Find notable cyber news and cases, enriched with sources, timelines, and signals.

Amazon Kiro IDE prompt injection data exfiltration security flaw

Vulnerability
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

Amazon Kiro IDE 0.7.45 on Windows was found to have a prompt injection vulnerability that let attacker-controlled repository content influence Kiro Powers and push sensitive local information to an external endpoint. The flaw enabled data exfiltration after a victim opened a malicious workspace file and sent a message, even without explicitly asking Kiro to access or transmit the data. Amazon released a fix in Kiro IDE 0.8.140 after responsible disclosure.

Related Happenings

Kiro prompt-injection config rewrite RCE remote code execution flaw

Vulnerability
H score31 First: 21.07.2026 19:06 Last: 21.07.2026 19:06 Sources 1

About this happening: AWS Kiro had a prompt-injection RCE vulnerability that let hidden web text rewrite ~/.kiro/settings/mcp.json and launch attacker-controlled code on a developer machine...

Checkmarx/kics Docker Hub repository hit by network compromise

Incident
H score36 First: 22.04.2026 20:55 Last: 22.04.2026 20:55 Sources 1

About this happening: Checkmarx's checkmarx/kics Docker Hub repository suffered a supply-chain compromise that could expose secrets from infrastructure-as-code scans. Unknown threat actor...

Cline AI coding assistant hit by network compromise

Incident
H score18 First: 09.03.2026 01:35 Last: 09.03.2026 01:35 Sources 1

About this happening: The Cline coding assistant suffered a supply-chain compromise that installed a rogue OpenClaw instance on thousands of systems, creating unauthorized full system...

Timeline

  1. 27.08.2026 16:39 2 articles · 6h ago

    Amazon Kiro IDE prompt injection flaw can exfiltrate sensitive local data

    Initial Disclosure

    Cybersecurity researchers disclosed a prompt injection flaw in Amazon Kiro IDE 0.7.45 on Windows that let attacker-controlled repository content influence Kiro Powers and transmit sensitive local information to an external endpoint after a victim opened a crafted workspace file and sent any message. Mindguard said the issue was reproducible in both trusted and untrusted workspaces, had low exploitation difficulty, and Amazon implemented a fix in Kiro IDE version 0.8.140.

    Show sources