THREATOPS
THREAT OPSThreat News › Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

lowthehackernewsPublished 2026-08-27

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.

The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html