Skip to main content

Tag: aws security

2 articles

Laptop screen on a clutter-free desk in an office setting displays blurred code.

AgentCore Harness Exposes Credential Risks

A default-enabled shell in AgentCore Harness can be exploited through prompt injection, allowing attackers to execute commands and extract plaintext credentials from the harness process memory, putting sensitive data at risk. This simple yet consequential chain highlights a critical vulnerability in credential security.

Analyst 207
Developer workstation with IDE open, laptop screen showing code, and terminal in background.

Amazon Q Developer Flaw Lets Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957, allowed malicious repositories to run commands and steal cloud credentials simply by being opened in an IDE. This vulnerability put developers at risk of having their sensitive AWS keys, cloud CLI tokens, and API secrets compromised.

Analyst 207