AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it.
Intezer, in research with Kodem Security, found… Continue reading AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code