LIVE NEWS
  • FDA-approved drug may finally help immunotherapy defeat rare liver cancer
  • Venezuela Live Updates: Rescuers Search for Quake Survivors as Leader Calls to ‘Militarize’ Area
  • Euro holds amid Middle East risk as Polymarket hikes July Fed hold odds to 81.5%
  • Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
  • StubHub blames FIFA after World Cup resale tickets go missing : NPR
  • Venezuela Earthquakes Live Updates: Death Toll Rises to 589 as Rescuers Search for Survivors
  • Universal sets ‘Donkey’ spinoff film for June 2028 theatrical release (CMCSA:NASDAQ)
  • House, mostly, backs $1.5B White House moves to fund E-7 Wedgetail
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Cybersecurity

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

primereportsBy primereportsJune 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Share
Facebook Twitter LinkedIn Pinterest Email


Researchers at Wiz have disclosed a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could allow attackers to steal developers’ cloud credentials by luring them into opening a booby-trapped code repository.

Amazon Q Developer is an AI-powered coding assistant that offers developers features such as code suggestions, automated refactoring, and access to external tools and services via integrations with local processes.

AWS was notified about the issue on April 20 and a patch was released on May 12. The cloud giant published a security advisory this week.

The root cause of the vulnerability was that the extension would automatically act on configuration files embedded in a workspace without first asking the user for permission. 

That meant a malicious repository could quietly run attacker-controlled commands in the background the moment a developer opened it, gaining access to whatever cloud credentials and API keys were loaded in their environment at the time.

Attack path examples include fake coding tests like those used by North Korean hackers, a typosquatted open source package, or a malicious pull request to a popular project, Wiz said.

Advertisement. Scroll to continue reading.

Developers authenticated to AWS or other cloud services would be particularly exposed, since active session credentials could be captured and exfiltrated without any visible warning.

“The combination of auto-execution, shell spawning, and environment inheritance created a high-severity vulnerability in a widely-used developer tool. A single malicious repository could compromise not just the developer’s local machine, but their cloud infrastructure as well,” Wiz noted.

AWS has patched the vulnerability, tracked as CVE-2026-12957, and a related issue involving symbolic link handling (CVE-2026-12958). 

Fixes are available across all affected Amazon Q Developer plugins covering VS Code, JetBrains, Eclipse, and Visual Studio, as well as the language server. 

“We would like to thank Wiz for collaborating with us on this issue. We have remediated this issue in language server version 1.65.0,” an AWS spokesperson told SecurityWeek.

“The AWS Language Server updates automatically unless the customer’s network configuration prevents it, so no action is required in most cases. For existing customers, reloading the IDE will trigger an update to the latest language server version, which includes this fix. If auto-update is blocked, we recommend upgrading to the latest version of the Amazon Q Developer plugin for your IDE. New customers require no action, as the latest patched version will be downloaded automatically,” the AWS spokesperson added.

Wiz noted that the underlying issue is not unique to Amazon Q; other researchers have identified similar problems in VS Code and other AI coding tools, including Claude and Cursor.

The Google-owned cloud security giant published technical details and PoC code on Friday.

Related: GitLab Patches Code Execution, Information Disclosure Vulnerabilities

Related: 25-Year-Old Vulnerability Patched in Curl

Related: Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleStubHub blames FIFA after World Cup resale tickets go missing : NPR
Next Article Euro holds amid Middle East risk as Polymarket hikes July Fed hold odds to 81.5%
primereports
  • Website

Related Posts

Cybersecurity

Proof’s x401 establishes an open protocol for AI agent identity and authorization

June 26, 2026
Cybersecurity

FCC passes new cybersecurity rules for emergency systems, undersea cables

June 25, 2026
Cybersecurity

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • FDA-approved drug may finally help immunotherapy defeat rare liver cancer
  • Venezuela Live Updates: Rescuers Search for Quake Survivors as Leader Calls to ‘Militarize’ Area
  • Euro holds amid Middle East risk as Polymarket hikes July Fed hold odds to 81.5%
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.