Security Flaws in AWS, Google, and Vercel AI Agent Infrastructure Allow Tool Triggering Without Model Execution

Security researchers at Black Hat USA 2026 revealed "CoreBreak" flaws in AI agent infrastructure from AWS (AgentCore's InvokeHarness API), Google (Agent Development Kit for Python), and Vercel (AI SDK harness packages), allowing attackers to trigger agent tools with untrusted instructions, bypassing model-level guardrails. AWS, Google, and Vercel have released patches.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai