Tartışma

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Başlatan The Hacker News · 21 Tem 2026 19:38 · 0 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it.

Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi