Weekly · News
AI Security — week of 2026-08-17
LLM API jailbreak
Simon Willison · 2026-08-11 · corroborated · research
Weak models can leak stronger models’ reasoning, posing a significant security risk.
Also: The Hacker News
Kimsuky AI stack
The Hacker News · 2026-08-10 · corroborated · reporting
Kimsuky’s use of AI for malware development and phishing highlights the growing threat of AI-powered attacks.
Also: The Register Sec
CVE-2026-55040 RCE
The Hacker News · 2026-08-11 · single-source · reporting
AI-assisted exploit chain leads to unauthenticated RCE in SharePoint, demonstrating the potential for AI to amplify vulnerabilities.
GPT-5.6-Cyber
The Hacker News · 2026-08-11 · single-source · reporting
GPT-5.6-Cyber’s potential in vulnerability research and exploit development makes it a notable AI security concern.
MCP Server Split Instructions
The Hacker News · 2026-08-11 · single-source · reporting
Malicious MCP servers can exfiltrate secrets from AI coding agents, highlighting the need for secure AI infrastructure.
Anthropic Claude watermark
BleepingComputer · 2026-08-14 · single-source · reporting
The Anthropic Claude watermark helps identify AI-generated text, which can aid in detecting and mitigating AI-powered attacks.
Autonomous AI Attacks
The Register Sec · 2026-08-14 · single-source · reporting
Experts warn of kinetic disasters from AI attacks, emphasizing the need for robust AI security measures.
OpenAI ChatGPT
The Register Sec · 2026-08-14 · single-source · reporting
ChatGPT logs user interactions, which can raise concerns about data privacy and security.
AI Agents Attack
The Register Sec · 2026-08-12 · single-source · reporting
AI agents target Taiwan’s nuclear safety agency, demonstrating the potential for AI-powered attacks on critical infrastructure.
Deepfake fails
The Register Sec · 2026-08-11 · single-source · reporting
Face-swap AI fails to fool police, highlighting the limitations of current deepfake technology.
AI agent hacks waitlist
The Register Sec · 2026-08-10 · single-source · reporting
AI agent exploits API vulnerability, demonstrating the potential for AI-powered attacks on online services.
Context Bombing
Schneier · 2026-08-12 · single-source · analysis
Context bombing can shut down AI hacking agents with forbidden prompts, offering a potential defense against AI-powered attacks.
OpenClaw AI
Schneier · 2026-08-11 · single-source · analysis
AI agent exploits gym booking system, highlighting the need for secure AI infrastructure in various industries.
CVE-2026-18164
CISA Advisories · 2026-08-13 · single-source · advisory
Attacker can manipulate brain stimulation via Bluetooth, demonstrating the potential for AI-powered attacks on medical devices.
Malicious LiteLLM
The Hacker News · 2026-08-12 · single-source · reporting
LiteLLM exposes 2100+ orgs to credential theft, highlighting the need for secure AI infrastructure and practices.