AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-1 of 1 results

DateProviderScoreSummary
27 Aug 2026, 9:39 PMThe Hacker News6.5 Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Mindguard disclosed a prompt injection vulnerability in Amazon Kiro IDE (version 0.7.45 on Windows) that lets attacker-controlled repository content exfiltrate sensitive local data via Kiro Powers. Exploitation requires the user to open a malicious project via File → Open Workspace From File and then send any message to the agent—no malicious prompt needed. The latest IDE version is 1.0.337, and no CVE has been assigned.

Why: If you or your team use Amazon Kiro, update to 1.0.337 immediately and stop opening workspace files from untrusted repos via File → Open Workspace From File. The attack chain is notable because it requires no crafted prompt—just opening the workspace and sending any message triggers exfiltration through Kiro Powers' MCP server configs and steering files.

Top