Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Summary
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.