Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments

A high-severity vulnerability in the Amazon Q Developer Extension for Visual Studio Code (VS Code), Amazon’s AI-powered coding assistant. Tracked as CVE-2026-12957 and CVE-2026-12958 and disclosed by Wiz Research, the flaws allowed attackers to achieve arbitrary code execution and cloud credential theft simply by having a developer open a malicious repository. The root cause was […]

The post Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: