MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension (opens in new tab)
Wiz Research found a critical Amazon Q vulnerability that enabled code execution and cloud credential theft through malicious MCP configurations.
Read the original article