Fetching from the wire…
Security2026-07-09 · source-backed
Wiz disclosed CVE-2026-12957 and CVE-2026-12958 in Amazon Q Developer, where the agent loaded MCP server configs straight out of a repo's .amazonq/mcp.json with no consent check and no workspace-trust gate. A booby-trapped repo could reach arbitrary code execution and steal AWS credentials just by being opened. In July the NSA responded with an official MCP Cybersecurity Information Sheet covering the inverted client-server pattern and arbitrary-code-execution exposure. This is now the canonical example of the rule agents keep breaking: workspace files are untrusted input, never trusted config. If your agent reads a dotfile from a cloned repo and acts on it, you have this bug.
Each link below shares sources, entities, or timing with this story.
Wiz Research disclosed that Amazon Q Developer auto-launched MCP servers defined in a repo's .amazonq/mcp.json, so a single config file in a cloned repo could execute code with your live AWS keys, cloud CLI tokens, and SSH agent attached. Reported April 20, fixed May 12, publi...
A year ago, GitHub Copilot was the default. Two out of three professional developers used it. That number is now barely half. CNBC reports that Copilot's share among professional developers dropped from 67% in 2025 to 51% in 2026. Cursor jumped to 29%. Amazon Q Developer grabb...
The June 12 release connects Cursor, Claude Code, Windsurf, VS Code, Amazon Q, and Kiro to pipeline, build, log, test, and workflow data over MCP. Agents can reason over CI state, like diagnosing a failing build straight from logs, without copy-paste. MCP is becoming the defau...
Six clients. One manifest. Zero vendor lock. Vercel published Agent Plugins 1.0.0 on August 6, an openly licensed spec that bundles Agent Skills and MCP servers behind a single portable manifest. The shape is deliberately boring: a plugin.json requiring only schemaVersion and...
AWS announced and open-sourced Kiro Crew on August 4, Apache-2.0. It's a persistent multi-agent development workspace that coordinates coding agents across repositories, tools, and sessions rather than inside a single chat. Persistent memory. Scheduling via cron and webhooks....
The single biggest cross-agent story this week isn't one CVE. It's that MCP became the dominant agent-hijack surface, and this is the defense that actually stops it. The pattern across a dozen findings: Sentry's MCP server weaponized via fake error events for an 85% agent-hija...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.