daily cyber × ai intelligence

index

tagged

[amazon-q]

2 editions · 2 items

July 24, 2026

  • Kaspersky details practical attacks that hijack AI tooling already inside the target. Rather than attackers bringing their own AI, the write-up focuses on abusing deployed coding/CLI agents — Claude Code CLI, Gemini CLI, Codex CLI, Amazon Q CLI — which can read/modify files, run shell commands, and install packages. NCSC-FI/Kaspersky. · AI & Model Security

in The Week AI Agents Started Doing the Hacking

July 1, 2026

  • Microsoft IR research shows how a single poisoned MCP tool description can steer an agent into quietly exfiltrating company data without ever "breaking a rule" — every step looks routine, so default setups raise no alarm. Separately, Wiz detailed an Amazon Q VS Code extension flaw that auto-loaded workspace MCP configs without consent, enabling code execution and cloud-credential theft on opening a malicious repo (fixed in language server 1.65.0). The Hacker News, Wiz · AI & Model Security

in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread