跳到正文
原文
The Decoder· Jonathan Kemper·· 22 小时前

Zenity Labs 披露 AWS Bedrock AgentCore 存在“AgentCorruption”漏洞,单个公开 Agent 可接管同区域所有 Agent

One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region

SI 导读

Zenity Labs 发现 AWS Bedrock AgentCore 存在名为“AgentCorruption”的漏洞,攻击者仅需访问一个公开 Agent 即可利用默认权限接管同 AWS 账户和区域内所有 Agent。研究人员通过窃取元数据服务凭证,实现读取私有对话、下载源代码及篡改长期记忆,AWS 已默认启用 IMDSv2 并收紧默认角色权限以修复该问题。

SI 评分39

来源:The Decoder · the-decoder.com

© 2026 SI·Hot · Super Intelligence Hot · 超级智能热点 · 网站数据均来源于网络公开资料,版权归来源方所有