All Tags

    MCP

    6 items across 1 section

    Weekly News6

    Week 12 - Mar 16-22, 2026

    AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.

    2026-03-16 - 2026-03-22

    Week 16 - Apr 14-20, 2026

    A Vercel employee had OAuth-trusted Context.ai with their corporate Google account. Lumma Stealer hit Context.ai. The attacker walked from Google Workspace into Vercel and read non-sensitive environment variables. Also this week: Vect ransomware lists Trivy/LiteLLM victims, AWS patches EFS CSI and Encryption SDK for Python.

    2026-04-14 - 2026-04-20

    Week 29 - July 13-19, 2026

    GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.

    2026-07-13 - 2026-07-19

    Week 30 - July 20-26, 2026

    GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.

    2026-07-20 - 2026-07-26

    Week 32 - Aug 3-9, 2026

    Bedrock AgentCore Runtime Instances reach general availability, letting agents run on dedicated EC2 instances for up to 14 days instead of the 8-hour microVM limit. AWS open-sources Dogwood, a Cedar-compatible policy language with temporal logic for governing sequences of agent tool calls. A path traversal bug in the AWS Transform MCP Server gets patched.

    2026-08-03 - 2026-08-09

    Week 36 - Aug 31 - Sep 6, 2026

    JetBrains concludes its investigation into a three-week breach of its Cadence CI/CD service, confirming attackers compromised AWS IAM users and credentials and accessed files in JetBrains-owned S3 buckets, alongside PyCharm source code and user data. Four new AWS security bulletins close the month, and AWS opens beta registration for its new AI Business Strategist certification.

    2026-08-31 - 2026-09-06

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us