
Amazon Q Developer bug let a cloned repo steal AWS credentials via a single config file
Wiz Research found CVE-2026-12957, Amazon patched May 12, and today’s disclosure shows how fast supply-chain access becomes account takeovers.
By Omar Al-Balawi·· 3 min

