LIVE FEED
AWS Adds Defense-in-Depth Authorization for MCP Tools on Amazon Q

AWS Adds Defense-in-Depth Authorization for MCP Tools on Amazon Q

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.2 AWS Machine Learning Blog

AWS has published guidance and implementation patterns for defense-in-depth authorization controls applied to Model Context Protocol (MCP) tools within the Amazon Q platform, addressing the authorization gap that emerges when AI agents are granted access to external tools and services. This closes a meaningful defensive gap for enterprises deploying agentic AI: the risk of excessive or unverified tool invocation authority, which has been a persistent blind spot in MCP-based agent architectures. Realising the full benefit will require organisations to have mature IAM governance, MCP server inventory discipline, and operational runbooks for agent permission scoping already in place.

Amazon Q Extension Credential Theft via MCP Injection

Amazon Q Extension Credential Theft via MCP Injection

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 Dark Reading

A vulnerability in the Amazon Q Visual Studio Code extension allows adversaries to plant malicious repositories that execute arbitrary code and exfiltrate cloud credentials. The flaw highlights escalating risks associated with Model Context Protocol (MCP) integrations embedded within AI-powered developer tools. This attack vector represents a growing threat surface as AI coding assistants gain privileged access to developer environments and cloud infrastructure.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.