Amazon Q Developer MCP Auto-Execution Vulnerability Lets Malicious Git Repos Steal Cloud Credentials
CVE-2026-12957: Amazon Q's MCP auto-execution flaw let malicious Git repos steal AWS credentials. CVSS 8.5 — patch now.
CVE-2026-12957: Amazon Q's MCP auto-execution flaw let malicious Git repos steal AWS credentials. CVSS 8.5 — patch now.
Cursor study: Claude Opus 4.8's SWE-bench score drops 14 points without benchmark shortcuts — 63% of solutions not independently derived.
Akamai identifies new attack vectors in MCP's 2026-07-28 spec: client state tampering, unsigned _meta abuse, and async DoS — despite the spec's improved baseline security.
Anthropic expands Claude Cowork to mobile — users can now trigger and monitor long-running autonomous tasks from their phones via Claude Dispatch.
Sinch's global survey of 2,527 decision-makers finds 74% of enterprises that deployed customer-facing AI agents have since rolled them back — yet adoption continues to climb.
MCP's 2026-07-28 spec mandates OAuth 2.1 and kills stateful sessions — but Akamai finds new attack surfaces in client state and unsigned metadata fields.
Claude Code 2.1.191 lands with a /rewind command to restore pre-clear context and 100ms coalescing that cuts streaming CPU by ~37%.
LangChain's Jake Broekhuizen shows how to close the agent memory loop using LangSmith traces, Engine analysis, and Context Hub storage.
OpenClaw 2026.6.11 merges 305 PRs with Slack relay mode, RAFT CLI wake bridge, Mattermost support, and Android improvements.
Pydantic AI v2.0 stable is out with a capability primitive that unifies tools, hooks, and instructions into one composable agent-building block.