PulseAugur
EN
LIVE 16:02:45

Amazon Kiro vulnerability allows data exfiltration via prompt injection

Researchers have discovered a critical vulnerability in Amazon Kiro, specifically affecting version 0.7.45 on Windows. This flaw allows malicious workspaces to exfiltrate local files through prompt injection attacks, potentially leading to data exfiltration. The issue has been addressed in version 0.8.140 of Kiro. AI

IMPACT This vulnerability highlights the risks of prompt injection in AI-powered tools, potentially impacting user trust and data security.

RANK_REASON Disclosure of a specific vulnerability and its fix in a software product.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Amazon Kiro vulnerability allows data exfiltration via prompt injection

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Disclosure of a specific vulnerability and its fix in a software product.
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
29 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [2]

  1. Mastodon — mastodon.social TIER_1 English(EN) · technoholic ·

    Cybersecurity researchers reveal a vulnerability in Amazon Kiro (IDE 0.7.45 on Windows) that could enable data exfiltration via prompt injection and Kiro Powers

    Cybersecurity researchers reveal a vulnerability in Amazon Kiro (IDE 0.7.45 on Windows) that could enable data exfiltration via prompt injection and Kiro Powers. # Cybersecurity # AI https:// thehackernews.com/2026/08/amaz on-kiro-prompt-injection-can.html

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    ⚠️ Kiro prompt injection leaks data A malicious workspace can make # Amazon # Kiro exfiltrate local files after any agent message; fixed in 0.8.140. 🔗 read more

    ⚠️ Kiro prompt injection leaks data A malicious workspace can make # Amazon # Kiro exfiltrate local files after any agent message; fixed in 0.8.140. 🔗 read more: https:// thehackernews.com/2026/08/amaz on-kiro-prompt-injection-can.html?utm_source=mastodon&utm_medium=social&utm_ca…