Daily digest · 2026-08-16

Daily Digest, 2026-08-16

TL;DR: Today's items pile up around AI systems reaching data they were never meant to touch. Researchers found that the encrypted reasoning objects OpenAI, Anthropic and Google pass between API calls can be replayed into other sessions, pulling back API keys and passwords, while a poisoned AI package quietly shipped terabytes of credentials out of 2,500 users' machines. PortSwigger showed styling code inside an email can break out of the message and manipulate the mail assistant reading it, stealing passwords and tokens across six major webmail services. On the accountability side, a man jailed for 17 months after a bad face match added Amazon Web Services as a defendant, and OpenAI's Black Hat talk on the Hugging Face incident produced a day-by-day timeline of how long the problem went unnoticed inside the company.

Top stories

Also notable