Amazon’s Kiro Prompt Injection Vulnerability Exposes Sensitive Data Across Accounts
A critical vulnerability has been discovered in Amazon’s Kiro, a cloud-based platform that enables businesses to build and manage large language models. The flaw, dubbed “Kiro Prompt Injection,” allows attackers to exfiltrate sensitive data from one account to another by exploiting the way Kiro handles user input. This exploit is particularly concerning as it affects multiple organizations across various industries, highlighting the need for enhanced security measures in cloud-based services.
Kiro’s architecture relies on a complex interaction between natural language processing (NLP) and machine learning algorithms. When users interact with the platform, their inputs are processed by these models to generate responses or perform tasks. However, researchers have discovered that an attacker can manipulate user input through “prompt injection,” essentially tricking Kiro into revealing sensitive information from another account. This data exfiltration occurs without requiring any direct access to the target account’s credentials.
The vulnerability is made possible due to a combination of factors, including lax input validation and the way Kiro handles cross-domain requests. When an attacker injects malicious prompts into their own Kiro instance, they can inadvertently request sensitive information from another user’s account through the platform’s API. This data can then be extracted and used for nefarious purposes.
The implications of this vulnerability are far-reaching, affecting businesses that rely on Kiro to manage sensitive data, such as financial institutions or healthcare providers. Attackers can exploit this flaw to gain unauthorized access to confidential information, potentially leading to significant reputational damage and financial losses.
Amazon’s response to the discovery has been swift, with the company releasing patches for affected users and recommending enhanced security measures, including multi-factor authentication and regular account reviews. While these steps are crucial in mitigating the risks associated with Kiro Prompt Injection, they underscore the importance of proactive security strategies that prioritize data protection and accountability.
To protect yourself from similar vulnerabilities, it’s essential to remain vigilant about cloud-based service security. Regularly review your account settings and access controls, and ensure that all users are aware of potential risks associated with their interactions with cloud platforms like Kiro. By staying informed and taking proactive steps, you can minimize the impact of these types of attacks on your organization’s sensitive data.
Source: The Hacker News — 2026-08-27