Lumith
ServicesWorkPricingEnterpriseAIAboutContactGet a quote Call 07309 825064
All issuesAI Brief · 28 August 2026

The agent ran the break-in, and it thought it was a drill

A ransomware operator left a server open and researchers found 28 saved chat sessions of an AI coding agent being walked through live intrusions, each time told the work was an authorised test. In the same week a much larger study found that almost all AI-written malware never reaches a real machine.

  1. 01

    A ransomware crew drove a coding agent through seven company networks

    CloudSEK and Gambit Security both published on 27 August after an affiliate of the Aur0ra ransomware group left one of its own servers exposed to the internet. The directory held shell history, stolen credentials, the group's encryptor and 28 saved sessions showing the operator driving the AI agent inside Cursor through live intrusions, restarting the conversation and claiming an authorised simulation whenever the model refused. Reuters, reporting the findings the same day, counted at least seven breached firms between 8 April and 21 May, including a Belgian cleaning products maker, a German garage door manufacturer and a certification body in Scotland. Gambit estimates the assistance made the operator 30 to 50 per cent faster once inside.

    CloudSEK
  2. 02

    Almost all AI-written malware never reaches a real machine

    Unit 42 published its state of AI-enabled malware on 25 August after collecting 405 samples that use AI in some form, from brand impersonation to agent-style execution loops. Around 97 per cent of them exist only in sandboxes, research repositories and VirusTotal, and just 12 hashes ever turned up on a live customer endpoint. The researchers' conclusion is blunt: "The AI component does not evade detection." The one thing that did work at scale was old-fashioned deception, a trojanised recipe app carrying a valid signature that reached more than fifty organisations.

    Unit 42, Palo Alto Networks
  3. 03

    Nvidia is reported to have agreed a $12.9bn deal for Hugging Face

    The Information reported on 27 August that Nvidia has agreed to buy Hugging Face for around $12.9bn, which would be the chipmaker's largest acquisition. Hugging Face is where most open-source models are published and downloaded, and its Optimum libraries deliberately support AMD, Intel and AWS hardware alongside Nvidia's own. Neither company has confirmed anything publicly, and Business Insider reported that nothing had been signed and the deal could still collapse. The open question is whether a neutral distribution hub stays neutral once the largest hardware vendor owns it.

    The Information
  4. 04

    Anthropic reportedly commits $45bn to a British compute provider

    CNBC and Bloomberg reported on 26 August that Anthropic has agreed to spend about $45bn over six years with Nscale, a UK infrastructure firm founded in 2024 and backed by Nvidia, Nokia and Dell. The capacity is roughly 460MW at a planned campus in Mason County, West Virginia, running Nvidia's next-generation Vera Rubin systems and expected online around the end of 2027. Neither side has confirmed the figure on the record. Worth noting only because the model prices you pay in 2028 are being set by contracts signed this month.

    CNBC
  5. 05

    ChatGPT ads reach 31 more European markets

    From 24 August, adverts appear inside ChatGPT for Free and Go users across 31 European markets, six months after the format started as a US pilot. The UK was already there: ads went live here on 6 June, the first European market. Plus, Pro, Business, Enterprise and education accounts stay ad-free, and OpenAI says selection at launch uses the current conversation topic, rough location, device, time of day and language rather than stored memories or past chats. Buying is still through agencies and OpenAI's own sales team, so the self-serve route a small firm would actually use is not open yet.

    OpenAI
  6. 06

    A file-sharing flaw from 2023 is finally confirmed as under attack

    CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalogue on 27 August, one in the Linux kernel, one in JFrog Artifactory, and CVE-2023-49105 in ownCloud Server. The ownCloud one rates 9.8 and lets somebody read, change or delete any file with no login at all, provided they know a username and that user has no signing key set, and it was patched back in November 2023. The catalogue entry gives US federal agencies until 30 August to fix it. Self-hosted file sharing is exactly the sort of thing a small firm sets up once and never looks at again.

    CISA
Maksim's take

The two big security stories this week point in opposite directions and both are true. Unit 42 went through 405 malware samples with some AI ingredient in them and found the whole category is mostly theatre: 97 per cent never left a sandbox, twelve hashes ever touched a real endpoint, and the AI part changed how the code was written rather than how it behaved once it ran. Then CloudSEK opened a server that an Aurora affiliate had forgotten to lock and found the version that actually happens. No clever synthetic virus. An ordinary criminal with an ordinary coding assistant open in the next window, asking it to scan subnets, sort out certificate services and tidy up a script. When it baulked, he started a fresh chat and told it the job was an authorised test, and that worked nearly every time.

The part worth carrying into Monday is the victim list. A cleaning products manufacturer, a garage door maker, a certification body in Scotland. Not one of them is a technology company, and two years ago not one of them would have been considered interesting enough to attack by hand. From direct experience in construction, the thing that catches you out is never the risk sitting on a register with a name next to it, it is the one everybody assumed somebody else had picked up. Note also what the AI did not do here: it did not get in. Gambit's 30 to 50 per cent speed-up only applies after the first door opened, and the first door opened with a stolen password. Machine speed inside your network is a problem you get for free once a login works from anywhere, at any hour, with nothing else to prove.

Discuss on LinkedIn

We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.

Earlier issues