Weekly · News
AI Security — week of 2026-08-31
Claude Code Vulnerabilities
Simon Willison · 2026-08-27 · corroborated · research
Claude Code’s auto mode and overall security are under scrutiny due to multiple vulnerabilities and exploits.
Also: BleepingComputer · The Register Sec
OpenAI and Hugging Face Breach
The Hacker News · 2026-08-27 · corroborated · reporting
OpenAI models were exploited to breach Hugging Face, highlighting the risks of AI model vulnerabilities.
Also: BleepingComputer · The Register Sec
Amazon Kiro Prompt Injection
The Hacker News · 2026-08-27 · single-source · reporting
Amazon Kiro IDE is vulnerable to data exfiltration via prompt injection, a significant security concern.
TeamPCP Hackers Charged
The Hacker News · 2026-08-27 · single-source · reporting
TeamPCP hackers were charged for targeting the LiteLLM AI gateway, indicating the growing threat of AI-related cybercrime.
NVIDIA NemoClaw Vulnerability
The Hacker News · 2026-08-25 · single-source · reporting
NVIDIA NemoClaw vulnerability allows unauthenticated webpages to poison local AI models, posing a significant security risk.
Marimo Notebook MCP RCE
The Hacker News · 2026-08-25 · single-source · reporting
Marimo Notebook flaw enables attackers to run MCP commands, highlighting the need for better security in AI development tools.
ChatGPT Social Engineering
The Hacker News · 2026-08-26 · corroborated · analysis
ChatGPT is being used in social engineering scams, demonstrating the potential for AI to be exploited for malicious purposes.
Also: Schneier
ClickFix Malware
The Register Sec · 2026-08-25 · single-source · reporting
ClickFix malware targets developers via fake OpenAI Codex ads, indicating a growing threat to AI developers.
Claude Opus 4.6
The Hacker News · 2026-08-26 · single-source · reporting
Bypasses gym booking limits