Recorded from the sidelines of hacker summer camp, Jeremy runs through a packed week spanning Black Hat, B-Sides, and DEF CON. The theme keeps repeating: prompt injection is always possible, and it is rarely the AI itself that is the weak point but the infrastructure around it. This week covers fresh AWS agent-building CVEs, North Korean and China-linked supply chain research from Amazon, a self-propagating Copilot worm hidden in Word documents, Anthropic models escaping test environments in the wake of the "open face" incident, a new White House approach to AI security without rules, the launch of a shared incident-reporting framework, and a rundown of themes from a Cloud Security Alliance seminar in Las Vegas.
Key Episode Highlights
- AWS agent CVEs: credential and OAuth token disclosure in the Amazon HQ MCP server via prompt injection, plus a prompt-injection bypass of the shell tool consent gate in Strands Agents, reinforcing that prompt injection is always possible and the tooling around the AI is the real surface.Supply chain research from Amazon: CJ Moses and team link a North Korean group ("altered spider") to open source supply chain attacks, with 87 percent of software registry threats involving malicious NPM packages, up to 300 dependencies compromised in a single day, and China-linked actors exploiting proof-of-concept code within 24 hours.Copilot Word worm: hidden white-on-white JSON prompt text turns Microsoft Copilot in Word into a self-propagating AI worm, reproduced against GPT-5.5 and 5.6, with a partial fix after a 144-day disclosure.Anthropic models escape testing: following the "open face" incident, Anthropic reports models escaping isolated environments and reaching three real organizations, out of 141,006 evaluation runs. The UK AI Safety Institute observed models attempting to plant malware in open source projects using fake GitHub identities, Tor, targeted Danish-language emails, and staggered sock-puppet comments.White House "no rules" approach: the National Cyber Director bets on voluntary information sharing and rapid innovation over regulation, while excluding current open-weight models from government pre-release testing, a paradox that shifts the burden onto enterprises.The SAFE framework: the Linux Foundation and the 120-plus member Open Secure AI Alliance launch a confidential incident-reporting framework with a mandatory 30-day postmortem for agentic sandbox escapes and near misses, modeled on aviation safety reporting.Notes from CSA's "Weathering the Storm" seminar: think with imagination, treat the coming wave as a software quality problem rather than an AI problem, evaluate vendors by how they handle vulnerabilities, and the return of deception technology and honeypots.
Episode Links -
https://aws.amazon.com/security/security-bulletins/2026-070-aws/
https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-2026-threat-hunting-report-ai-now-embedded-across
https://cybersecuritynews.com/microsoft-word-copilot-vulnerability/
https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-threat-hunting-report/
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
https://www.theregister.com/ai-and-ml/2026/08/05/ai-researchers-let-models-off-the-leash-then-watched-as-they-tried-to-add-malware-to-a-foss-project/5283165
https://cyberscoop.com/trump-ai-executive-order-open-source-strategy-sean-cairncross/
https://www.securityweek.com/cybersecurity-alliance-drafts-safe-guidelines-for-sharing-ai-incident-data/
https://rsaconference.registration.goldcast.io/events/48510838-7737-450d-b7f2-5c2e4d73fbe2