Zenity researchers discovered a critical vulnerability in AWS Bedrock AgentCore that allowed attackers to hijack all AI agents in an AWS account through a single prompt to one public agent. The flaw stemmed from improper isolation and overly broad default permissions, enabling access to credentials, source code, and private data. AWS has partially patched the issue but recommends companies implement stricter access controls.