跳到正文
千机 API
原文
The Decoder· Jonathan Kemper·· 1 天前精选AI 评分78

Zenity 研究发现,AWS Bedrock AgentCore 单个公开智能体可危及同区域所有智能体

One public-facing AI agent on AWS could read, rewrite, and delete every other agent in the region

AI 导读

Zenity Labs 研究人员称,攻击者只需向 Amazon Bedrock AgentCore 中一个公开智能体发送提示词,就能利用一系列漏洞控制同一 AWS 账户和区域内的所有 AgentCore 智能体。

推荐理由

这项披露具体呈现了公开智能体、凭证暴露与跨智能体默认权限如何串联成攻击路径,也交代了 AWS 后续收紧部分默认设置的变化。

来源:The Decoder · the-decoder.com