AI/ML Security & Trends
The standout story for this audience: Wiz's autonomous "Red Agent" found and exploited a real GitHub Actions vulnerability in Snowflake's public repo — one that GitHub Copilot's own Autofix had missed — extracting a live Jira token in a controlled, responsibly-disclosed test, a vivid demonstration of AI-vs-AI security dynamics. Beyond that, it was a big money day for AI infrastructure (NVIDIA's $105B Ohio backstop for OpenAI, Anthropic's first profitable quarter) and a fast-moving open-weight model race (Qwen3.8-27B, DeepSeek V4 Pro).
Wiz's autonomous "Red Agent" finds Snowflake vuln that Copilot Autofix missed AI Security & Safety
Wiz Research's autonomous "Red Agent" discovered a script-injection vulnerability in the public snowflakedb/snowflake-connector-net GitHub Actions workflow, letting an unauthenticated user execute commands in a runner via a crafted GitHub issue title. After an initial failed payload, the agent read the runner's syntax error, adjusted its injection, and extracted a base64-encoded Jira token (read access to Snowflake's engineering, security-compliance, and bug-bounty projects). Disclosed responsibly to Snowflake on June 23 and remediated same-day, the case became public at Black Hat-adjacent coverage this week because GitHub Copilot's Autofix was a co-author on the commit that introduced the flaw — a concrete instance of one AI agent finding what another AI missed.
Read at Wiz Research →Alibaba's Qwen3.8-27B becomes first local model to hit frontier-level agentic scores Model & Product Releases
Alibaba's Qwen team released Qwen3.8-27B under Apache 2.0, with a 262K-token context window, native image/video understanding, and configurable reasoning. Artificial Analysis scored it 52 on its Intelligence Index (matching GPT-5.6 Luna at max reasoning) and 51 on its Agentic Index — beating Claude Opus 4.8 on max reasoning effort. Coding-agent maker Cline called it the first time a local model has scored frontier-level capability, running at FP8 on ~28GB of GPU memory, a notable shift in the open-weight/local-deployment threat and capability landscape.
Read at VentureBeat →NVIDIA backs up to $105B for OpenAI's 8-gigawatt Ohio data center Industry & Trends
NVIDIA announced it will guarantee up to $105 billion in conditional lease and power payment obligations for an 8-IT-gigawatt data center in Pike County, Ohio, that OpenAI has signed a 20-year lease on. SB Energy (a SoftBank subsidiary) will build and manage the site on former federal uranium-enrichment land; NVIDIA will be the exclusive chip supplier. It's the latest example of circular financing tying chipmaker, cloud, and model-lab balance sheets together as AI infrastructure buildout accelerates.
Read at CNBC →Anthropic's Q2 revenue tops $11.5B with first operating profit Industry & Trends
Preliminary figures shared with investors show Anthropic's Q2 2026 revenue exceeded $11.5 billion, ahead of the $10.9B/$559M-operating-profit projection it gave earlier this year, and the company posted positive adjusted operating income for the first time. The results land as Anthropic's backers reportedly discuss a valuation near $2 trillion, underscoring how fast enterprise and API revenue (much of it agentic/coding-driven) is scaling relative to frontier-lab cost structures.
Read at CNBC →GitLab patches critical unauthenticated GraphQL flaw (CVSS 9.4) AI Security & Safety
GitLab shipped emergency patches (19.2.4, 19.1.6, 19.0.8, 18.11.11) for CVE-2026-19478, a critical code-injection flaw in a GraphQL directive affecting Community and Enterprise Edition. An unauthenticated remote attacker could modify or delete public projects and user data without a valid account. GitLab.com and GitLab Dedicated are already patched; self-managed instances need to upgrade immediately. No in-the-wild exploitation or public PoC has been reported yet, but the severity and reach into CI/CD pipelines widely used by AI coding agents make it worth prioritizing.
Read at The Hacker News →Researchers show encrypted chain-of-thought can be decrypted across sessions AI Security & Safety
A paper from ELLIS Institute Tübingen and the Max Planck Institute ('Stealing Reasoning Traces from Proprietary LLM APIs') shows that when providers return encrypted chain-of-thought blocks to clients instead of storing them server-side, those blocks are fully interchangeable across sessions, users, and models within the same provider's ecosystem. By feeding a stronger model's encrypted reasoning trace to a weaker, less-guarded model from the same provider, the researchers force it to decode and output the trace in plaintext — recovering hidden reasoning without ever jailbreaking the stronger model directly. A public reproduction is on GitHub (mitkox/stolen-thoughts).
Read at arXiv →DeepSeek ships V4 Pro 0813, hikes API prices up to 14x Model & Product Releases
DeepSeek's V4-Pro-0813 went GA at $1.32/M input and $3.96/M output tokens — roughly 9x and 14x V4 Flash's input/output pricing respectively — with cache-hit pricing up 12x. The model posted 87.9 on Terminal-Bench 2.1 and a notable 83.3 on CyberGym (a cyber-capability benchmark), plus 42.7%/60.0% on Humanity's Last Exam without/with tools. The steep price hike signals DeepSeek shifting from loss-leading distribution toward profitability ahead of a reported CNY 50B fundraising round and IPO plans.
Read at Fortune →xAI opens Grok Bot public beta — always-on cloud AI teammates Tools & Frameworks
xAI put Grok Bot into public beta, describing it as a team of always-on AI agents that get their own cloud computer, sign into a user's existing web tools, learn workflows from demonstration, and complete multi-step jobs with human approval only at final steps. Access is bundled into SuperGrok Heavy, Cursor Ultra, and Cursor Teams Premium, available on desktop and iOS (Linux build posted, Android "coming soon"). A wider rollout is gated on fixes following the Grok 4.6 launch.
Read at xAI →OpenAI hires ex-Wiz President Dali Rajic as Chief Revenue Officer Industry & Trends
OpenAI appointed Dali Rajic — most recently President and COO of cybersecurity company Wiz, with prior stints at Zscaler and AppDynamics — as Chief Revenue Officer. He succeeds Denise Dresser, who joined in December 2025 and is leaving after a transition period. OpenAI says its products now reach over 1 billion weekly users and 2 million businesses, making the enterprise-scaling hire notable, and continuing a pattern of security-industry executives moving into frontier-lab leadership.
Read at OpenAI →Check Point: ransomware victims up 33% YoY, ecosystem now 93 active groups Industry & Trends
Check Point Research's August 17 threat intelligence report logs 2,139 publicly reported ransomware victims in Q2 2026, up 33% year-over-year, with the number of active ransomware groups climbing to 93. The report is part of a broader trend of AI tooling lowering the barrier to both attack tooling development and victim reconnaissance, a backdrop relevant to the AI-authored/AI-assisted attack chains showing up elsewhere this week (see Wiz/Snowflake item).
Read at Check Point Research →AI companion-app maker Eva AI listed on Direwolf ransomware leak site Breaches & Incidents
The Direwolf ransomware group added Eva AI Limited — maker of the EVA AI Chat Bot & Soulmate companion app — to its leak site, claiming to have exfiltrated internal company data. Details and scope remain unverified and Eva AI has not issued a public statement. Companion/chatbot apps handle unusually intimate personal data, so any confirmed breach at a company in that category carries outsized privacy risk relative to typical SaaS breaches.
Read at Ransomware.live →Anthropic hit by 36-minute multi-service outage Industry & Trends
Starting at 21:58 UTC on August 16, Anthropic users hit sign-in failures and stalled requests across Claude.ai, Claude Code, Claude Cowork, Claude Console, and the API. Anthropic widened the incident scope four minutes in, deployed a fix by 22:22 UTC, and marked it resolved at 22:34 UTC. The company has not disclosed a root cause.
Read at BleepingComputer →