Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    What happens to older devices when Secure Boot Certificates expire

    June 26, 2026

    Amazon Prime Day deal cuts the Nothing Ear (a) to just $53

    June 26, 2026

    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

    June 26, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
    Cybersecurity

    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

    The Tech GuyBy The Tech GuyJune 26, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Researchers at Wiz have disclosed a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could allow attackers to steal developers’ cloud credentials by luring them into opening a booby-trapped code repository.

    Advertisement

    Amazon Q Developer is an AI-powered coding assistant that offers developers features such as code suggestions, automated refactoring, and access to external tools and services via integrations with local processes.

    AWS was notified about the issue on April 20 and a patch was released on May 12. The cloud giant published a security advisory this week.

    The root cause of the vulnerability was that the extension would automatically act on configuration files embedded in a workspace without first asking the user for permission. 

    That meant a malicious repository could quietly run attacker-controlled commands in the background the moment a developer opened it, gaining access to whatever cloud credentials and API keys were loaded in their environment at the time.

    Attack path examples include fake coding tests like those used by North Korean hackers, a typosquatted open source package, or a malicious pull request to a popular project, Wiz said.

    Advertisement. Scroll to continue reading.

    Developers authenticated to AWS or other cloud services would be particularly exposed, since active session credentials could be captured and exfiltrated without any visible warning.

    “The combination of auto-execution, shell spawning, and environment inheritance created a high-severity vulnerability in a widely-used developer tool. A single malicious repository could compromise not just the developer’s local machine, but their cloud infrastructure as well,” Wiz noted.

    AWS has patched the vulnerability, tracked as CVE-2026-12957, and a related issue involving symbolic link handling (CVE-2026-12958). 

    Fixes are available across all affected Amazon Q Developer plugins covering VS Code, JetBrains, Eclipse, and Visual Studio, as well as the language server. 

    “We would like to thank Wiz for collaborating with us on this issue. We have remediated this issue in language server version 1.65.0,” an AWS spokesperson told SecurityWeek.

    “The AWS Language Server updates automatically unless the customer’s network configuration prevents it, so no action is required in most cases. For existing customers, reloading the IDE will trigger an update to the latest language server version, which includes this fix. If auto-update is blocked, we recommend upgrading to the latest version of the Amazon Q Developer plugin for your IDE. New customers require no action, as the latest patched version will be downloaded automatically,” the AWS spokesperson added.

    Wiz noted that the underlying issue is not unique to Amazon Q; other researchers have identified similar problems in VS Code and other AI coding tools, including Claude and Cursor.

    The Google-owned cloud security giant published technical details and PoC code on Friday.

    Related: GitLab Patches Code Execution, Information Disclosure Vulnerabilities

    Related: 25-Year-Old Vulnerability Patched in Curl

    Related: Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Linux Foundation Unveils New Open Source Security Project Akrites

    June 26, 2026

    Philip Martin Joins Uber as Chief Information Security Officer

    June 26, 2026

    Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

    June 25, 2026

    Runlayer Raises $30 Million in Series A Funding

    June 25, 2026

    Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

    June 25, 2026

    Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk

    June 25, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202684 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202621 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    What happens to older devices when Secure Boot Certificates expire

    June 26, 2026

    Amazon Prime Day deal cuts the Nothing Ear (a) to just $53

    June 26, 2026

    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

    June 26, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.