BREAKING
Hidden Text Hijacks AWS Kiro AI
How The Attack Worked
1Hide text in web page
2User asks Kiro to summarize
3Overwrite mcp.json config
4Attacker code runs
Approval Prompt Was Bypassed
0s
exfiltration interval
0
data types leaked
Disclosure And The Fix
The FlawJuly 2025
Indirect prompt injection
No CVE, no bug bounty
The Fixv0.1.42
Config changes need approval
Supervised operating mode
Treat Agent Input As Hostile
AI NEWS BLITZ
Invisible web-page text tricked AWS's Kiro coding assistant into running attacker code.