Web Hack List

Preliminary research

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Managed agent tools keep the cloud instance metadata endpoint reachable from inside them, so JavaScript in AWS Bedrock AgentCore's browser or Python in its code interpreter can fetch the microVM's IAM role credentials; a hidden div on a page the agent visits is enough to make it do so and exfiltrate them. The harnesses give up more: a tool-call block sent as the last message makes Strands run that tool with no model call, and Google ADK accepts a forged approval event.

Record

Researcher
Aviyam Ivgi and Hedi Ingber
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aviyam Ivgi and Hedi Ingber, first published at the original source. Preserved copies are kept so the citation survives its host.