{"data":{"id":"281ea321-43ad-4fd3-81b9-074e543855e3","title":"ICYMI: July 2026 @AWS Security","summary":"This AWS Security blog roundup from July 2026 covers guidance on securing AI systems, protecting software supply chains, and managing encryption keys. The posts address topics like preventing unauthorized access in multi-agent AI systems, stopping data leaks from AI models, detecting prompt injection attacks (tricking an AI by hiding instructions in its input), and implementing security controls for AI coding agents.","solution":"The source explicitly mentions several mitigations: (1) Use Cedar policy models with OAuth 2.0 authentication via Amazon Verified Permissions to enforce least-privilege authorization in multi-agent AI chains; (2) Use Amazon Bedrock Projects and service control policies to enforce zero data retention; (3) Implement defense-in-depth mitigations for system prompt leakage using Amazon Bedrock Guardrails prompt attack filters, canary tokens, semantic similarity detection, and sandwich instruction patterns; (4) Implement author-time and build-time application security controls for AI coding agents; (5) Use AWS WAF Bot Control with Web Bot Authentication to cryptographically verify legitimate AI agent traffic; (6) Implement a one-line dependency cooldown for npm and pip that skips packages published in the last 24 hours to protect against supply chain attacks.","labels":["security","policy"],"sourceUrl":"https://aws.amazon.com/blogs/security/icymi-july-2026-aws-security/","publishedAt":"2026-08-26T19:32:55.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS","Amazon Bedrock","Amazon Verified Permissions","Amazon Linux","Amazon EKS","Amazon ECS","AWS WAF","AWS KMS","AWS CloudHSM","AWS Network Firewall"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-26T19:32:55.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}