threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of MCP server configurations without user approval, granting attackers access to sensitive secrets like… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials