The Decoder· Jonathan Kemper·· 22 小时前
Zenity Labs 披露 AWS Bedrock AgentCore 存在“AgentCorruption”漏洞,单个公开 Agent 可接管同区域所有 Agent
One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
SI 导读
Zenity Labs 发现 AWS Bedrock AgentCore 存在名为“AgentCorruption”的漏洞,攻击者仅需访问一个公开 Agent 即可利用默认权限接管同 AWS 账户和区域内所有 Agent。研究人员通过窃取元数据服务凭证,实现读取私有对话、下载源代码及篡改长期记忆,AWS 已默认启用 IMDSv2 并收紧默认角色权限以修复该问题。
SI 评分39
来源:The Decoder · the-decoder.com