AI Security — week of 2026-06-29

June 29, 2026 · 12 developments

Amazon Q Flaw Exposes Credentials

The Hacker News · 2026-06-26 · single-source · reporting

A flaw in Amazon Q allows malicious repositories to steal credentials via MCP configurations, posing a significant security risk.

Google Liable for AI Errors

Schneier · 2026-06-25 · corroborated · analysis

Analysis confirms companies may be liable for errors caused by their AI systems, shifting the liability landscape.

Also: Simon Willison

Gaslight Malware Disrupts AI-Assisted Analysis

The Hacker News · 2026-06-25 · single-source · reporting

Gaslight malware is capable of disrupting AI-assisted analysis, undermining the effectiveness of security tools.

Fake AI Agent Skills Bypass Security Scans

The Hacker News · 2026-06-23 · single-source · reporting

Malicious AI agent skills can bypass security scans, and legacy infrastructure can be exploited to hijack AI agents.

Also: The Hacker News

AI Coding Agent Hides from AI and Humans

BleepingComputer · 2026-06-27 · corroborated · reporting

Malware can hide from both AI and human detection, using tactics like decoy text to evade analysis.

Also: BleepingComputer · Schneier

AI assistant resists prompt injection attacks

Simon Willison · 2026-06-26 · single-source · research

Research highlights AI’s vulnerability to prompt injection attacks and potential costly inference spend due to disagreement loops.

Also: Simon Willison · Simon Willison

OpenAI Releases GPT-5.5-Cyber for Security Patching

The Hacker News · 2026-06-23 · single-source · reporting

OpenAI’s release of GPT-5.5-Cyber aims to help defenders patch security flaws, enhancing AI security.

LLM-Generated Resumes Raise Identity Concerns

Simon Willison · 2026-06-24 · single-source · research

Research notes that LLM-generated resumes can hide candidate identities, raising concerns about impersonal hiring practices.

Dify AI Chat Flaws Expose Conversations

The Hacker News · 2026-06-22 · single-source · reporting

Flaws in Dify AI chats can expose conversations, highlighting the need for secure communication protocols.

AI Amplifies Infosec Risks

The Register Sec · 2026-06-23 · single-source · reporting

The integration of AI can amplify the impact of security breaches, making infosec risks more significant.

Fable 5 Model Jailbroken, AI Safety Features Fail

Schneier · 2026-06-23 · single-source · analysis

The jailbreaking of the Fable 5 model demonstrates that AI safety features can fail, posing risks to secure operations.

LLMs Vulnerable to Prompt Injection Attacks

Schneier · 2026-06-25 · corroborated · analysis

Analysis confirms that Large Language Models are vulnerable to prompt injection attacks, which can subtly shift their states.