Daily Brief ↗ source

AI/ML Security & Trends

AI infrastructure took the brunt of this cycle's security news: CISA rushed the Ray ML framework onto its Known Exploited Vulnerabilities list with a 3-day patch order, attackers began mass-scanning exposed MLflow servers for an SSRF flaw within hours of disclosure, Microsoft patched a Copilot chain ("CoSnitch") that let a single click trigger prompt injection plus persistent memory poisoning, and US agencies confirmed threat actors are using AI-generated exploit scripts against Siemens PLCs in water and energy utilities — a rare confirmed case of AI-assisted attack tooling causing real-world OT disruption.

13 stories 7 high priority 5 categories
CISA orders 3-day emergency patch for actively exploited Ray AI framework flaw CVE-2025-62593 lets attackers trigger RCE via DNS rebinding against Ray instances used by OpenAI, Amazon and Apple. Breaches & Incidents The Hacker News / CISA · 2026-08-17

CISA added CVE-2025-62593 (CVSS 9.4) in the Ray distributed-compute framework to its Known Exploited Vulnerabilities catalog on Aug 17, giving federal agencies until Aug 20 to patch — one of the tightest windows CISA issues. The flaw allows remote code execution via browser-based DNS rebinding against Ray's /api/jobs endpoints; Ray is widely used to scale ML training/inference workloads. Fix: upgrade to Ray 2.52.0+.

Read at The Hacker News / CISA →
US agencies confirm AI-generated exploit scripts hitting Siemens PLCs at water utilities NSA/CISA/FBI advisory: threat actors used AI to write Python tools that breached water-system controllers in 12+ states. Breaches & Incidents CISA · 2026-08-19

NSA, CISA, FBI, DOE and EPA issued a joint advisory (AA26-231A) on an active threat to Siemens S7 Series PLCs across critical manufacturing, energy, water/wastewater and defense-industrial-base sectors. Attackers used AI to develop Python scripts (via snap7.dll/python-snap7) disguised as legitimate OT monitoring tools to read/write PLC memory and ladder logic; confirmed disruptions forced water utilities in at least 12 states to abandon automated operations. This is a concrete, documented case of AI-assisted attack tooling causing physical-infrastructure impact.

Read at CISA →
Attackers exploit MLflow SSRF flaw for cloud credential theft within hours of disclosure CVE-2026-64849 (CVSS 9.3) lets unauthenticated attackers hit cloud metadata endpoints via MLflow's Tracking Server. Breaches & Incidents The Hacker News · 2026-08-18

watchTowr Intel observed attackers targeting cloud-hosted MLflow instances almost immediately after CVE-2026-64849 was assigned — an unauthenticated SSRF in webhook delivery validation (bypassed via HTTP redirects and DNS rebinding) affecting versions before 3.15.0. Successful exploitation lets attackers reach internal cloud metadata services to extract credentials and secrets, directly threatening ML pipeline infrastructure.

Read at The Hacker News →
Microsoft patches "CoSnitch": one-click Copilot prompt injection with persistent memory poisoning Chained flaws let a single malicious link execute attacker prompts and poison Copilot's memory across sessions, no click confirmation needed. AI Security & Safety Varonis · 2026-08-19

Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a chain of three flaws in Microsoft Copilot Personal where a crafted URL's `?q=` parameter plus an undocumented parameter executed attacker-supplied prompts instantly on page load, exfiltrating data from linked accounts. Worse, attackers could poison Copilot's persistent memory with hidden instructions that survived password changes and session revocation. Reported to Microsoft in December 2025; patched Aug 18, 2026. No evidence of in-the-wild exploitation.

Read at Varonis →
Anthropic and EPFL show prompt-injection payloads can self-propagate between AI agents "Mind Viruses" paper: agents persuaded to write a goal into memory, then convince the next agent they meet to do the same. AI Security & Safety The Hacker News · 2026-08-18

A preprint from Anthropic and EPFL researchers, "Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems," demonstrates payloads that persuade an agent to adopt a goal, persist it into its own memory/config files, and pass it to the next agent it interacts with — tested in a six-agent coding collaboration and chains modeled on the open-source OpenClaw agent harness. No evidence of successful spread in the wild (a review of the Moltbook agent social network found none), and a one-paragraph system-prompt warning reduced spread to near zero. Directly relevant to multi-agent security and fuzzing-style adversarial testing.

Read at The Hacker News →
Alibaba open-sources Qwen3.8-Max weights and ships Qwen3.8-27B for laptops 2.4T-parameter Qwen3.8-Max weights go open, plus a 27B on-device model matching 10x-larger models — direct shot at Meta's Muse Glimmer. Model & Product Releases CNBC · 2026-08-18

Alibaba released Qwen3.8-27B on Aug 18, a laptop-targeted model aimed at the same on-device niche Meta entered days earlier with Muse Glimmer (30B, Apache 2.0). Alongside it, Alibaba open-sourced the weights of Qwen3.8-Max — its most capable model, scaling to 2.4T total / 95B active parameters — the first time the company has released weights at that scale. Qwen-derived projects on Hugging Face now exceed 151,000, putting Alibaba ahead of Meta and Google in open-weight developer adoption.

Read at CNBC →
Anthropic's annualized revenue tops $65B ahead of expected fall IPO Sevenfold jump since end of 2025; Q2 revenue over $11.5B; Morgan Stanley, Goldman and JPMorgan working the listing. Industry & Trends TechCrunch · 2026-08-17

Anthropic told investors its annualized revenue run rate surpassed $65 billion as of late July, up more than 7x since the close of 2025, with preliminary Q2 revenue exceeding $11.5 billion (vs. $787M a year earlier) and positive adjusted operating income. The company has confidentially filed for an IPO that could price as early as this fall, potentially putting it on public markets ahead of OpenAI.

Read at TechCrunch →
CareCloud confirms healthcare breach hit 3.7 million patients, 10x earlier estimate Attackers accessed CareCloud's AWS environment for six days in March; SSNs, payment and medical data exposed. Breaches & Incidents TechCrunch · 2026-08-19

Healthtech firm CareCloud's HHS filing confirmed a breach discovered in July actually affected 3.7 million individuals — more than ten times initial estimates and the fifth-largest US health data theft of 2026 so far. Threat actors accessed one of CareCloud's AWS environments between March 10–16, exposing Social Security numbers, payment card data, and medical/insurance records for patients across CareCloud's network of 45,000+ practitioners.

Read at TechCrunch →
US moves to close loophole letting Chinese firms access Nvidia AI chips via Southeast Asia Washington targets remote compute access routed through Thailand, Malaysia and Japan by ByteDance, Alibaba and Tencent. Industry & Trends CNBC · 2026-08-19

US officials are working to close a workaround in export controls that let Chinese hyperscalers — including ByteDance, Alibaba and Tencent — remotely access Nvidia AI chip compute hosted in third countries like Thailand, Malaysia and Japan, circumventing direct chip-export bans. The move extends the ongoing US-China AI chip export control fight into cloud/remote-access channels.

Read at CNBC →
Pennsylvania orders new guardrails on AI data center development Executive Order 2026-05 pulls all AI data center proposals from Fast Track permitting, bans NDAs, mandates local approval. Industry & Trends Commonwealth of Pennsylvania · 2026-08-18

Gov. Josh Shapiro signed Executive Order 2026-05, making "GRID" (Responsible Infrastructure Development) requirements legally binding for data-center developers in Pennsylvania: developers must secure local approval, fully fund needed electricity infrastructure, meet water-conservation and workforce standards, and can no longer use the state's Fast Track permitting program or NDAs. More than 100 data center proposals — many AI-driven — are currently under discussion in the state.

Read at Commonwealth of Pennsylvania →
Nvidia in talks to invest in data-labeling firm Mercor at $20B valuation Would double Mercor's valuation in ~10 months; Mercor supplies human-expert data for Nvidia's open Nemotron models. Industry & Trends Yahoo Finance / The Information · 2026-08-20

Nvidia is discussing a strategic investment in AI data-labeling supplier Mercor as part of a round led by General Catalyst that would value the company at $20 billion, double its $10B valuation from an October Series C. Mercor, which generated over $2B in annualized gross revenue by June, supplies specialized human-expert data Nvidia uses to train its open-source Nemotron models.

Read at Yahoo Finance / The Information →
VS Code 1.134 overhauls agent/subagent workflows in Copilot Chat Side-by-side subagent chat groups, a prompt timeline for navigating changes, and in-chat search land in this release. Tools & Frameworks Microsoft · 2026-08-19

Visual Studio Code 1.134 (Aug 19) adds side-by-side arrangement of related chats and subagent sessions for easier comparison, a prompt timeline to jump across prompts and review file changes, full-conversation search ("find in chat"), and the option to make the integrated browser the default editor for local HTML previews — practical upgrades for anyone driving multi-agent coding workflows day to day.

Read at Microsoft →
OpenAI expands ChatGPT Ads to 31 European countries Ads begin Aug 24 for Free/Go tier European users; Pro, Plus and Enterprise stay ad-free. Industry & Trends OpenAI · 2026-08-19

OpenAI announced ChatGPT Ads will roll out to 31 European markets (Germany, France, Spain, Italy, Nordics, etc.) starting Aug 24, its largest expansion since the ad business launched as a US pilot in February. Ads target Free and Go plan users only; OpenAI says ad revenue has grown over 25% since the start of August.

Read at OpenAI →