Amazon Q Developer flaw let malicious repos steal AWS credentials via rogue MCP servers

Amazon Q Developer flaw let malicious repos steal AWS credentials via rogue MCP servers

TL;DR A flaw in Amazon Q Developer auto-loaded rogue MCP servers from cloned repos, letting attackers steal AWS credentials silently. A high-severity flaw in Amazon Q Developer allowed a malicious code repository to silently execute commands on a developer’s machine and steal their AWS credentials. Wiz Research discovered the vulnerability, tracked as CVE-2026-12957, and reported…

Read More
Corgi, the buzzy Y Combinator-backed insurance tech startup, says it didn’t steal an open source product

Corgi, the buzzy Y Combinator-backed insurance tech startup, says it didn’t steal an open source product

Y Combinator-backed insurance tech startup Corgi became embroiled in yet another controversy earlier this week when Papermark, maker of open source data room software, accused Corgi of stealing its software and passing it off as its own. Corgi denies this, telling TechCrunch, “No code was used from Papermark.” But there were reasons why people believed…

Read More
A Student Just Designed the Lantern Every Nomad Needs

A Student Just Designed the Lantern Every Nomad Needs

Most portable lights exist to solve a problem. They help you see when there’s no overhead fixture, charge your phone during a power outage, or keep your campsite from going completely dark. They’re useful, and that’s about where the conversation ends. Designer Benjamin Mtonya clearly thought that wasn’t enough. His student project, Fluted, just earned…

Read More