Executive Summary
In August 2026, cybersecurity researchers disclosed a critical vulnerability in Amazon Kiro IDE that enables data exfiltration through prompt injection attacks. The flaw allows attacker-controlled repository content to influence Kiro's AI agent, causing sensitive local information to be transmitted to external endpoints without explicit user consent. Exploitation requires minimal user interaction - simply opening a malicious workspace file and sending any message to the agent triggers the vulnerable flow. Amazon addressed the issue in version 0.8.140 following responsible disclosure.
This incident highlights the emerging threat landscape surrounding AI-powered development tools, where prompt injection attacks are becoming increasingly sophisticated. As organizations rapidly adopt AI coding assistants and autonomous development environments, these tools present new attack vectors that blur traditional security boundaries between trusted and untrusted content.
Why This Matters Now
AI development environments are being rapidly deployed across enterprises without adequate security controls, creating new attack vectors where malicious prompts can exfiltrate sensitive code and data through seemingly legitimate AI interactions.
Attack Path Analysis
Attackers exploit AI IDE vulnerability through prompt injection via malicious workspace files to exfiltrate sensitive developer data. The attack leverages Kiro Powers steering files to manipulate AI agent behavior, causing automatic transmission of local workspace data to external endpoints without user awareness.
Kill Chain Progression
Initial Compromise
Description
Attacker crafts malicious workspace file containing prompt injection payloads targeting Amazon Kiro IDE vulnerability, distributed through repositories or social engineering to target developers
MITRE ATT&CK® Techniques
Spearphishing Link
PowerShell
Process Injection
DLL Side-Loading
Data from Local System
Exfiltration Over C2 Channel
Bypass User Account Control
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.02(g)
DORA – Third-party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Data Security and Protection
Control ID: Data Pillar
NIS2 Directive – Supply Chain Security Measures
Control ID: Article 21.2(a)
ISO 27001:2022 – Separation of Development and Production Environments
Control ID: A.8.31
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI-powered development environments face prompt injection vulnerabilities enabling data exfiltration through malicious workspace files and steering configurations without user awareness.
Information Technology/IT
Enterprise IT systems using AI development tools risk sensitive data exposure through trust boundary failures in agentic IDE environments and MCP configurations.
Financial Services
Banking institutions utilizing AI coding assistants face regulatory compliance violations through unauthorized data transmission and insufficient access controls in development workflows.
Health Care / Life Sciences
Healthcare organizations risk HIPAA violations when AI development tools exfiltrate protected health information through compromised workspace configurations and steering file manipulation.
Sources
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powershttps://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.htmlVerified
- Amazon Kiro Data Exfiltration via Prompt Injection and Kiro Powershttps://mindgard.ai/blog/amazon-kiro-data-exfiltrationVerified
- Amazon Kiro IDE Data Exfiltration via Steering File Disclosurehttps://mindgard.ai/disclosures/amazon-kiro-ide-data-exfiltration-via-steering-fileVerified
- Amazon Kiro IDE Changelog - Version 0.8.140 Security Fixhttps://kiro.dev/changelog/ide/Verified
- Zero-Click RCE and Prompt Injection in AI Development Toolshttps://cymulate.com/blog/zero-click-rce-prompt-injection-ai-tools/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely constrain this AI IDE prompt injection attack by limiting network access paths and reducing lateral movement scope within developer environments. The segmentation controls could reduce the blast radius of compromised AI agents accessing sensitive workspace data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF monitoring would likely detect the anomalous behavior patterns when AI agents begin accessing files outside normal operational scope, potentially alerting security teams to the malicious workspace activity.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the AI agent's access scope, reducing its ability to escalate beyond predefined workspace boundaries and limiting access to sensitive configuration files.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely limit the AI agent's ability to traverse beyond its designated workspace segment, constraining lateral access to other developer resources and sensitive file systems.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect the establishment of unauthorized communication channels, potentially identifying suspicious network patterns when AI agents attempt to contact external endpoints.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain data transmission paths, potentially blocking or limiting the AI agent's ability to send workspace data to unauthorized external endpoints without proper validation.
With reduced lateral movement and constrained egress paths, the overall impact scope would likely be limited to individual workspace segments rather than exposing broader development infrastructure assets.
Impact at a Glance
Affected Business Functions
- Software Development Operations
- Intellectual Property Protection
- Source Code Management
- Developer Productivity
Estimated downtime: 1 days
Estimated loss: N/A
Sensitive local workspace data including source code, configuration files, API keys, and proprietary development artifacts could be exfiltrated to external endpoints without user consent through malicious workspace files
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) inline enforcement to detect and block prompt injection attacks targeting AI agents and autonomous systems
- • Deploy egress security controls with FQDN filtering to prevent unauthorized data exfiltration from development environments to external endpoints
- • Enable multicloud visibility and control to monitor anomalous AI agent interactions and detect suspicious automation patterns in real-time
- • Establish zero trust segmentation with least privilege policies to limit AI agent access to sensitive workspace data and configuration files
- • Implement threat detection and anomaly response capabilities to baseline normal AI agent behavior and alert on covert data transmission activities



