Skip to content
Opens in a new window
This Week in AI Security - 30th July 2026
30 July 2026

This Week in AI Security - 30th July 2026

Modern Cyber with Jeremy Snyder

About

The final episode before Black Hat, and Jeremy keeps it tight with a few quick hits before settling into the week's biggest theme: identity, visibility, and the open-versus-closed model debate. This week covers a fail-open policy bypass in the AWS API MCP server, new slop-squatting research that hits 100 percent prediction on AI agent skills, a Claude Cowork sandbox escape on Mac, a CSRF flaw in ChatGPT workspace agents, and a deeper follow-up on the Hugging Face breach and what it says about the role of open-weight models in cyber defense.

Key Episode Highlights

    AWS API MCP fail-open flaw: a startup failure in the AWS API MCP server causes it to fail open and allow all traffic if the security policy fails to load. Fixed in version 1.3.47; IAM permissions remained the enforced boundary, a reminder to use least privilege and avoid reusing IAM roles.Slop squatting hits skills: new research across Claude Sonnet 4.6, GPT-5.4 Mini, Gemini 2.5 Pro, and DeepSeek 3.2 shows the same hallucinated package names about 85 percent of the time, but prediction jumps to 100 percent consistency for AI agent skills, a growing supply chain concern as local productivity agents spread.Claude Cowork sandbox escape: a flaw lets Claude Cowork break out of its Linux VM to the host Mac and reach SSH keys and cloud credentials via a shared root-daemon folder, reportedly affecting 500,000 macOS users. Rooted in the Apple virtualization layer, so no vendor fix.ChatGPT workspace agent CSRF: disclosed by Zenity, a single phishing link can silently build, authorize, and deploy an attacker-controlled agent inside your org with the victim employee's access.Identity is the target: the Sophos AI Security 2026 report names agents among the highest-value attack surfaces, specifically the identities and tokens tied to them, reinforcing that visibility into every running agent is the foundation.Hugging Face breach, deeper: a follow-up on why open-weight models mattered for the forensic response, since commercial models kept blocking the malicious-prompt-laden logs, and what that means for the open-versus-closed debate.

Episode Links -

https://aws.amazon.com/security/security-bulletins/2026-063-aws/

https://socket.dev/blog/slopsquatting-targets-across-frontier-llms

https://www.infosecurity-magazine.com/news/ai-agents-attack-surface/

https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html

https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html

https://www.politico.com/news/2026/07/24/big-tech-companies-defend-open-weight-ai-models-01010981