32
Hacker Plants Computer 'Wiping' Commands in Amazon's AI Coding Agent
(www.404media.co)
So it was due to a misconfiguration in their GitHub project, that inappropriately accepted a PR? Or because a random account was added to the project?
I don't see it in the commit history either. There's one merge on the 13th, and it was immediately reverted. Have they modified the history?
Why did the prompt injection ultimately didn't do anything?
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Enjoy!