build1 publisher
A malicious support ticket moved an AgentCore agent's vault token to an attacker endpoint
AWS closed Unit 42's AgentCore finding as informative and put tool scoping on the customer. Every step the agent took to leak the token was a capability someone granted it on purpose. That moves the control into the grant list.
Publishers:dev.to
Reality
- Evidence36
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence45