AI/ML Security & Trends
AI infrastructure took the brunt of this cycle's security news: CISA rushed the Ray ML framework onto its Known Exploited Vulnerabilities list with a 3-day patch order, attackers began mass-scanning exposed MLflow servers for an SSRF flaw within hours of disclosure, Microsoft patched a Copilot chain ("CoSnitch") that let a single click trigger prompt injection plus persistent memory poisoning, and US agencies confirmed threat actors are using AI-generated exploit scripts against Siemens PLCs in water and energy utilities — a rare confirmed case of AI-assisted attack tooling causing real-world OT disruption.
CISA orders 3-day emergency patch for actively exploited Ray AI framework flaw Breaches & Incidents
CISA added CVE-2025-62593 (CVSS 9.4) in the Ray distributed-compute framework to its Known Exploited Vulnerabilities catalog on Aug 17, giving federal agencies until Aug 20 to patch — one of the tightest windows CISA issues. The flaw allows remote code execution via browser-based DNS rebinding against Ray's /api/jobs endpoints; Ray is widely used to scale ML training/inference workloads. Fix: upgrade to Ray 2.52.0+.
Read at The Hacker News / CISA →US agencies confirm AI-generated exploit scripts hitting Siemens PLCs at water utilities Breaches & Incidents
NSA, CISA, FBI, DOE and EPA issued a joint advisory (AA26-231A) on an active threat to Siemens S7 Series PLCs across critical manufacturing, energy, water/wastewater and defense-industrial-base sectors. Attackers used AI to develop Python scripts (via snap7.dll/python-snap7) disguised as legitimate OT monitoring tools to read/write PLC memory and ladder logic; confirmed disruptions forced water utilities in at least 12 states to abandon automated operations. This is a concrete, documented case of AI-assisted attack tooling causing physical-infrastructure impact.
Read at CISA →Attackers exploit MLflow SSRF flaw for cloud credential theft within hours of disclosure Breaches & Incidents
watchTowr Intel observed attackers targeting cloud-hosted MLflow instances almost immediately after CVE-2026-64849 was assigned — an unauthenticated SSRF in webhook delivery validation (bypassed via HTTP redirects and DNS rebinding) affecting versions before 3.15.0. Successful exploitation lets attackers reach internal cloud metadata services to extract credentials and secrets, directly threatening ML pipeline infrastructure.
Read at The Hacker News →Microsoft patches "CoSnitch": one-click Copilot prompt injection with persistent memory poisoning AI Security & Safety
Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a chain of three flaws in Microsoft Copilot Personal where a crafted URL's `?q=` parameter plus an undocumented parameter executed attacker-supplied prompts instantly on page load, exfiltrating data from linked accounts. Worse, attackers could poison Copilot's persistent memory with hidden instructions that survived password changes and session revocation. Reported to Microsoft in December 2025; patched Aug 18, 2026. No evidence of in-the-wild exploitation.
Read at Varonis →Anthropic and EPFL show prompt-injection payloads can self-propagate between AI agents AI Security & Safety
A preprint from Anthropic and EPFL researchers, "Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems," demonstrates payloads that persuade an agent to adopt a goal, persist it into its own memory/config files, and pass it to the next agent it interacts with — tested in a six-agent coding collaboration and chains modeled on the open-source OpenClaw agent harness. No evidence of successful spread in the wild (a review of the Moltbook agent social network found none), and a one-paragraph system-prompt warning reduced spread to near zero. Directly relevant to multi-agent security and fuzzing-style adversarial testing.
Read at The Hacker News →Alibaba open-sources Qwen3.8-Max weights and ships Qwen3.8-27B for laptops Model & Product Releases
Alibaba released Qwen3.8-27B on Aug 18, a laptop-targeted model aimed at the same on-device niche Meta entered days earlier with Muse Glimmer (30B, Apache 2.0). Alongside it, Alibaba open-sourced the weights of Qwen3.8-Max — its most capable model, scaling to 2.4T total / 95B active parameters — the first time the company has released weights at that scale. Qwen-derived projects on Hugging Face now exceed 151,000, putting Alibaba ahead of Meta and Google in open-weight developer adoption.
Read at CNBC →Anthropic's annualized revenue tops $65B ahead of expected fall IPO Industry & Trends
Anthropic told investors its annualized revenue run rate surpassed $65 billion as of late July, up more than 7x since the close of 2025, with preliminary Q2 revenue exceeding $11.5 billion (vs. $787M a year earlier) and positive adjusted operating income. The company has confidentially filed for an IPO that could price as early as this fall, potentially putting it on public markets ahead of OpenAI.
Read at TechCrunch →CareCloud confirms healthcare breach hit 3.7 million patients, 10x earlier estimate Breaches & Incidents
Healthtech firm CareCloud's HHS filing confirmed a breach discovered in July actually affected 3.7 million individuals — more than ten times initial estimates and the fifth-largest US health data theft of 2026 so far. Threat actors accessed one of CareCloud's AWS environments between March 10–16, exposing Social Security numbers, payment card data, and medical/insurance records for patients across CareCloud's network of 45,000+ practitioners.
Read at TechCrunch →US moves to close loophole letting Chinese firms access Nvidia AI chips via Southeast Asia Industry & Trends
US officials are working to close a workaround in export controls that let Chinese hyperscalers — including ByteDance, Alibaba and Tencent — remotely access Nvidia AI chip compute hosted in third countries like Thailand, Malaysia and Japan, circumventing direct chip-export bans. The move extends the ongoing US-China AI chip export control fight into cloud/remote-access channels.
Read at CNBC →Pennsylvania orders new guardrails on AI data center development Industry & Trends
Gov. Josh Shapiro signed Executive Order 2026-05, making "GRID" (Responsible Infrastructure Development) requirements legally binding for data-center developers in Pennsylvania: developers must secure local approval, fully fund needed electricity infrastructure, meet water-conservation and workforce standards, and can no longer use the state's Fast Track permitting program or NDAs. More than 100 data center proposals — many AI-driven — are currently under discussion in the state.
Read at Commonwealth of Pennsylvania →Nvidia in talks to invest in data-labeling firm Mercor at $20B valuation Industry & Trends
Nvidia is discussing a strategic investment in AI data-labeling supplier Mercor as part of a round led by General Catalyst that would value the company at $20 billion, double its $10B valuation from an October Series C. Mercor, which generated over $2B in annualized gross revenue by June, supplies specialized human-expert data Nvidia uses to train its open-source Nemotron models.
Read at Yahoo Finance / The Information →VS Code 1.134 overhauls agent/subagent workflows in Copilot Chat Tools & Frameworks
Visual Studio Code 1.134 (Aug 19) adds side-by-side arrangement of related chats and subagent sessions for easier comparison, a prompt timeline to jump across prompts and review file changes, full-conversation search ("find in chat"), and the option to make the integrated browser the default editor for local HTML previews — practical upgrades for anyone driving multi-agent coding workflows day to day.
Read at Microsoft →OpenAI expands ChatGPT Ads to 31 European countries Industry & Trends
OpenAI announced ChatGPT Ads will roll out to 31 European markets (Germany, France, Spain, Italy, Nordics, etc.) starting Aug 24, its largest expansion since the ad business launched as a US pilot in February. Ads target Free and Go plan users only; OpenAI says ad revenue has grown over 25% since the start of August.
Read at OpenAI →