CyberSecurity News
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
AI summary
Cybersecurity researchers have found a vulnerability in Amazon Kiro, an AI-powered integrated development environment, that can be exploited to exfiltrate sensitive data. The vulnerability can be leveraged through prompt injection and Kiro Powers. It affects Kiro IDE version 0.7.45 on Windows, according to the researchers at Mindguard. The vulnerability does not have a CVE identifier assigned to it. The discovery was made by Mindguard, which has disclosed details of the security flaw. The issue is present in a specific version of the Kiro IDE, with the latest version potentially addressing the vulnerability.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

