
🚨 The number to watch in AI security isn't discovery. It's verification. Three AI-security stories hit the feed this week and they look like they're arguing. They're not. 🔎 1️⃣ : a flaw in Amazon Q (CVE-2026-12957) let a booby-trapped code repo auto-run hostile commands and walk off with cloud credentials. Open the wrong repo, the agent does exactly what it was built to do, reads project context and acts on it, except the context was poisoned. Similar flaws hit Claude Code, Cursor, and Windsurf the same week. That's not one vendor being sloppy. That's the category. 2️⃣ : AI is genuinely, categorically good at finding vulnerabilities. One coalition surfaced 20,000+ findings across 500 projects. The flaws were always there. We finally built something patient enough to look at all of it. 3️⃣ : confidence in *fully autonomous* AI pentesting dropped to 9%, down from 29% a year ago. The honest read isn't "AI declined." People ran it long enough to learn where it fails, and adjusted. That's the system working. Here's the takeaway for leaders. AI is a force multiplier, and the word doing the work is *multiplier*. You can buy discovery for almost nothing now. You can't buy senior judgment at the same rate. If your AI's output outruns your team's ability to verify it, you didn't add security. You added an unverified backlog wearing a security costume. 🧠 Keep your verification capacity ahead of your discovery rate. That ratio is the whole game. Sources: https://www.theregister.com/cyber-crime/2026/06/26/amazon-q-flaw-let-booby-trapped-git-repos-execute-code-swipe-cloud-creds/5263202 https://www.theregister.com/security/2026/06/27/its-looking-like-a-hot-messy-summer-for-security-teams-as-ai-finds-countless-previously-hidden-vulns/5260478 https://www.darkreading.com/cybersecurity-operations/ai-decline-confidence-autonomous-penetration-testing Wrote about why this matters → https://medium.com/@penquestr #AISecurity #Cybersecurity #AI #InfoSec #TechNews
Post summary
The post confirms that CVE‑2026‑12957 was actively exploited in Amazon Q to run malicious code and exfiltrate cloud credentials, but it provides no PoC, patch, or exploit tool details.















