Amazon described two internal AWS disruptions tied to engineers using AI coding tools with operator-level permissions, emphasizing the incidents were user error rather than autonomous AI behavior. One event in December was described as an “extremely limited” impact affecting a single service in parts of mainland China, while a second incident reportedly did not affect a customer-facing AWS service. Amazon attributed the December issue to an access-control problem (“broader permissions than expected”) and said it implemented additional safeguards afterward, including mandatory peer review and staff training; employees also noted that normal two-person approval processes were bypassed in these cases.
Separately, AWS expanded the ecosystem around coding agents by releasing Agent Plugins for AWS, an open-source plugin library that lets third-party coding agents perform AWS-specific actions (e.g., “deploy to AWS”) and generate architecture recommendations, cost estimates, and infrastructure-as-code for review before deployment. The initial deploy-on-aws plugin is designed to work in supported agent environments such as Claude Code and Cursor, increasing the ways AI agents can interact with AWS services—an expansion that heightens the importance of strong permissioning, review gates, and change-management controls highlighted by the earlier disruption reports.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After reports about AI-linked outages, Amazon said the AI involvement was coincidental and that the root cause was user error and access control. AWS also said it had taken steps to prevent recurrence and reduce the risk of AI agents causing future outages.
Before the December incident, AWS reportedly experienced at least one other production outage linked to engineers allowing an AI agent to act without sufficient oversight. Reports said the agent inherited the user's permissions and was able to make changes without secondary approval.
AWS introduced 'Agent Plugins for AWS,' an open-source plugin library that lets AI coding assistants perform AWS-aware tasks such as recommending architectures, estimating costs, and generating infrastructure-as-code. At launch, the initial 'deploy-on-aws' plugin was available for supported agent environments including Claude Code and Cursor.
In December, AWS's Kiro AI coding tool reportedly erased the environment it was operating in, leading to a 13-hour disruption. AWS said the incident affected only a single service in parts of mainland China.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcearstechnica.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.