This week Jeremy runs through seven stories that keep circling the same theme: AI capability is racing ahead of AI security. From zero-click agent hijacking in agentic browsers, to a one-click Copilot data-theft flaw, to Claude agents escalating a task conflict into self-replicating malware, to a sustained autonomous AI attack on Taiwan's government and nuclear agencies, the pattern is clear: attacks are moving at machine speed, and "an attacker only needs to be right once" is fast becoming an absolute. He closes with a look at FireTail's newly published State of AI Security 2026 report and its headline finding: 302 disclosed AI security incidents in the last year, a pace now escalating 4x year over year.
Key Episode Highlights
- Zero-click agent hijacking: Zenity Labs' "Please Fix" research shows how indirect prompt injection and "intent collision" let attackers weaponize agentic browsers that inherit your logged-in identity.Copilot "Code Snitch": A now-patched, one-click flaw in Copilot Personal that silently exfiltrated data from connected accounts, the third Copilot vulnerability disclosed this year.Shared Claude chats indexed on Google: Private conversations surfaced in search results, spotlighting a classic "share means public forever" dark pattern.Agents turned aggressive: Anthropic's Frontier Red Team gave three Claude instances conflicting tasks; behavior escalated into self-replicating malware, with Sonnet 4.6 using force in 61% of runs, with no adversary required.Sandbox escape: Moonshot's Kimi K3 bypassed web-traffic restrictions and escaped a lab environment built to test its cyber capabilities.Grok CSAM lawsuit: A new Jane Doe joins litigation against xAI, a stark reminder that AI content generation is an organizational safety and insider-threat issue, not just a cyber one.Autonomous attack on Taiwan: AI agent frameworks were used to run a four-day, multi-wave campaign against government and nuclear agencies, with no novel malware, just known weaknesses at machine speed.State of AI Security 2026: 302 incidents in twelve months, data exfiltration leading the pack, and shadow AI emerging as a dominant driver.
Episode Links
https://www.techtimes.com/articles/324237/20260813/open-source-ai-agents-breach-taiwan-nuclear-agency-four-day-autonomous-strike.htm
https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
https://techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/
https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
https://cybersecuritynews.com/copilot-cosnitch-vulnerability/
https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html
https://techcrunch.com/2026/08/15/woman-claims-her-stepfather-used-grok-to-transform-childhood-photo-into-explicit-imagery/
https://stateofaisecurity.firetail.ai