Amazon’s Kiro platform has been found vulnerable to a novel type of attack, dubbed “Kiro Prompt Injection.” This sophisticated technique allows malicious actors to exfiltrate sensitive data from organizations using Amazon’s services. The exploit takes advantage of a feature designed to streamline workflows within Kiro Powers, but instead enables attackers to bypass security controls and access unauthorized information.
At the heart of this vulnerability lies Amazon’s Kiro platform, which provides a suite of tools for integrating various AWS services into a single interface. Kiro Powers is one such feature that allows users to create custom workflows between different AWS services. However, an investigation by cybersecurity researchers has revealed that an attacker can inject malicious code into these custom workflows, effectively granting them access to sensitive data.
As the attack unfolds, the malicious actor creates a compromised workflow within Kiro Powers, which appears legitimate to the user but secretly sends stolen data to an external server under their control. This process is facilitated by Amazon’s S3 bucket service, which stores and manages large amounts of data for AWS users. In this case, the attacker uses S3 buckets to receive and store exfiltrated data, effectively creating a backdoor into the compromised organization.
The exploit relies on the fact that Kiro Powers allows users to define custom workflows using various AWS services, including those with elevated privileges. By crafting a malicious workflow, an attacker can gain access to sensitive information stored within these privileged services. The attack is particularly insidious because it exploits the trust placed in Amazon’s platform, which is designed to simplify complex tasks and streamline workflows.
The implications of this vulnerability are significant, as many organizations rely on Amazon’s Kiro platform for their day-to-day operations. With an estimated 100,000+ AWS customers using Kiro, the potential attack surface is substantial. The researchers who discovered the exploit have emphasized that the issue stems from a design flaw within Kiro Powers and not from any weaknesses in underlying AWS services.
In light of this finding, it’s essential for organizations using Amazon’s Kiro platform to take immediate action to secure their sensitive data. This includes implementing robust security controls, conducting thorough risk assessments, and educating employees on the potential risks associated with custom workflows. By staying vigilant and proactive, businesses can mitigate the threat posed by this exploit and maintain the trust placed in them by their customers and partners.
Source: The Hacker News — 2026-08-27