Desk/2025-W30

Week of Jul 21–27, 2025

2 records0 status changes on new evidence2 new findings

New findings

Attacks & incidents

Jul 23, 2025
Malicious agent instruction merged into Amazon Q Developer VS Code extension release 1.84.0
AttackIncidentAmazon Web Services

An actor used an improperly scoped GitHub token in AWS's build configuration to insert code into the Amazon Q Developer extension that instructed the agent to wipe local and cloud resources, and it shipped in version 1.84.0 on 2025-07-17. AWS says the code failed to execute due to a syntax error, no customer resources were affected, and it released 1.85.0 and assigned CVE-2025-8217.

Policy & standards

Jul 23, 2025
America's AI Action Plan calls for a DHS-led AI-ISAC and CAISI evaluation of frontier cyber risks
PolicyProgramThe White House, US Department of Homeland Security, CISA

The White House AI Action Plan recommends establishing an AI Information Sharing and Analysis Center led by DHS with CAISI and the National Cyber Director, DHS guidance on AI-specific vulnerabilities, and updates to CISA incident response playbooks for AI systems. It also directs CAISI to evaluate frontier models for national security risks including cyberattacks, and to assess adversary AI systems for backdoors. As of February 2026, a CISA official described the AI-ISAC as still a pre-decisional memo.