news.mlab.sh
Back to the feed
threat-intel

Amazon Q VS Extension Flaw Leads to Cloud Credential Theft

High
Image: Dark Reading
Summary

A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of MCP server configurations without user approval, granting attackers access to sensitive secrets like AWS credentials and API keys. This highlights a growing risk within AI infrastructure and underscores the importance of secure coding practices and developer vigilance.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.