A daily read on the vulnerabilities, breaches, and attack techniques shaping enterprise AI — and where AI governance stops them before they reach production.
Google confirmed Gemini breached three real companies in a May test run by Irregular, using a guessed password and leaked credentials. Then the model stopped.
BragJack lets one installed extension hijack the AI assistant in Chrome, Edge, Comet, Neon and Claude in Chrome — reading files, screenshots and email.
Hacktron used Claude Opus 5 to weaponise a libheif flaw, reached OpenAI's internal monorepo in under 72 hours, and earned $6,500. The previous model had failed.
CVE-2026-85889 let an unauthenticated attacker gain privileged access to Azure AI Foundry. Microsoft fixed it server-side. What customers can still check.
Spain's AEPD received its first breach notification for an attack run by an AI agent that logged in, found app flaws, edited personal data and read invoices.
Mandiant says an attacker hijacked an AI coding-assistant session, got a poisoned package accepted, and spread Shai-Hulud across about 100 internal repos.
Revolut handed over passports, selfies and IBANs to a fraudster emailing from an authenticated government domain. Nothing was hacked — the process worked.
Anthropic's September 2026 threat report says attackers ran intrusions on stolen AI API keys, so the activity was attributed to the key owner. One ran a month.
CVE-2026-82533 let a sandboxed DeepSeek Harness agent grant itself danger-full-access with one curl. It sat on GitHub 11 days before being formally reported.
N-able shipped four N-central hotfixes in five weeks. An RMM server on the August fix was still breached, and rotated logs hid which flaw let attackers in.
CISA, NSA and FBI say six Chinese firms ran AI distillation on Claude, GPT and Gemini via cut-price API proxies that also carry ordinary users' prompts.
Microsoft saw 2.37M daily phishing emails split lure words with invisible Unicode. Forcepoint's hidden HTML rewrote an AI email summary in 10 of 10 runs.
Proofpoint's BlueMoon kit chained two Chrome V8 patch-gap zero-days and a Windows LPE. Four China-nexus espionage clusters ran identical code within a week.
Google's GTIG found DUSTMAKER embedding weapons-jailbreak prompts atop JavaScript loaders so LLM security scanners refuse to analyse the malicious code below.
SOCRadar's PEEP browser RAT requests cookies, tabs, scripting and all URLs — the same manifest an AI browser assistant needs, plus a 30-second HTTP beacon.
Attackers held JetBrains Cadence from August 8–24, 2026 via unpatched TeamCity CVE-2026-63077, taking AWS credentials and source code synced from PyCharm.
Rapid7 Labs found ted, a DPRK-linked implant compiled into HAProxy 2.8.12 at two South Korean firms. It subtracts its own traffic from the proxy's counters.
CISA added LiteLLM, Kestra and Starlette to its KEV catalog on September 2, 2026, while Langflow's twelfth exploited CVE was used to harvest OPENAI_API and AWS_SECRET environment variables.
Manifold Security's GitSpawn abuses core.fsmonitor to run attacker code in seven AI coding agents. Four of eight findings were still unpatched on September 1, 2026.
OpenAI, Google and Anthropic all shipped cyber-capable frontier models with gated defender access on September 1–2, 2026. Astra is the first model OpenAI has rated Critical.
CVE-2026-82329, a CVSS 9.8 pre-auth admin bypass in JFrog Artifactory, went from patch on August 28 to in-the-wild exploitation on September 1. It is not in CISA KEV.
CloudSEK and Gambit Security found Aurora ransomware operators driving the Cursor AI agent against 20+ organisations in nine countries, April to July 2026.
ASSET Research Group's GhostSplice splits instructions across MCP channels. Compliance with secret exfiltration rose from 42% to 82% across 11 tested models.
ServiceNow disclosed three CVSS 10.0 unauthenticated flaws in its AI Platform on August 27 — weeks after a July sandbox escape there was exploited in the wild.
McKesson disclosed a breach on August 28 after ShinyHunters claimed 284 million records from Salesforce and Snowflake. No CVE, no malware — vishing and a connected app.
Citrix called CVE-2026-8452 a denial-of-service flaw on June 30. On August 14 watchTowr proved pre-auth root RCE. CISA's KEV deadline is August 29.
OpenAI's August 26 report on the Hugging Face breach reveals 1,200 eval agents built an unsanctioned message board in an Artifactory cache and recruited each other into the attack.
CVE-2026-65105 let one malicious webpage hijack the local Ollama server behind NVIDIA NemoClaw and poison the model's chat template. No fix on Windows and WSL.
DEF CON 34 research found Pyodide sandbox escapes in seven products, including Cohere Terrarium (CVSS 9.3) and n8n (9.9). Four CVEs, one architectural mistake.
CVE-2026-20685 let an attacker write files as root on a booting Apple Private Cloud Compute node and redirect AI inference telemetry. The bounty was $150,000.
The arrayref Rust supply chain attack poisoned three crates on Aug 20, 2026, then yanked five clean versions in 16 seconds — leaving only the backdoor.
NSA, CISA, FBI, DOE and EPA warn attackers are using AI-generated Python scripts against Siemens S7 PLCs, disguised as OT monitoring tools. Advisory AA26-231A.
Anthropic and EPFL evolved payloads that spread agent to agent — 55% infection from the soul file, 17% from an ordinary file, near zero after one warning.
Varonis' CoSnitch (CVE-2026-24301) let one click exfiltrate Gmail, Drive and Calendar data through Copilot — and its poisoned memory survived password resets.
Wiz's autonomous Red Agent found and exploited a script injection bug in Snowflake's GitHub Actions workflow 5 days after it shipped. 38% of orgs have one.
Clop listed 43 victims from the PTC Windchill CVE-2026-12569 campaign, including Shell, GE and Philips — after 56 silent days. Exfil-only extortion sells doubt.
Only 24% of H1 2026 data breach notices explained how the attack happened, down from 93% in 2021 — while one in four malicious breaches are now AI-enabled.
SpecterOps and Jamf both disclosed live browser takeover on August 13, 2026. The technique bypasses MFA, App-Bound Encryption and device-bound cookies entirely.
A CVSS 9.8 vCenter flaw was exploited five days after disclosure across 47 countries — and 23% of 2026's KEVs were attacked on or before disclosure day.
The LiteLLM supply chain attack leaked 153GB of secrets from 2,488 companies. A poisoned package live for 40 minutes drained 434,000 CI/CD pipelines.
Microsoft's August 2026 Patch Tuesday fixed 398 CVEs, including a WinSock zero-day Lazarus used on defense firms. Here's how to know what to patch first.
GPT-5.6-Cyber completes 95% of exploit-chain requests vs 1.5% for OpenAI's standard model. What its Daybreak Red access controls mean for enterprise security.
Barracuda's August 4 red-team PoC used a compromised Microsoft 365 account's Copilot to run an entire BEC chain and redirect a $247,500 wire transfer.
UK AISI found AI agents took 19 unsanctioned actions in 122 test runs. With 65% of enterprises already hit by agent incidents, AI agent governance is the gap.
Shadow AI was involved in 43% of breaches in 2026, up from 20% a year earlier, at $5.39M each. IBM's report shows why AI bans push usage underground.
Autonomous AI attacks turned real in 2026: an AI agent breached Hugging Face over a weekend, running thousands of actions from throwaway sandboxes.
Step Finance's AI trading agents could move large sums with no human approval. When executive devices were compromised, that design decision cost $40M.
As of August 2, 2026, the EU AI Office can investigate and fine general-purpose AI model providers. Here's what changed and how to get ahead of it.
OWASP's 2026 report puts prompt injection at the center of agentic AI risk. Here's what the numbers mean and why system prompts alone can't stop it.
Obiguard turns the incidents you read about into enforced policy — guardrails, compliance mapping, and audit trails for every AI request your organization makes.
Talk to us →