跳到正文
原文
The Decoder· Jonathan Kemper·· 4 小时前精选AI 评分80

Zenity 发现 AWS AgentCore 存在“AgentCorruption”漏洞:单条提示词可劫持账户内所有 AI 智能体

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

AI 导读

Zenity Labs 研究人员发现 Amazon Bedrock AgentCore 存在名为“AgentCorruption”的系统性安全漏洞,攻击者仅需通过聊天界面向一个公开智能体发送单条提示词,即可利用平台隔离缺失和默认权限过宽问题,接管同一 AWS 账户和区域内所有 AgentCore 智能体。

推荐理由

Zenity 披露了 AWS AgentCore 的“AgentCorruption”漏洞链,展示了单一提示词如何导致账户内所有智能体被接管及数据泄露。

来源:The Decoder · the-decoder.com