AWS published a reference architecture for Amazon Bedrock AgentCore that limits AI agents to the requesting user’s permissions by propagating end-user authorization context to downstream services instead of enforcing access control in agent code. In the design, users authenticate through Amazon Cognito, custom claims such as department are added to JWTs, and AgentCore Runtime validates those claims before the agent runs. AWS said this approach reduces the risk of unauthorized data exposure from prompt injection or application bugs because the agent acts as an orchestrator rather than a trusted gatekeeper.
The architecture demonstrates three enforcement patterns across common enterprise data sources: user-scoped temporary AWS credentials for Amazon DynamoDB using STS AssumeRoleWithWebIdentity and session tags, metadata-based filtering for Amazon Bedrock Knowledge Bases, and OAuth 2.0 on-behalf-of token exchange for Salesforce through AgentCore Identity. In the example CRM workflow, Sales and Finance employees can use the same agent while only receiving records allowed by their own roles, with AWS also recommending stronger isolation such as separate knowledge bases and IAM policies where stricter separation is required.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
AWS published a security blog describing a reference architecture for AI agents built with Amazon Bedrock AgentCore that propagates end-user authorization context to downstream services such as DynamoDB, Bedrock Knowledge Bases, and Salesforce. The design aims to enforce least-privilege access outside the agent itself, including against prompt injection or application bugs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.