
AWS Kiro IDE Flaw Lets Hidden Web Prompts Execute Code on Developer Machines
A critical vulnerability in AWS’s agentic IDE Kiro lets attackers hide malicious instructions inside ordinary web pages, tricking the AI agent into rewriting its own configuration file and executing arbitrary code on a developer’s machine without any suspicious approval prompt ever appearing. Kiro ships with tools that let the AI act autonomously, including web fetching, […]
The post AWS Kiro IDE Flaw Lets Hidden Web Prompts Execute Code on Developer Machines appeared first on Cyber Security News.