AI/ML Security & Trends
The day's biggest story is on the industry/leadership axis: OpenAI's executive exodus deepened with data-center chief Chris Malone's exit, the ~13th senior departure since January, landing just as NVIDIA posted blowout Q2 earnings ($96.2B revenue, +106% YoY) that underscore how much is riding on the AI infrastructure buildout. On the security side, the most consequential item is the DOJ/FBI's seizure of the China-linked QScan/QTRouter hacking platforms used against US critical infrastructure (NASA, the Fed, DOE, DOJ, HHS, NIH, the Senate).
DOJ and FBI seize China-linked QScan/QTRouter hacking platforms Breaches & Incidents
The Justice Department and FBI announced court-authorized seizures of QScan (used to scan for and infect vulnerable IoT devices) and QTRouter (an obfuscation/routing network), both operated by China-based group QTFY (linked to Nanjing Xinjiuwei Network Technology) and used by actors including China's Ministry of State Security. Confirmed victims include NASA, the Federal Reserve, DOE, DOJ, HHS, NIH and the Senate. Because the domains were hard-coded into the malware for C2 and authentication, the seizure rendered both platforms inoperable.
Read at US Dept. of Justice →OpenAI's executive exodus deepens ahead of delayed IPO Industry & Trends
Chris Malone, OpenAI's head of data centers overseeing plans for ~$600B in compute spending by 2030, departed last week, continuing a string of over a dozen executive exits since January including COO Brad Lightcap, top Altman deputy Fidji Simo, CMO Kate Rouch, and others. Co-founder Greg Brockman is reportedly reasserting direct control over infrastructure and product teams. The turnover comes as OpenAI's IPO slips to 2027 amid concerns about mounting losses despite revenue growth.
Read at TechCrunch →NVIDIA posts blowout Q2 FY2027 earnings, guides 70% growth Industry & Trends
NVIDIA reported fiscal Q2 2027 earnings of $2.22/share on $96.2B revenue, more than double a year earlier. CFO Colette Kress guided to ~70% revenue growth in FY2028, and CEO Jensen Huang said demand exceeds even that supply figure. Shares fell despite the beat as investors questioned the durability of AI capex spending — a bellwether for the entire AI infrastructure trade.
Read at Bloomberg →Microsoft patches "CoSnitch" one-click Copilot Personal data-exfiltration flaws AI Security & Safety
Varonis Threat Labs detailed CVE-2026-24301 ("CoSnitch"), three chained flaws in Microsoft Copilot Personal (copilot.microsoft.com) discovered via a "meta-hacking" technique of repeatedly asking Copilot why prompts required user interaction — surfacing an undocumented autorun=1 URL parameter. The bugs enabled one-click automatic prompt execution and exfiltration of email, calendar, cloud file names and chat history from connected accounts, plus memory poisoning via web summarization that persisted across sessions. Microsoft patched August 18 after a December 2025 disclosure; no in-the-wild exploitation was found.
Read at The Hacker News →AI browsers remain broadly vulnerable to prompt injection, researchers warn AI Security & Safety
Security researchers, including Brave's Artem Chaikin at Black Hat USA 2026, report that agentic AI browsers remain susceptible to indirect prompt injection — malicious instructions embedded in web pages that the agent executes with the user's own permissions, enabling data exfiltration and account takeover. Browseruse and Agent-E were specifically named as vulnerable. Researchers argue the exploit class is structurally embedded in current agentic-browser architecture and won't be resolved by patch cycles alone, while regulatory frameworks (EU AI Act, NIST, MITRE ATLAS) increasingly map prompt injection as a compliance risk.
Read at Dark Reading →Alibaba's Qwen releases Qwen3.8-Flash-Next, previewing Qwen4 architecture Model & Product Releases
Alibaba released Qwen3.8-Flash-Next, an open-weight (Hugging Face/ModelScope) MoE model pairing a 125B main model with a 51B n-gram embedding and 4B multi-token-prediction module (180B on disk, 6B active per token). It previews the coming Qwen4 architecture, trains at roughly 1/9th the compute of Qwen3.7-Plus, and is positioned as competitive with Anthropic's Opus 4.6 and DeepSeek's V4-Flash on coding and office tasks — part of a broader price-war push into cost-efficient frontier-adjacent models.
Read at Bloomberg →Z.ai releases GLM-5.3-Flash, a 320B MoE on Chinese AI chips Model & Product Releases
Z.ai launched GLM-5.3-Flash, a 320B-total/18B-active parameter MoE model with native multimodality, a 1,048,576-token context window, and an MIT license. It runs entirely on Chinese AI chips and was previously topping OpenRouter/OpenCode usage anonymously as "Ox Alpha." Priced at $0.075/$0.25 per million input/output tokens, it targets efficient coding and long-horizon agent workloads, benchmarking against Claude Opus 4.8 and GPT-5.6 Terra.
Read at MarkTechPost →Chinese AI firms route around chip export controls via Southeast Asia cloud Industry & Trends
Reporting confirms Chinese AI companies are increasingly accessing advanced NVIDIA compute via cloud data centers in Southeast Asia rather than importing restricted chips directly, exploiting the fact that US export controls target chip ownership/location rather than remote compute access. Lawmakers are weighing authority to regulate remote cloud access to controlled technology, but enforcement hurdles remain significant.
Read at CNBC →Ransomware groups list Integrex RCM, WireCo, ATF as new victims Breaches & Incidents
Several organizations — including healthcare-adjacent Integrex RCM, industrial firm WireCo, and ATF — appeared on ransomware data-leak sites on August 26, 2026, with attackers claiming exfiltrated internal data. Separately, a Taco Bell/Pizza Hut franchise operator disclosed a breach after detecting suspicious network activity the same day.
Read at SharkStriker →AI-infrastructure-adjacent funding: nuclear, silicon, and inference deals Industry & Trends
A cluster of funding rounds closed August 26 reflecting capital rotating from model training toward compute infrastructure: Apollo Atomics raised a $31M seed (YC, Alumni Ventures, others) for compact nuclear reactors targeting AI data centers; Auradine raised $110M Series A (Mayfield, Samsung Catalyst, Prosperity7) for energy-efficient AI compute silicon; Korean AI firm WRTN Technologies raised ~$72.2M Series C.
Read at Tech Startups →Groq valuation halves to $3.5B in $350M round after NVIDIA chip-licensing deal Industry & Trends
AI inference chipmaker Groq raised $350M led by Disruptive (with NVIDIA participating), valuing the company at $3.5B — half its $6.9B valuation from a September 2025 round. The drop follows NVIDIA's December 2025 deal paying roughly $20B to license Groq's chip technology and hire founder/CEO Jonathan Ross plus key engineers, with Groq now pivoting toward cloud inference services.
Read at Bloomberg →