其称为 AgentCorruption 的漏洞:攻击者只需对一个公开智能体拥有聊天权限,用一条提示词就能接管同一 AWS 账户和区域内所有 AgentCore 智能体,读取私密对话、源代码和存储的凭证。
推荐理由
Zenity Labs 披露 AWS AgentCore 默认权限可让单个公开智能体接管同区域全部智能体,并给出 AWS 的修复动作。
来源:The Decoder · the-decoder.com