Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Read full story on The Hacker News
Share
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
AI disclosure

Summary

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.