The Decoder· Jonathan Kemper·· 4 小时前精选AI 评分80
Zenity 发现 AWS AgentCore 存在“AgentCorruption”漏洞:单条提示词可劫持账户内所有 AI 智能体
A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
AI 导读
Zenity Labs 研究人员发现 Amazon Bedrock AgentCore 存在名为“AgentCorruption”的系统性安全漏洞,攻击者仅需通过聊天界面向一个公开智能体发送单条提示词,即可利用平台隔离缺失和默认权限过宽问题,接管同一 AWS 账户和区域内所有 AgentCore 智能体。
推荐理由
Zenity 披露了 AWS AgentCore 的“AgentCorruption”漏洞链,展示了单一提示词如何导致账户内所有智能体被接管及数据泄露。
来源:The Decoder · the-decoder.com