Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
    Cybersecurity

    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

    The Tech GuyBy The Tech GuyJune 26, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Researchers at Wiz have disclosed a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could allow attackers to steal developers’ cloud credentials by luring them into opening a booby-trapped code repository.

    Advertisement

    Amazon Q Developer is an AI-powered coding assistant that offers developers features such as code suggestions, automated refactoring, and access to external tools and services via integrations with local processes.

    AWS was notified about the issue on April 20 and a patch was released on May 12. The cloud giant published a security advisory this week.

    The root cause of the vulnerability was that the extension would automatically act on configuration files embedded in a workspace without first asking the user for permission. 

    That meant a malicious repository could quietly run attacker-controlled commands in the background the moment a developer opened it, gaining access to whatever cloud credentials and API keys were loaded in their environment at the time.

    Attack path examples include fake coding tests like those used by North Korean hackers, a typosquatted open source package, or a malicious pull request to a popular project, Wiz said.

    Advertisement. Scroll to continue reading.

    Developers authenticated to AWS or other cloud services would be particularly exposed, since active session credentials could be captured and exfiltrated without any visible warning.

    “The combination of auto-execution, shell spawning, and environment inheritance created a high-severity vulnerability in a widely-used developer tool. A single malicious repository could compromise not just the developer’s local machine, but their cloud infrastructure as well,” Wiz noted.

    AWS has patched the vulnerability, tracked as CVE-2026-12957, and a related issue involving symbolic link handling (CVE-2026-12958). 

    Fixes are available across all affected Amazon Q Developer plugins covering VS Code, JetBrains, Eclipse, and Visual Studio, as well as the language server. 

    “We would like to thank Wiz for collaborating with us on this issue. We have remediated this issue in language server version 1.65.0,” an AWS spokesperson told SecurityWeek.

    “The AWS Language Server updates automatically unless the customer’s network configuration prevents it, so no action is required in most cases. For existing customers, reloading the IDE will trigger an update to the latest language server version, which includes this fix. If auto-update is blocked, we recommend upgrading to the latest version of the Amazon Q Developer plugin for your IDE. New customers require no action, as the latest patched version will be downloaded automatically,” the AWS spokesperson added.

    Wiz noted that the underlying issue is not unique to Amazon Q; other researchers have identified similar problems in VS Code and other AI coding tools, including Claude and Cursor.

    The Google-owned cloud security giant published technical details and PoC code on Friday.

    Related: GitLab Patches Code Execution, Information Disclosure Vulnerabilities

    Related: 25-Year-Old Vulnerability Patched in Curl

    Related: Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    September 12, 2026

    GitLab Vulnerability Exploited One Day After Disclosure

    September 12, 2026

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    September 12, 2026

    Phishing Research Challenges Conventional Security Awareness Testing

    September 11, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.