Security and media reporting highlighted growing enterprise exposure created by AI agents and the expanding ecosystem around the Model Context Protocol (MCP). AWS detailed new IAM governance controls for AWS-managed remote MCP servers, introducing standardized context keys aws:ViaAWSMCPService and aws:CalledViaAWSMCP to differentiate agent-initiated API calls from human activity and enable tighter policy enforcement, with additional network perimeter controls (VPC endpoint support) planned. Separately, AI governance startup JetStream announced a $34M seed round to provide visibility and control over AI behavior in production, explicitly targeting MCP server/key sprawl and cost/accountability concerns; multiple commentaries also warned that AI-driven development and “AI ultimatums” can increase IP theft and governance risk if organizations lack clear controls and monitoring.
Threat-focused coverage underscored that AI is also accelerating offensive capability and complicating defense. CSO Online reported AI-powered attack kits moving into open source (including tooling referenced as CyberStrikeAI), lowering barriers for cybercrime and enabling faster iteration of malicious tradecraft. In parallel, FBI messaging emphasized that Salt Typhoon activity remains ongoing following prior compromises of sensitive US telecom infrastructure, reinforcing the need for stronger government–telecom partnerships and improved readiness against Chinese cyber operations (including the FBI’s Operation Winter SHIELD focus on preparedness and faster intel sharing). Additional technical threat-hunting research described operationalizing Cobalt Strike C2 feeds via API automation for SIEM/EDR use, noting continued rapid infrastructure rotation and increased association with state-backed espionage and advanced ransomware operations, while a Dark Reading podcast recapped Interpol-supported law-enforcement disruption of an African cybercrime syndicate (hundreds of arrests and multiple malware decryptions).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Interpol coordinated Operation Sentinel across 19 countries, resulting in 574 arrests, recovery of more than $3 million, takedown of over 6,000 malicious links, and decryption of six malware or ransomware variants.
FBI Assistant Director Brett Leatherman said Operation Winter SHIELD is being used to improve U.S. readiness for growing Chinese cyber threats and accelerate intelligence sharing with industry.
AI governance startup JetStream Security disclosed a $34 million seed financing led by Redpoint Ventures to build visibility and control for enterprise AI systems and MCP environments.
AWS said it plans to add VPC endpoint support for AWS-managed MCP servers, enabling private connectivity and additional network-level controls for regulated environments.
AWS announced new IAM context keys, aws:ViaAWSMCPService and aws:CalledViaAWSMCP, to help customers distinguish and govern AI-agent-initiated API calls on AWS-managed MCP servers.
An FBI deputy assistant director for cyber intelligence publicly said Salt Typhoon activity is still ongoing and called for stronger collaboration between government and telecom providers.
In 2024, the Chinese threat actor Salt Typhoon compromised parts of U.S. telecommunications wiretap infrastructure, establishing a long-term intrusion into sensitive national infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
franklyspeaking.substack.com
Open sourcegopher.security
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcehunt.io
Open sourcecsoonline.com
Open sourceaws.amazon.com
Open sourcevulnu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.