logo

When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications

ID: 6b59961a-b749-5c8a-a554-d597857369ea

STIX ID: report--6b59961a-b749-5c8a-a554-d597857369ea

Feed Name: Palo Alto Networks Unit 42

Threat Score
45/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: Jay Chen and Royce Lu

...
...

This red-team assessment explores how prompt-injection across Amazon Bedrock multi-agent orchestration (Supervisor and Supervisor-with-Routing modes) can be chained to discover collaborator agents, extract internal instructions and tool schemas, and invoke tools with attacker-controlled inputs; the authors performed controlled tests (no Bedrock product flaws found), and demonstrate that enabling Bedrock pre-processing and Guardrails plus agent hardening (scoped capabilities, input validation, least privilege) mitigates the risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.