Security News AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code TheHackerNews Daniel Bender 21 Jul 2026 Share AWS fixed a Kiro prompt injection chain that rewrote mcp.json and launched attacker-controlled code with developer privileges, bypassing approval.