跳到正文
The Decoder· Jonathan Kemper·· 2 小时前精选AI 评分78

Zenity 研究发现单条提示词即可接管 AWS Bedrock AgentCore 同账号全部智能体

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

AI 导读

安全公司 Zenity Labs 研究人员发现,仅凭与 Amazon Bedrock AgentCore 一个公开智能体的聊天入口,用一条提示词就能接管同一 AWS 账号和区域内所有 AgentCore 智能体,该漏洞链被命名为 AgentCorruption。

推荐理由

文章还原了从一条提示词到接管全账号的完整攻击链和厂商整改过程,可用于评估云上智能体默认权限的风险面。

来源:The Decoder · the-decoder.com