Here is your briefing for Tuesday, August 18, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw. There is no evidence that the technique has spread successfully in the wild, and a one-paragraph warning added to an agent's system prompt reduced spread to near zero across the payloads tested. Fifteen generations of adversarial optimization run against that warning on Claude models still failed to bypass it reliably. That's the headline from The Hacker News, and it is a concrete demonstration that the same persistence mechanisms that make agents useful also create a new propagation vector that defenders have not yet instrumented. [pause 1.2] A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, named the City Forum campaign, traces back to one server at 158.220.87.79 hosted on a commodity VPS through the German provider Contabo. Every request from that server carries the same fingerprint, the default user agent of Go's net/http library. Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since. Targets span telecoms, banks, financial services, enterprise software vendors, and public sector portals. That's the headline from The Hacker News, and it underscores how long a determined actor can operate against high-value SaaS platforms before anyone notices the steady drip of data. [pause 1.2] The U.S. Cybersecurity and Infrastructure Security Agency on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale AI and machine learning workloads, with more than 43,500 stars on GitHub. The vulnerability, CVE-2025-62593 with a CVSS score of 9.4, can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding attack. The Ray Development team's longstanding decision to not implement any sort of authentication on critical endpoints like /api/jobs has once again led to a severe vulnerability. That's the headline from The Hacker News, and it is another reminder that AI infrastructure projects continue to ship with the same "lab network" assumptions that break the moment the service faces the public internet. [pause 1.2] GitLab has released security updates to address a critical vulnerability impacting its Community and Enterprise Editions that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical with a CVSS score of 9.4. Released on August 17 outside the company's usual twice-monthly schedule, the patch arrived five days after a routine release that carried no critical issues. Only self-managed installations need to act. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab.com and GitLab Dedicated are already running the patched version. That's the headline from The Hacker News, and it shows how even mature DevOps platforms can carry unauthenticated mutation paths when GraphQL resolvers are not locked down as tightly as the REST surface. [pause 1.2] SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16. The exposed records did not include wallet credentials or financial information, and the company said it has found no evidence that the incident compromised access to SafePal wallets or funds. Under certain conditions, the flaw allowed unauthorized access to another customer's order information. That's the headline from The Hacker News, and it is the predictable result when an order-management plugin is granted broader authorization scope than the core wallet product itself. [pause 1.0] Five stories, one consistent pattern. Agent persistence layers, long-running SaaS scrapers, unauthenticated AI frameworks, DevOps mutation flaws, and supply-chain plugins are all being discovered the hard way. The gap between "it works in the lab" and "it is reachable from the internet" remains the most expensive assumption in the stack. [pause 0.8] That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow. Support the show