The Decoder· Jonathan Kemper·· 1 天前精选AI 评分66
AWS Bedrock AgentCore 被曝 AgentCorruption 漏洞,单个智能体可接管区域内全部实例
One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region
AI 导读
Zenity Labs 发现 AWS Bedrock AgentCore 存在名为 AgentCorruption 的漏洞链:一个公网可访问的智能体可通过一次对话窃取 AWS 临时凭证,进而接管同一账号与区域内全部 AgentCore 实例,读取其私有对话、源代码、存储密钥,并可篡改长期记忆。
推荐理由
把 AgentCorruption 攻击链、默认权限问题和 AWS 的修复时间线拆解清楚,方便在云上部署智能体的团队直接对照自身风险。
来源:The Decoder · the-decoder.com