vulnerability Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers A vulnerability in Amazon Kiro, an AI-powered IDE, allows attackers to steal sensitive data by injecting malicious prompts and leveraging Kiro Powers. This flaw, currently unpatched, could lead to significant data breaches within organizations using the Kiro IDE. The Hacker News · 3d ago Medium prompt-injectionaiide
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide