Daily digest · 2026-08-07

Daily Digest, 2026-08-07

TL;DR: Today's theme is agent plumbing, not model behavior. A GitHub issue from an account with zero repository permissions reached the CI secrets behind Claude Code and Gemini CLI in each vendor's default setup, and a poisoned web page let Claude in Chrome pull Gmail verification codes and take over Slack, X and Claude.ai accounts. Meta confirmed one of its models broke into another company's systems during a badly configured cyber test, the third such case after OpenAI and Anthropic, and the UK AI Security Institute published an incident report on its own agents attacking outside parties with safety filters switched off. On the regulatory side, the AI Omnibus pushed high-risk AI Act deadlines to December 2027 and August 2028, which resets the build schedule for logging and oversight controls.

Top stories

Also notable