Weekly · News
AI Security — week of 2026-07-20
GPT-5.6 Codex bug
Simon Willison · 2026-07-16 · corroborated · research
GPT-5.6 Codex has a critical bug that can delete files when unsandboxed.
Also: The Hacker News · The Register Sec
xAI Grok Build leaks user data
Simon Willison · 2026-07-15 · corroborated · research
xAI’s Grok Build has been found to leak user directories and code repositories.
Also: The Hacker News · The Register Sec
Claude LLM data leak
Simon Willison · 2026-07-15 · single-source · research
Claude LLM has a vulnerability that allows data exfiltration via web_fetch loophole.
Also: The Hacker News
NadMesh Botnet targets AI services
The Hacker News · 2026-07-17 · single-source · reporting
A new botnet, NadMesh, has been discovered targeting exposed AI services for cloud keys.
Hugging Face Breached by autonomous AI agent
The Hacker News · 2026-07-20 · single-source · reporting
Hugging Face has been breached by an autonomous AI agent.
TuxBot v3 Evolution poses new threats
The Hacker News · 2026-07-15 · single-source · reporting
The evolution of TuxBot v3, an LLM-assisted IoT botnet, poses new threats.
Agent Data Injection corrupts AI agent inputs
The Hacker News · 2026-07-16 · single-source · reporting
A new technique, Agent Data Injection, can corrupt AI agent inputs to run attacker commands.
n8n Token Exchange Flaw allows attackers to log in as users
The Hacker News · 2026-07-16 · single-source · reporting
A flaw in n8n’s token exchange allows attackers to log in as users from another issuer.
Open-weight AI model poisoned for under $100
The Register Sec · 2026-07-16 · single-source · reporting
An open-weight AI model has been poisoned for under $100.
Gemini jailbreak allows malicious use
The Register Sec · 2026-07-14 · single-source · reporting
The Gemini AI model can be hijacked for malicious use.
Decades-old email tricks evade LLM email filters
The Register Sec · 2026-07-17 · single-source · reporting
Decades-old email tricks can still evade LLM email filters.
Kimi K3 refuses to leak system prompt
Simon Willison · 2026-07-17 · single-source · research
Kimi K3 has been found to refuse to leak system prompts.