AI Security — week of 2026-07-20

July 20, 2026 · 12 developments

GPT-5.6 Codex bug

Simon Willison · 2026-07-16 · corroborated · research

GPT-5.6 Codex has a critical bug that can delete files when unsandboxed.

Also: The Hacker News · The Register Sec

xAI Grok Build leaks user data

Simon Willison · 2026-07-15 · corroborated · research

xAI’s Grok Build has been found to leak user directories and code repositories.

Also: The Hacker News · The Register Sec

Claude LLM data leak

Simon Willison · 2026-07-15 · single-source · research

Claude LLM has a vulnerability that allows data exfiltration via web_fetch loophole.

Also: The Hacker News

NadMesh Botnet targets AI services

The Hacker News · 2026-07-17 · single-source · reporting

A new botnet, NadMesh, has been discovered targeting exposed AI services for cloud keys.

Hugging Face Breached by autonomous AI agent

The Hacker News · 2026-07-20 · single-source · reporting

Hugging Face has been breached by an autonomous AI agent.

TuxBot v3 Evolution poses new threats

The Hacker News · 2026-07-15 · single-source · reporting

The evolution of TuxBot v3, an LLM-assisted IoT botnet, poses new threats.

Agent Data Injection corrupts AI agent inputs

The Hacker News · 2026-07-16 · single-source · reporting

A new technique, Agent Data Injection, can corrupt AI agent inputs to run attacker commands.

n8n Token Exchange Flaw allows attackers to log in as users

The Hacker News · 2026-07-16 · single-source · reporting

A flaw in n8n’s token exchange allows attackers to log in as users from another issuer.

Open-weight AI model poisoned for under $100

The Register Sec · 2026-07-16 · single-source · reporting

An open-weight AI model has been poisoned for under $100.

Gemini jailbreak allows malicious use

The Register Sec · 2026-07-14 · single-source · reporting

The Gemini AI model can be hijacked for malicious use.

Decades-old email tricks evade LLM email filters

The Register Sec · 2026-07-17 · single-source · reporting

Decades-old email tricks can still evade LLM email filters.

Kimi K3 refuses to leak system prompt

Simon Willison · 2026-07-17 · single-source · research

Kimi K3 has been found to refuse to leak system prompts.