Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

General News

Summary

Researchers disclosed a high-severity flaw in Amazon Q Developer for VS Code that could let a malicious repository steal cloud credentials from a developer’s environment. The issue came from automatic execution of workspace configuration files without user permission. AWS released patches across the affected Amazon Q plugins and language server, and it said most customers will update automatically or only need to reload their IDE. Wiz also pointed out that similar risks can affect other AI coding tools, making this a broader developer-security concern.

Classifications

industries
Entertainment
applications
Anti Piracy

AskAI Classifications

Labels
SaaS Shipping Software Inventory Management Software

Linked Companies

Wiz, Inc.
$50M to $100M