The day's headlines highlight escalating AI security risks, with 'mind viruses' spreading between agents and vulnerabilities in Microsoft Copilot and MLflow posing threats. Open source software also faces scrutiny, with typosquatted RubyGems packages stealing credentials and a vulnerability in the SafePal hardware wallet exposing customer data. Meanwhile, Warp's new AI development system aims to streamline creation, while Bluesky grapples with ongoing DDoS attacks. This week, prioritize addressing open-source security weaknesses and monitoring developments in AI safety and governance.
Researchers at Anthropic and EPFL demonstrated self-propagating AI payloads spreading between six AI agents through editable prompt files used to maintain state. This "mind virus" technique exploits persistent prompt files, enabling malicious code to transfer and potentially compromise multiple AI agents.
OpenAI is launching an initiative to support government institutions with tools, training, and expertise related to AI in national security. The goal is to strengthen democratic oversight of AI within this domain.
Varonis Threat Labs identified three vulnerabilities, dubbed CoSnitch, in Microsoft Copilot Personal. These vulnerabilities allow a single click on a crafted link to exfiltrate data from connected apps and the victim's Copilot session through an undocumented URL parameter.
Ransom Busters, a ransomware affiliate, hacked servers belonging to other ransomware groups and is offering data recovery services to victims for $20,000 to $60,000. This technique involves direct communication with victims and claims of data deletion from compromised servers.
Warp launched Warp Factories, a system simplifying the creation of AI software factories. This infrastructure enables developers to build and deploy AI applications with reduced complexity and increased efficiency.
A single attacker using the server 158.220.87.79 has scraped data from Salesforce and ServiceNow customer portals since at least 2025. This "City Forum" campaign impacted customers across multiple industries by extracting records through an unknown technique.
OpenAI is implementing enhanced monitoring, alignment, and security measures for its frontier AI models. These safeguards aim to guide the pace of model development while mitigating potential risks associated with increasingly powerful AI capabilities.
AI companies Anthropic and OpenAI publish reports on user behavior with products like Claude and ChatGPT, but these reports only present data they choose to disclose. Independent researchers, such as Anka Reuel from Stanford's Trustworthy AI Research, lack access to corroborate this information.
Attackers are exploiting a Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI platform, to steal cloud credentials and secrets. Vulnerable versions of MLflow include 1.28.0 and earlier, and FUXA, an open-source SCADA/HMI software, is also impacted by the same vulnerability.
Cursor, creator of the AI Code Editor, launched a code-hosting platform competing with GitHub. The new platform aims to address developer frustrations with GitHub and attract a significant number of users.
Bluesky experienced a recent outage due to a distributed denial of service (DDoS) attack. This marks the second major DDoS attack targeting Bluesky in 2023.
Researchers discovered TWINLOOT, a Python implant framework that leverages SharePoint and Teams to steal credentials and laterally move across networks. TWINLOOT utilizes PyArmor hardening and operates within Microsoft services for command-and-control, posing a significant threat to organizations reliant on these platforms.
OpenSourceMalware identified 16 typosquatted RubyGems packages named ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, and joxn that steal browser credentials and crypto wallets. The Windows-based information stealer, dubbed StubMaker by OpenSourceMalware, was discovered on August 15, 2026.
SafePal disclosed an authorization flaw in their order-tracking plug-in exposed data of 39,798 customers. The flaw allowed unauthorized access to customer names, email addresses, shipping addresses, phone numbers, and purchase details.
Large language models (LLMs) are capable of writing code, generating synthetic data, and optimizing their own hardware. Experts predict that this recursive self-improvement will lead to rapid advancements in AI capabilities.
OpenAI implemented stricter safeguards following a Hugging Face data breach affecting an unspecified number of AI models. These safeguards involve enhanced model monitoring during development and increased focus on alignment and security after training.
ChatGPT Ads is expanding into 31 European markets. This expansion allows advertisers to utilize AI-powered text generation to reach users during their research and decision-making processes.
Reach Capital closed its fifth fund, Fund V, raising $265 million from investors. The fund will invest in artificial intelligence (AI) founders developing technologies to expand human potential.
TikTok is exploring peer-to-peer (P2P) payment functionality within direct messages (DMs), leveraging its existing TikTok Pay system. This move aims to expand TikTok Pay's reach beyond Southeast Asian markets and facilitate in-app transactions, potentially impacting user engagement and monetization strategies.