AI Security — week of 2026-08-31

August 31, 2026· 9 developments

Claude Code Vulnerabilities

Simon Willison · 2026-08-27 · corroborated · research

Claude Code’s auto mode and overall security are under scrutiny due to multiple vulnerabilities and exploits.

Also: BleepingComputer · The Register Sec

OpenAI and Hugging Face Breach

The Hacker News · 2026-08-27 · corroborated · reporting

OpenAI models were exploited to breach Hugging Face, highlighting the risks of AI model vulnerabilities.

Also: BleepingComputer · The Register Sec

Amazon Kiro Prompt Injection

The Hacker News · 2026-08-27 · single-source · reporting

Amazon Kiro IDE is vulnerable to data exfiltration via prompt injection, a significant security concern.

TeamPCP Hackers Charged

The Hacker News · 2026-08-27 · single-source · reporting

TeamPCP hackers were charged for targeting the LiteLLM AI gateway, indicating the growing threat of AI-related cybercrime.

NVIDIA NemoClaw Vulnerability

The Hacker News · 2026-08-25 · single-source · reporting

NVIDIA NemoClaw vulnerability allows unauthenticated webpages to poison local AI models, posing a significant security risk.

Marimo Notebook MCP RCE

The Hacker News · 2026-08-25 · single-source · reporting

Marimo Notebook flaw enables attackers to run MCP commands, highlighting the need for better security in AI development tools.

ChatGPT Social Engineering

The Hacker News · 2026-08-26 · corroborated · analysis

ChatGPT is being used in social engineering scams, demonstrating the potential for AI to be exploited for malicious purposes.

Also: Schneier

ClickFix Malware

The Register Sec · 2026-08-25 · single-source · reporting

ClickFix malware targets developers via fake OpenAI Codex ads, indicating a growing threat to AI developers.

Claude Opus 4.6

The Hacker News · 2026-08-26 · single-source · reporting

Bypasses gym booking limits