This Week in AI Security - 30th J...
This Week in AI Security - 30th July 2026

Modern Cyber with Jeremy Snyder by Jeremy Snyder

Episode notes

The final episode before Black Hat, and Jeremy keeps it tight with a few quick hits before settling into the week's biggest theme: identity, visibility, and the open-versus-closed model debate. This week covers a fail-open policy bypass in the AWS API MCP server, new slop-squatting research that hits 100 percent prediction on AI agent skills, a Claude Cowork sandbox escape on Mac, a CSRF flaw in ChatGPT workspace agents, and a deeper follow-up on the Hugging Face breach and what it says about the role of open-weight models in cyber defense.

Key Episode Highlights

  • AWS API MCP fail-open flaw: a startup failure in the AWS API MCP server causes it to fail open and allow all traffic if the security policy fails to load. Fixed in version 1.3.47; IAM permissions remained the enforced boundary, a reminde ... 
Read more
Keywords
AI NewsModern Cyber