news.mlab.sh
Back to the feed
vulnerability

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

Critical
Summary

A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execution of configuration files without user consent created an opportunity for attackers to gain access to sensitive information like API keys and session credentials. AWS has released a patch, but the issue highlights a broader risk in AI-powered coding tools.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.