A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Cybersecurity Classified by Officially
Unit 42 researchers have identified an issue where using default configurations in Amazon Web Services (AWS) AgentCore Harness could allow attackers to steer an agent's actions through prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity.
To reach that finding, we examined two of the harness's many integrations:
AWS AgentCore Identity provides encryption at rest, encryption in transit, key management service (KMS) keys and identity and access management (IAM)-gated access. We wanted to know what happens at runtime, when a credential has to leave the vault to be used. What we found was that the harness's own built-in shell tool, which is enabled by default, reaches into the same memory space where credentials are resolved to plaintext.
We disclosed this finding to AWS. AWS reviewed and closed the report as informative under the AgentCore shared responsibility model, citing allowedTools scoping and egress filtering as customer-side controls.
For operators building on AgentCore today, defense takes a layered approach:
Palo Alto Networks customers are better protected from the threats discussed in this article through the following products and services:
Unit 42 Cloud Security Assessment is an evaluation service that reviews cloud infrastructure to identify misconfigurations and security gaps.
If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
This is an extract. The publication continues at the source.
Read the original at the source: https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Palo Alto Networks Unit 42 — imported from official source
- Official source
- https://unit42.paloaltonetworks.com/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://unit42.paloaltonetworks.com/?p=187347