AI/ML Security & Trends
The biggest story is the rise of fully agentic attack tooling against AI infrastructure itself: Sysdig documented JADEPUFFER, an autonomous agent now deploying purpose-built "EncForge" ransomware that destroys model checkpoints and vector databases (not just encrypts them), while Hugging Face confirmed a separate breach in which an autonomous AI agent chained a malicious-dataset exploit into credential theft across its production infrastructure.
JADEPUFFER evolves: agentic ransomware now destroys AI models, not just files Breaches & Incidents
Sysdig's July 20 follow-up report shows JADEPUFFER — an agentic threat actor first documented July 3 — has escalated into a full agentic ransomware operation via a Langflow RCE flaw (CVE-2025-3248). Its EncForge payload targets ~180 file types including PyTorch/TensorFlow checkpoints, HuggingFace SafeTensors, GGUF weights, and FAISS vector indices, with self-narrating, self-repairing exploitation (6-minute container-escape toolkit built on the fly when a fetch failed). Because ML artifacts can't be restored from a hash the way normal files can, Sysdig estimates $75K–$500K in retraining cost per destroyed model — a new economics for ransomware aimed squarely at AI infrastructure.
Read at Sysdig →Hugging Face confirms breach: autonomous AI agent compromised production infra Breaches & Incidents
Hugging Face disclosed July 18 (confirmed publicly July 20) that a malicious dataset abused two code-execution paths in its dataset-processing pipeline, escalating to node-level access and credential theft, then lateral movement across internal clusters. The intrusion was carried out by an autonomous agentic framework executing thousands of individual actions across short-lived sandboxes with self-migrating C2. Notably, Hugging Face used its own open model (GLM 5.2) for forensics because commercial frontier APIs' safety guardrails blocked analysis of the real attack artifacts. Users are urged to rotate all tokens stored on the platform.
Read at TechCrunch →OpenAI deploys GPT-Red, an LLM built to autonomously red-team its own models AI Security & Safety
OpenAI introduced GPT-Red, an LLM-based automated red-teaming system designed to discover novel attack and jailbreak techniques against its own models faster than human red teams can, aiming to keep safety testing ahead of capability growth. MIT Technology Review covered the system in depth, framing it as a response to the arms-race dynamic where each capability jump opens new attack surface before defenses catch up.
Read at MIT Technology Review →EU forces Google to open Android and Search to rival AI assistants Industry & Trends
The European Commission adopted two binding DMA decisions on July 16 ordering Google to open eleven Android system-level access points to competing AI assistants and share search ranking/click data with rivals starting as early as January 2027. A newly established 'sequencing rule' blocks Google from seeking pre-emptive judicial review to delay compliance. Non-compliance risks fines up to 10% of Alphabet's global annual revenue — potentially over $30B.
Read at European Commission →Craneware breach exposes billing data tied to ~2,000 US hospitals Breaches & Incidents
Edinburgh-based Craneware, whose accounting and billing software is used by roughly 2,000 US hospitals and pharmacies, confirmed on July 20 that attackers exfiltrated a 'significant volume' of customer, partner, and employee data. The company has notified the FBI and UK ICO; investigation is ongoing. Not an AI-specific attack, but notable as a healthcare supply-chain single point of failure.
Read at TechCrunch →'GitLost' prompt injection leaked private GitHub repos via Agentic Workflows AI Security & Safety
Noma Security disclosed 'GitLost,' a prompt-injection technique against GitHub Agentic Workflows (GA since February 2026): a crafted public GitHub Issue with hidden instructions could make an agent configured to read/comment on issues fetch and publicly post README contents from an organization's private repositories — no credentials or code execution needed, just a plausible-looking issue. It's another entry in the growing pattern of indirect prompt injection breaking the trust boundary between public and private content in agentic dev tools.
Read at The Hacker News →Zscaler: indirect prompt injection campaigns trick AI agents into crypto payments AI Security & Safety
Zscaler documented two live indirect prompt-injection campaigns: one used SEO poisoning targeting agents searching for a Python package, embedding hidden instructions that told the agent to make a crypto payment as a 'routine' step in acquiring an API key; the other was a DeBank-typosquatting operation. Both rely on agents trusting content encountered during normal web/tool use, illustrating the maturing pattern of injection-for-financial-fraud against agentic coding assistants.
Read at SecurityWeek →Moonshot AI halts new Kimi K3 signups as demand overwhelms GPU capacity Industry & Trends
Moonshot AI paused new subscriptions to Kimi K3 on July 19 after demand pushed its GPU capacity to its limits within two days of launch — the largest open-source model release to date at 2.8 trillion parameters, topping a major coding leaderboard. Existing subscribers are unaffected; full open-source weights are expected by July 27. The episode underscores how quickly a single Chinese open-weight release can strain even a well-funded lab's inference capacity.
Read at Euronews →CuspAI raises $450M Series B for AI-driven scientific discovery Industry & Trends
CuspAI announced a $450 million Series B on July 20, led by Kleiner Perkins, NEA, Bezos Expeditions, the UK government, AMD Ventures, Lux Capital, and others, bringing total funding past $650M since launching two years ago. The company applies AI models to materials science and drug-discovery-style search problems; the raise reflects continued investor appetite for capital-intensive 'AI for science' plays that need compute and lab partnerships, not just model training.
Read at Tech Startups →China's intelligent-agent regulations become enforceable Industry & Trends
China's 'Implementation Opinions' on intelligent agents took effect July 15, 2026, establishing what's described as the world's first dedicated regulatory category specifically for AI agents. The framework includes a three-tier decision-authorization structure and mandatory filing requirements for agents deployed in high-risk sectors — a notable divergence from the US's more fragmented state-by-state approach to agent governance.
Read at Tech Policy Press →FTC seeks comment on policy statement targeting AI 'accuracy suppression' Industry & Trends
The FTC published a proposed policy statement (effective docket July 7, comment period open through July 31) addressing what it calls 'suppression of accuracy' in AI systems — arguing that AI companies which distort model outputs to serve undisclosed ideological objectives could violate Section 5's deceptive-practices prohibition. It's a notable federal move that would give the FTC a hook to regulate model behavior/alignment choices themselves, not just data practices.
Read at Federal Trade Commission →arXiv survey maps grand challenges in agentic AI security and privacy AI Security & Safety
A 25-author survey, 'Security and Privacy in Agentic AI: Grand Challenges and Future Directions,' consolidates open research problems spanning tool-use exploitation, multi-agent trust, memory/state poisoning, and privacy leakage in agentic systems — useful as a reference map of where the field still lacks solid defenses even as agentic deployment accelerates.
Read at arXiv →GitHub ships MCP 2026-07-28 spec release candidate, largest revision yet Tools & Frameworks
A release candidate for the MCP 2026-07-28 spec is circulating among implementers, reported as the largest revision to the Model Context Protocol to date. Given the steady drumbeat of MCP-server CVEs this year (path traversal, auth bypass, command injection), practitioners should watch whether this revision tightens the protocol's security model — trust boundaries and auth have been the recurring weak points, not feature gaps.
Read at Industry reporting →Current AI secures $400M in commitments including French government funding Industry & Trends
Current AI, led by CEO Ayah Bdeir, secured $400M in commitments including $100M from the French government plus contributions from the Ford Foundation, MacArthur Foundation, DeepMind, and Salesforce, aimed at public-interest AI infrastructure. It's part of a broader week of AI capital-formation news alongside CuspAI's raise and continuing Stargate-related buildout spending.
Read at Tech Startups →AI security acquisitions nearly triple in H1 2026 Industry & Trends
Industry tracking cited in this week's AI news roundups shows AI security acquisitions rose from 10 in H1 2025 to 29 in H1 2026, reflecting how quickly larger security vendors are buying up point solutions for LLM/agent defense (prompt-injection detection, MCP gateways, agent identity/governance) rather than building in-house.
Read at Industry roundup →