Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Prompt Injection Flaw in AWS AgentCore Harness Can Leak Credentials

Security researchers at Unit 42 found that default configurations in AWS AgentCore Harness create a gap between the agent runtime and identity management, allowing prompt injection attacks to exfiltrate credentials from agents.

Disclosed 18 September 2026 · Record updated 18 September 2026

Impact

Default configurations in AWS AgentCore Harness can allow attackers to use prompt injection to exfiltrate credentials from agents, exposing an identity/credential management gap.

Our coverage

Sources

  1. unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials