跳到正文
The Decoder· Jonathan Kemper·· 23 小时前精选AI 评分79

Zenity Labs 发现单一公开 AgentCore 智能体可接管同账户同区域其他智能体

One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region

AI 导读

Zenity Labs 称,攻击者只需向 AWS Bedrock AgentCore 中一个公开智能体发送单条提示词,就能接管同一 AWS 账户和区域内的其他 AgentCore 智能体。该漏洞链可暴露私密对话、源代码和存储凭据,默认权限还允许读取、改写和删除其他智能体;AWS 在收到报告后将 IMDSv2 设为新部署默认值,并收紧了默认执行角色权限。

推荐理由

文章梳理了 AgentCore 隔离与默认权限问题如何串联成跨智能体接管路径,并交代 AWS 已采取的权限与元数据访问调整。

来源:The Decoder · the-decoder.com