threat-intel
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
High
Summary
A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of MCP server configurations without user approval, granting attackers access to sensitive secrets like AWS credentials and API keys. This highlights a growing risk within AI infrastructure and underscores the importance of secure coding practices and developer vigilance.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
_Kiattisak_Lamchan_Alamy.png?width=720&quality=80&disable=upscale)