September 12, 2026
- A new analysis maps a prompt-injection-to-code-execution path in Amazon Kiro. NSFOCUS revisits Mindgard’s August 27 disclosure, tested on Kiro 0.7.45. Because the IDE agent could read and write repository files, invoke native tools, and trigger IDE actions, injected instructions could cross into unauthorized execution. This was a research demonstration; the analysis does not establish that current builds remain vulnerable. · AI & Agent Security
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack