MetaFilter

The past 24 hours of MetaFilter

Newly discovered spider uses ballista web to capture prey

Newly discovered spider uses ballista web to capture prey. A bizarre species of spider from the rainforests of Far North Queensland springs a nasty surprise.

thexiffy

Last.fm last recent tracks from thexiffy.

Spasmodique - He's On Fire

Spasmodique

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code meant that opening the wrong Git repository could allow an attacker to execute code on a developer's machine and potentially hand them the keys to the dev's cloud environment. The bug, tracked as CVE-2026-12957 and assigned a CVSS 4.0 score of 8.5, centers on how Amazon Q handled Model Context Protocol (MCP) server configurations. Wiz found the extension would automatically load a repository's .amazonq/mcp.json file and execute the commands it contained when a developer opened the project and activated Amazon Q. "The security model assumes the user explicitly configures these servers. After all, you're granting an AI assistant permission to run arbitrary commands on your machine. This should require informed consent," the researchers write. "The vulnerability arose when this assumption was violated: Amazon Q automatically loaded MCP configurations from .amazonq/mcp.json within the workspace – no prompt, no consent, no workspace trust check." MCP lets AI assistants launch local processes to carry out tasks. In Amazon Q's case, those processes inherited the developer's environment, giving them access to AWS credentials, API keys, authentication tokens, SSH agent sockets, and other secrets already loaded into the session. "The combination meant that a single malicious config file could execute arbitrary commands with full access to the developer's credentials – no user interaction required beyond opening the folder and activating Amazon Q," Wiz said. To prove the attack worked, Wiz built a repository with a malicious MCP configuration. Opening the project and activating Amazon Q caused the extension to execute a command against AWS using the developer's existing credentials. Amazon fixed the bug in version 1.65.0 of its language server, which powers Amazon Q's IDE integrations. Existing installations should receive the patched component automatically unless you've blocked automatic updates. "We would like to thank Wiz for collaborating with us on this issue. We have remediated this issue in language server version 1.65.0," Amazon said in an advisory, though it didn't respond to The Register's questions. Wiz argues the bug is less an Amazon problem than an industry one. More and more AI coding assistants are adopting MCP to connect models to local tools and services, allowing them to execute commands on developers' machines. According to the researchers, similar workspace configuration flaws have recently surfaced in other AI coding tools. It suggests attackers have found a new place to lurk: the hidden files that developers rarely think twice about trusting. ®

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Stikstofplannen komen ‘hard binnen’ bij boeren: ‘onbegrijpelijk en disproportioneel’

Uitvinder vrouwelijke lustpil: ‘Geen gerommel met geld’

Omarming van de airco zal Europese economie niet zomaar behoeden voor schade door hittestress

De economische schade van een hittegolf is niet altijd even zichtbaar. Maar die is er wel degelijk: de productiviteit daalt erdoor. Met de opwarming van de aarde loopt vooral Zuid-Europa het risico op welvaartsverlies, óók als de airco’s vaker aanstaan.


Hitte in Nederland is (steeds minder) uitzonderlijk

Het aantal extreem warme dagen neemt toe in Nederland. Dat geldt ook voor hittegolven, zelfs na een ingrijpende correctie van het KNMI.


The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Andy Burnham’s long coup: the chaotic year-long project to return him to Westminster

Efforts of campaign groups, supporters and party figures coalesced after May elections as MPs’ views began to change

The third coming of Andy Burnham began in earnest on the dancefloor of the Ministry of Sound. It was the annual conference of the centre-left pressure group Compass on an unusually hot spring weekend in May 2025. Keir Starmer, a year into his premiership, was deep in the trenches of the welfare battle, and the event’s keynote speakers were Burnham and Louise Haigh.

Under the hot pink lights, the mayor of Greater Manchester joked that he was doing the “rally the troops” slot, inappropriate for a pessimistic Evertonian. But he said there was one reason to still be cheerful.

Continue reading...

Behance Featured Projects

The latest projects featured on the Behance

Festa de la Ciència


A visual identity for Barcelona's Festa de la Ciència, transforming microorganisms, cells and invisible structures into a playful graphic system designed to spark curiosity and discovery.

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Kind valt van zeven hoog van balkon in Hoogvliet en komt in bosjes terecht

In een flat aan de Schakelweg in Hoogvliet is vrijdagmiddag een kind van een balkon gevallen. Het slachtoffer maakte een val van zeven hoog. Hoe dat kon gebeuren, is nog onduidelijk. De politie gaat uit van een ongeluk.