When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications
ID: 6b59961a-b749-5c8a-a554-d597857369ea
STIX ID: report--6b59961a-b749-5c8a-a554-d597857369ea
Feed Name: Palo Alto Networks Unit 42
This red-team assessment explores how prompt-injection across Amazon Bedrock multi-agent orchestration (Supervisor and Supervisor-with-Routing modes) can be chained to discover collaborator agents, extract internal instructions and tool schemas, and invoke tools with attacker-controlled inputs; the authors performed controlled tests (no Bedrock product flaws found), and demonstrate that enabling Bedrock pre-processing and Guardrails plus agent hardening (scoped capabilities, input validation, least privilege) mitigates the risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
