The Decoder· Jonathan Kemper·· 1 天前精选AI 评分76
Zenity Labs 发现 AWS AgentCore 漏洞:一个公开智能体可接管同区域全部智能体
One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
AI 导读
安全公司 Zenity Labs 称,AWS 的 Bedrock AgentCore 存在一串被其命名为 AgentCorruption 的漏洞,攻击者只需对一个公开智能体拥有聊天权限,用一条提示词即可接管同一 AWS 账号和区域内的所有 AgentCore 智能体,读取私密对话、源代码和存储的凭证。
推荐理由
Zenity Labs 披露 AWS AgentCore 的默认权限与隔离缺陷,呈现了智能体平台在权限边界上的系统性风险。
来源:The Decoder · the-decoder.com