SOC2Prep

AWS agent tooling can leak credentials

October 6, 2026. From issue 9 of The Compliance Brief, one story for teams preparing for a first SOC 2 audit.

Last reviewed 2026-10-06Written by Jacob Masse, TrazTech Inc.

Issue 9 of The Compliance Brief went to subscribers on October 6, 2026. One of its 5 stories bears on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Infosecurity

Researchers reported flaws in the Amazon Bedrock AgentCore SDK that could allow an attacker to run commands inside AI sandboxes and reach AWS credentials. The issue sits in the agent runtime layer rather than in a customer's own application code.

Our take, in short

If you shipped an AI feature in the last year, it probably got a lighter design review than the rest of your product, and the credentials behind it are probably broader than they need to be. Treat the agent runtime as an untrusted execution environment: separate account, scoped role, no long-lived keys sitting where the model can see them.

Read the full take on traztech.ca

Also in issue 9

Outside the controls a SOC 2 audit tests, but in the same email:

Older: issue 8 All issues on SOC2Prep