BREAKING
Hidden Text Hijacks AWS Kiro AI
How The Attack Worked
1
Hide text in web page
↓
2
User asks Kiro to summarize
↓
3
Overwrite mcp.json config
↓
4
Attacker code runs
Approval Prompt Was Bypassed
0
s
exfiltration interval
0
data types leaked
Disclosure And The Fix
The Flaw
July 2025
●
Indirect prompt injection
●
No CVE, no bug bounty
The Fix
v0.1.42
●
Config changes need approval
●
Supervised operating mode
Treat Agent Input As Hostile
AI NEWS BLITZ
Invisible web-page text tricked AWS's Kiro coding assistant into running attacker code.