Web Hack List

Preliminary research

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Managed agent tools keep the cloud instance metadata endpoint reachable from inside them, so JavaScript in AWS Bedrock AgentCore's browser or Python in its code interpreter can fetch the microVM's IAM role credentials; a hidden div on a page the agent visits is enough to make it do so and exfiltrate them. The harnesses give up more: a tool-call block sent as the last message makes Strands run that tool with no model call, and Google ADK accepts a forged approval event.

Record

Researcher
Aviyam Ivgi and Hedi Ingber
Published by
i.blackhat.com
Format
Whitepaper
Topic
AI

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aviyam Ivgi and Hedi Ingber, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .