Hackread–Amazon Q AI Assistant Compromised by Hacker Injecting Data-Wiping Commands
A security vulnerability in Amazon's AI coding assistant 'Q' allowed a hacker to inject malicious commands that instructed the system to delete user files and wipe AWS cloud resources. The hacker used a temporary GitHub account to submit a pull request that granted administrative access, embedding destructive instructions that Amazon reportedly merged and released without detection. In response to such vulnerabilities, Jozu has released PromptKit, a local-first, open-source tool that provides auditable and production-safe prompt management to prevent similar incidents through policy-controlled workflows and verified prompt artifacts.
Originally published on Hackread. For more details, visit the source.