AWS AgentCore's Recurring Credential Flaws Expose a Structural Agentic Risk
Source
AWS's repeated problems with AI agent controls illustrates the autonomous agent dilemmaAWS / Palo Alto Networks Unit 42 / Zenity Labs
What happened
Researchers from Palo Alto Networks Unit 42 and Zenity Labs published findings documented in AWS's repeated problems with AI agent controls illustrates the autonomous agent dilemma showing that AWS AgentCore suffered multiple credential theft vulnerabilities across 2025 and 2026. Each patch AWS issued closed one attack route while leaving others open, a pattern the researchers describe as structurally inevitable. The root cause is not a coding error but an architectural tension. Broad access permissions let autonomous agents function across an AWS environment. Those same permissions also expose live login credentials, agent source code, and pathways into other systems within the same cloud region. The research builds on a growing body of agentic incident reporting, including prior findings on how agent permission boundaries fail under real attack conditions. It also reinforces concerns raised in coverage of CISA's consent-gate bypass in Amazon Strands Agents.
Why it matters
- ·Vendors can patch individual flaws without fixing the structural problem, so enterprises relying on cloud-provider patches as a primary control are carrying residual risk they may not have assessed. Compliance teams should not treat a vendor patch notice as proof that the access risk is resolved.
- ·Agentic AI deployments that operate with broad cloud permissions create a risk profile that falls outside traditional model-risk and cyber-risk frameworks. Programs built around NIST AI Risk Management Framework (AI RMF 1.0) and Playbook or equivalent internal standards may need explicit controls for agent credential scope, not just model behavior.
- ·Enterprises that deploy agents in AWS environments without explicit least-privilege scoping own that exposure. Regulators in multiple jurisdictions are beginning to treat deployer-side agent controls as a named compliance obligation.
Governance controls affected
What to do now
- ☐Ask your cloud and engineering teams to list every AWS AgentCore deployment and confirm what permissions each agent holds, specifically whether any agent has access beyond what a single, defined task requires.
- ☐Review whether your agentic AI vendor contracts specify which party is responsible for scoping agent access rights, and flag any contract where the enterprise has implicitly accepted that responsibility without controls in place.
- ☐Treat AWS patch notices for AgentCore as a trigger for a re-review of permission scope, not as a sign-off that the underlying access risk is resolved. Each patch cycle has historically opened a different attack path.
- ☐Ask your security team whether credentials used by AI agents are rotated on a schedule distinct from standard service accounts, and whether agent credential use is logged and monitored separately from human user activity.
- ☐Brief your AI governance committee on the structural nature of this risk: the problem is not a single flaw but a design tension in agentic systems that requires ongoing permission governance, not a one-time fix.
What to watch next
Regulators are beginning to name deployer-side agent controls as an explicit obligation rather than a vendor responsibility. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and emerging frameworks from South Korea and the EU are each moving toward prescriptive agent permission standards. Compliance teams should monitor whether cloud providers publish formal shared-responsibility matrices specific to agentic workloads. They should also watch whether enforcement actions begin citing deployer failures to scope agent credentials. The pattern of patch-and-repeat documented here is likely to appear in future regulatory guidance as a case study for why voluntary patching is insufficient without structural access governance.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI systems built to extend your reach are now extending attackers' reach too, and regulators in California and South Korea are making clear that containment failures belong to deployers, not just vendors.8 Oct
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
Free every Thursday. Unsubscribe anytime.
