Security researchers found a way to fire agent tools without running the model. amazon bedrock's…
security researchers found a way to fire agent tools without running the model. amazon bedrock's agentcore, google's adk and vercel's ai sdk harness all had the flaw, reported september 16.
the tool layer became the attack surface.
Context
The Hacker News, a secondary trade outlet, reported on August 6, 2026 that AWS, Google and Vercel patched agent flaws, citing researchers Hedi Ingber and Aviyam Ivgi, named as co-founders of Stealth, who presented a pattern they call CoreBreak at Black Hat USA 2026. Per that report, an AWS bulletin CVE-2026-18830 (CVSS v4.0 8.6) covered the managed InvokeHarness, fixed before July 31 with no customer action. Google ADK Python before 2.5.0 had CVE-2026-18236 (9.3), a confirmation-forgery path, and Vercel patched @ai-sdk/harness-codex 1.0.29 and @ai-sdk/harness-opencode 1.0.28.
No primary vendor advisory was inspected, so versions and scores are unverified beyond that one secondary report. The report says the conditions differ: AWS needed an authenticated remote request, Google needed attacker-controlled session events or user-authored function calls, and Vercel needed untrusted code already inside a Linux sandbox, so all had the flaw compresses three different issues. The researchers say an AWS Strands open-source path remains with documentation and no code fix, which was not independently verified. No source dated September 16 was found, a later Cloud Security Alliance note of September 19 was seen only as a snippet, and no exposure of any particular owner is inferred. The tool layer became the attack surface is the author's take.
Watch next
- First-party AWS, Google and Vercel advisories.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 22 September 2026 at 20:39 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →