AWS AgentCore prompt injection exposes credential risks

Palo Alto Networks’ Unit 42 researchers have demonstrated how an indirect prompt-injection attack against AWS’ AgentCore Harness could be used to extract plaintext credentials managed by AgentCore Identity. The researchers said the attack worked with a default Harness configuration, combining malicious instructions embedded in external content with its built-in shell tool. AWS reviewed the disclosure […]

The post AWS AgentCore prompt injection exposes credential risks appeared first on Cloud Computing News.