Critical vulnerability in Amazon Q Developer exposes AWS credentials
A high-severity vulnerability in Amazon Q Developer, discovered by Wiz Research, allowed a malicious repository to silently execute commands on the developer's machine and steal their AWS credentials. The flaw, identified as CVE-2026-12957, has been patched by Amazon, but the case highlights security risks in AI assistants integrated into development environments.

