Daily digest · 2026-08-06

Daily Digest, 2026-08-06

TL;DR: Today is about attacks that reach an agent's tools without ever passing a guardrail. AWS, Google and Vercel patched flaws where forged instructions fired tool calls with no model turn at all, so system prompts and filters never ran. Zenity says it hijacked Claude and ChatGPT Atlas browsing with no user click, using text planted in emails and X posts, and the issues are still unpatched. Meanwhile "Ask AI" buttons on real marketing pages are carrying hidden instructions that rewrite what an assistant remembers, and OWASP's 2026 LLM Top 10 keeps prompt injection and data leakage in the top two slots.

Top stories

Also notable