Threat Intelligence

Security Flaw Found in Amazon's AI Coding Tool Could Leak Sensitive Data

The Hacker News · 27 Aug 2026
Key Takeaway If your business uses AI-powered tools for coding or data handling, keep them updated and limit what sensitive data they can access, since AI systems can be tricked into leaking information.

Cybersecurity researchers have disclosed a vulnerability in Amazon Kiro, an AI-powered development environment used by programmers to write and manage code with the help of artificial intelligence. The flaw could allow attackers to exfiltrate sensitive data by exploiting 'prompt injection' — a technique where malicious instructions are hidden in content the AI processes, tricking it into performing unintended actions.

The issue was identified by security firm Mindguard and affects Kiro IDE version 0.7.45 running on Windows. According to researchers, the vulnerability specifically involves 'Kiro Powers,' a feature within the tool, which attackers could exploit to extract confidential information without the user's knowledge. At this stage, the flaw does not have an official vulnerability identifier (CVE), though details have been made public.

While this specific tool may not be widely used by small businesses today, the broader trend it highlights is important: AI-powered coding and productivity tools are becoming common attack targets. As more staff use AI assistants for coding, writing, or data analysis, businesses should be aware that these tools can be manipulated through cleverly crafted inputs, potentially exposing sensitive company or customer data.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.