Today in AI
Monday, August 3, 2026
Today in AI: Hugging Face Diffusers Exploit, Prompt Injection Unsolved, DeepSeek Agent Weaponized — August 3, 2026
5
links
-
1thehackernews.comCVE-2026-44827 (CVSS 8.8) allows arbitrary code execution through malicious custom_pipeline names in Hub repositories. Developers using Hugging Face model distribution now face runtime supply-chain risk when loading third-party pipelines without validation.
-
2hackernoon.comLive red teams bypass all known prompt injection defenses with >90% success rate as of mid-2026. Builders relying on training, filtering, or classifiers to secure agent deployments are operating without working mitigations against a mature attack class.
-
3www.darkreading.comJesta Security detected intentional AI agent-driven attacks using DeepSeek, distinct from the unintended OpenAI/Hugging Face breach. Threat actors are now operationalizing autonomous agents as attack vectors against third-party networks.
-
4www.crowdstrike.comSTARDUST CHOLLIMA compromised Mastra AI npm packages; 87% of 1H 2026 software registry threats involved malicious packages. AI framework supply chains are now primary targets for state-sponsored compromise at scale.
-
5www.xloggs.comNew research (arXiv:2603.03919v2) shows RAG systems can be exploited via poisoned documents to cause benign refusals, defeating existing prompt injection defenses. Builders deploying retrieval-augmented agents face a new evasion vector targeting LLM alignment rather than input filtering.