<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Aws-Agentcore on CuraSec</title><link>https://curasec.metacog.co.kr/tags/aws-agentcore/</link><description>Recent content in Aws-Agentcore on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 18 Sep 2026 14:58:07 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/aws-agentcore/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS AgentCore Harness default configs enable prompt-injection credential theft</title><link>https://curasec.metacog.co.kr/insights/2026-09-18-a-vault-with-a-heap-view-the-uncomfortable-space-between-age/</link><pubDate>Fri, 18 Sep 2026 14:58:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-18-a-vault-with-a-heap-view-the-uncomfortable-space-between-age/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you run AWS AgentCore Harness for AI agent workloads, audit your default IAM role assignments and trust boundaries this quarter — the research identifies specific misconfigurations that allow injected prompts to reach credential storage. No active exploitation or PoC noted, but the hardening steps are concrete and low-effort.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The prompt-injection-to-credential-exfiltration path in AI agent runtimes is a maturing attack class worth understanding for future detection coverage, but no IOCs, active campaigns, or ATT&amp;amp;CK mappings are surfaced here to act on today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This illustrates the emerging risk of AI agent frameworks inheriting over-privileged identities — useful context for shaping an AI/LLM agent governance policy before the attack surface grows, but no immediate leadership action is required.&lt;/li>
&lt;/ul></description></item></channel></rss>