<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cybercrime.club</title><link>https://cybercrime.club/tags/developer-tools/</link><description>Infrastructure security news for people who build infrastructure.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 23:10:32 -0400</lastBuildDate><atom:link href="https://cybercrime.club/tags/developer-tools/" rel="self" type="application/rss+xml"/><item><title>Hidden Web Text Turns AWS Kiro Into an RCE Chain: MCP Config Rewrite via Prompt Injection</title><link>https://cybercrime.club/posts/aws-kiro-agentic-ide-mcp-config-prompt-injection-rce/</link><pubDate>Wed, 22 Jul 2026 23:10:32 -0400</pubDate><guid>https://cybercrime.club/posts/aws-kiro-agentic-ide-mcp-config-prompt-injection-rce/</guid><description>Researchers at Intezer and Kodem Security show how hidden text on an ordinary web page could make AWS's Kiro agentic IDE rewrite its own MCP config and execute attacker code — no approval dialog, no CVE, patched in Kiro 0.11.130.</description><category>vulnerabilities</category></item></channel></rss>