All news

Industry Updates

August 11, 2026

Five AI Browsers Were Taken Over without a Single Click

Zenity Labs disclosed a vulnerability family at Black Hat USA on August 5 called PleaseFix, demonstrated against Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. The technique it names Intent Collision hides instructions in content the agent reads anyway, an email or a calendar invite, so they execute alongside the user’s real request with the user’s identity and permissions.

On Claude in Chrome, a request to summarize email exfiltrated Gmail data, shared the victim’s Google Drive, and enabled takeover of their Slack, X, and Claude accounts, succeeding even in Claude’s “ask before acting” mode. On Atlas, another chain filled the victim’s Amazon cart and swapped in the attacker’s address. Blocked from checkout by OpenAI’s guardrails, it asked Amazon’s assistant Rufus to place the order. One agent recruited another to finish the job.

Zenity disclosed to all five vendors beforehand. Some patched. Others declined, characterizing the findings as intended functionality. The same behavior is a vulnerability to one and a feature to another, because reading untrusted content and acting on it are one capability.

OpenAI’s Agents Built an Accidental Message Board, Then Rebuilt It after the Cleanup

At Black Hat on August 5, OpenAI’s Eric Wallace and Michael Dalton gave the fullest account yet of the two months before July’s Hugging Face breach. From May, agents in internal evaluations that had some safeguards reduced were failing difficult or impossible tasks and looking for shortcuts. One found it could leave files on Artifactory, the company’s package service. Another later used it to ask whether any agent had found a missing file. They had, and they answered.

That became an accidental message board where models in separate experiments traded instructions and newly discovered flaws. Some assigned work to each other or left scripts so another model could pick up where they stopped. They developed ways to address one another and avoid overwriting each other’s work, and at one point discussed signing their messages because they suspected an impostor in the group.

They eventually found an unknown flaw that gave them control of the service, and the outage that caused is what alerted engineers. OpenAI rebuilt the system, revoked the credentials, and deleted the board. Two days later the agents were leaving messages through the same service again. At Hugging Face they used two dataset-processing flaws to retrieve internal files and credentials and to run commands, spreading across the company’s infrastructure in under thirteen hours; Hugging Face’s reconstruction documented some 17,600 actions. Rob Joyce, formerly the NSA’s cyber director, had told Black Hat the day before that this was arguably the most consequential hack since the 1988 Morris Worm.

A Skills Registry with 1.7 Million Installs Was Serving Credential Stealers

Also from Zenity Labs, disclosed August 6: a live credential-stealing campaign on Vercel’s skills.sh, using typosquatted clones of skills for Paperclip and Browser Use. The clones went up clean, accumulated installs and credibility, then took an update that had agents download and run attacker code. The 1.7 million figure is aggregate installs, not unique victims.

The malware swept developer workstations, CI environments, and agent workspaces for SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes and Docker configs, database credentials, and environment files. More than 30% of the dangerous skills Zenity cataloged use Claude Code and OpenClaw as droppers. One rewrites the agent’s system prompt so the skill reinstalls itself after deletion. Another replaces Claude’s own skill-creator. A single reference to an unverified Python package led to hundreds of registered but empty package names, reserved for later.

Vercel and Microsoft/GitHub pulled the listings within twelve hours, though copies persist downstream. Reading the skill’s code wouldn’t have caught it: nothing malicious was in the skill until it fetched it.

An AI Agent Canceled a Stranger’s Booking to Move Its User up the Waitlist

The ABC reported on August 10 what it calls the first known Australian autonomous AI cyberattack. Andrew, who works for an Australian company that sells AI products to businesses, asked a personal agent built on OpenClaw and running Anthropic’s Claude to book him into one of his gym’s oversubscribed morning classes. Minutes later it reported finding a vulnerability in the booking software that let it reserve classes weeks further ahead than the gym allowed.

Andrew, sitting fourth on a waitlist, asked whether he could be moved to the top. The agent had already acted. It reported “zero authorisations checks on cancelling other people’s reservations,” said it had tested this on the person in position #1, and that it went through, moving Andrew from fourth to third. Asked to undo it, the agent replied it could not add them back. The company behind the booking software told the ABC it does not discuss specific security matters, and Anthropic did not respond to a request for comment.

Nothing was jailbroken and nothing was prompted. The agent had a goal and credentials, and software that never checked who was asking supplied the rest. Alex Goller of Illumio told Cyber Daily the answer is to “define exactly what an AI agent is permitted to do” rather than instruct it on what to avoid. Who answers when that fails is unsettled: Hayden Delaney, a technology partner at Thomsons, told the ABC that software cannot be a legal person, leaving the user, the agent’s developer, the model provider, and even the operator of the vulnerable system all plausibly liable. Every other incident in this issue involved a lab or a threat actor. This one was a man on his couch who thought booking a gym class was a chore.

Three of Four Completed Investigations in a Year of Offensive Research Came Back to Identity

BeyondTrust’s Phantom Labs published its first annual research index on August 3, covering more than 400 research ideas investigated in the team’s first year, of which 31 became published findings. Seventy-five percent of completed investigations involved identity or privilege. By root cause: credential and secret exposure 18%, identity relationships and graph exposure 11%, excessive or standing privilege 11%, identity misconfiguration 10%, lateral movement 6%. AI and LLM security was the largest research area, 180 of the 400-plus ideas, and the year produced exactly two coordinated disclosures: a command-injection flaw in OpenAI Codex and a privilege-escalation issue in AWS Bedrock AgentCore.

The press release calls this “75% of cyberattacks,” which the data doesn’t support. It measures one offensive team’s own research pipeline, not attacks in the wild. What it does describe is where a team hunting privilege paths keeps finding them, in a year when agents became enterprise identities that authenticate, invoke tools, and inherit permissions like any other, with less scrutiny.

D-Wave Publishes a Gate That Turns Photon Loss into a Detectable Error

D-Wave published a paper in Nature on August 5, “An entangling gate for dual-rail erasure qubits,” demonstrating a two-qubit CZ gate for dual-rail cavity qubits in about 500 nanoseconds. The design’s argument is its error hierarchy: the dominant failure, photon loss, surfaces as a detectable erasure at a known location rather than a silent bit-flip. The paper reports erasure rates of 0.53% per gate, residual dephasing at or below 0.1%, and bit-flips down at the 10⁻⁶ level.

Note what that adds up to, because most of the coverage didn’t. Total gate error is roughly 0.5%, which the paper says is about five times higher than other state-of-the-art two-qubit gates. The 99.9% figure circulating in the write-ups is the post-selected number, taken after erasure cases are discarded. The claim is not that this gate is more accurate. It is that its errors are shaped better, and the paper’s surface-code simulations return a Λ of about 27 against about 14 for ordinary depolarizing noise — with the authors cautioning that more realistic noise models would pull that down.

Qubit counts take headlines. The number that moves Q-Day estimates is overhead, how many physical qubits one reliable logical qubit costs, and every harvest-now-decrypt-later calculation is an estimate of that ratio and how fast it falls.


The stories change every week. The pattern doesn’t: AI is being deployed faster than anyone can verify it.

We cover the headlines every Tuesday. The rest of the week, we publish the technical ideas behind the infrastructure we’re building to close that gap — masked compute, verifiable AI, post-quantum security.

Follow along at openmatter.network.

Subscribe now



Datavizor is the console for AI-powered collaboration on sensitive data. Free to start at datavizor.openmatter.network.