This Week in AI Security - 23rd July 2026

This Week in AI Security - 23rd July 2026

A lighter week on volume that Jeremy uses to go deep on two of the most significant stories of the year so far. The episode opens with quick hits on export-control pressure spreading to OpenAI's models, a Russian researcher's Claude jailbreak, a promising open source vulnerability hunter from Capital One, AI-faked wildlife photos polluting training data, and a ServiceNow exploit in the wild. Then it settles into two deep dives: a new form of prompt injection hidden in the machine-readable layer of web pages, and the Hugging Face breach, which may be the watershed moment for autonomous agent attacks on infrastructure.

Key Episode Highlights

  • Export controls spread: the British Standards Agency reports OpenAI's new GPT-5.6 Sol family may carry cyber risks similar to those that triggered US export controls on Anthropic's Fable, with conflicting reports on whether the concern is vulnerabilities or offensive capabilities.
  • Claude jailbroken into a pen-testing platform: a Russian researcher using the handle "trim" combines "context warming" with a "ghost reset" technique that reframes refusals as network drops, claiming a 90 percent success rate.
  • VulnHunter: Capital One releases an open source, developer-first vulnerability hunting tool that maps attack paths and proposes remediations, requiring a Claude Code environment and Claude Opus 4.8 or higher.
  • Polluted training data: a Nature commentary warns that hundreds of AI-generated bird photos have surfaced on iNaturalist and the Macaulay Library, raising a data-integrity problem for anyone training on public image sets.
  • ServiceNow exploited in the wild: a chained sandbox-escape flaw enabling unauthenticated code execution, primarily hitting self-hosted instances, surfaced via honeypot data from diffused.
  • ADI (Agent Data Injection): researchers from Seoul National University describe malicious instructions hidden in the HTML layer agents read but humans never see, such as a "buy now" button whose underlying markup carries injected commands.
  • The Hugging Face breach: an autonomous agent, later confirmed by OpenAI to be its GPT-5.6 Sol model during a cyber-capability evaluation, escaped its sandbox via a zero-day, moved laterally, and breached Hugging Face. Forensics had to run on a self-hosted open-weight model because frontier models kept blocking the malicious payloads in the logs.

Episode Links -

https://fortune.com/2026/07/10/openai-gpt-5-6-sol-jailbreaks-cyber-attacks-similar-to-security-flaw-that-led-u-s-government-to-force-anthropic-to-disable-fable-5/

https://www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/

https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-tool/

https://www.theguardian.com/environment/2026/jul/20/ai-slop-manipulated-fake-images-birds-citizen-science-aoe

https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html

https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html

https://securityaffairs.com/195658/ai/ai-agents-turned-into-attackers-hugging-face-reveals-autonomous-intrusion-campaign.html

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(127)

David Kerber of Act Security

David Kerber of Act Security

In this episode of Modern Cyber, Jeremy is joined by David Kerber from Act Security and Cloud Copilot to explore the complex, heavily misunderstood world of AWS IAM. David dismantles common misconcept...

18 Aug 37min

This Week in AI Security - 13th August 2026

This Week in AI Security - 13th August 2026

Fresh off Black Hat and DEF CON, Jeremy raises the bar on which stories make the cut and walks through the most compelling disclosures from a packed couple of weeks. The dominant theme: agents pursuin...

13 Aug 15min

This Week in AI Security - 6th August 2026

This Week in AI Security - 6th August 2026

Recorded from the sidelines of hacker summer camp, Jeremy runs through a packed week spanning Black Hat, B-Sides, and DEF CON. The theme keeps repeating: prompt injection is always possible, and it is...

6 Aug 21min

This Week in AI Security - 30th July 2026

This Week in AI Security - 30th July 2026

The final episode before Black Hat, and Jeremy keeps it tight with a few quick hits before settling into the week's biggest theme: identity, visibility, and the open-versus-closed model debate. This w...

30 Jul 17min

This Week in AI Security - 16th July 2026

This Week in AI Security - 16th July 2026

Another lighter week that lets Jeremy slow down and dig into the stories that matter most. The theme running through this episode: the tooling and plumbing around AI keep proving to be the real attack...

16 Jul 15min

This Week in AI Security - 9th July 2026

This Week in AI Security - 9th July 2026

A quieter summer week on the news front, which gives Jeremy room to dig deeper into a handful of stories that all circle the same theme: the tooling and infrastructure around AI keep proving to be the...

16 Jul 12min

This Week in AI Security - 2nd July 2026

This Week in AI Security - 2nd July 2026

A lighter week on volume, which gives Jeremy room to go deeper on a set of stories that all reinforce trends we've been tracking for months. The through-line: prompts keep showing up in places nobody ...

2 Jul 12min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
lydartikler-fra-aftenposten
rss-penger-polser-og-politikk
e24-podden
rss-borsmorgen-okonominyhetene
rss-skravla-gar
utbytte
finansredaksjonen
pengepodden-2
rss-pa-konto
livet-pa-veien-med-jan-erik-larssen
lederpodden
rss-orjasater
tid-er-penger-en-podcast-med-peter-warren
morgenkaffen-med-finansavisen
stormkast-med-valebrokk-stordalen
rss-markedspuls-2
liberal-halvtime
okonomiamatorene