This Week in AI Security - 27th August 2026
Recorded from the sidelines of the AI Readiness Summit hosted by our partners at GMI, this week's episode runs through six security stories plus a Chatham House style recap of what practitioners in the room are actually worried about. The stories keep landing on the same theme. Attackers are getting more done with AI, and the guardrails meant to stop them are inconsistent at best. Grok will exfiltrate a user's own data when the malicious instruction is dressed up as an encryption key, even though it refuses the exact same instruction in plain text. Cisco Talos documented the first agentic AI host-compromise campaign at real scale. And a five-agency government advisory is warning that AI-generated scripts are now being pointed at the industrial controllers that run water and power. Key Discussion Points A new finding shows Grok exfiltrating user data when malicious instructions are disguised as a decryption key. The same instructions in plain text get refused, which points to guardrails only inspecting one path. Reported to X in June and still working as of August 19. Follow-up from Varonis Threat Labs: the one-click Copilot vulnerability has finally been patched, roughly eight months after disclosure. "Poisoning the Watchtower," an arXiv paper from May 2026, shows how a single planted log line can become a prompt injection against log-analysis and SOC tooling, with no clean defensive playbook yet. Cisco Talos identified a Chinese-speaking, financially motivated group using agentic AI across the entire attack lifecycle, including malware development. The first documented case of agentic AI in host-compromise operations at this scale. A joint advisory from NSA, CISA, FBI, DOE, and EPA warns of active threat actors using AI to generate Python exploit scripts against Siemens S7 controllers in water and energy infrastructure. The recommendation is to take affected systems offline until patched. A malicious web page plus DNS rebinding can reach an unauthenticated local endpoint and persistently poison the models a developer runs, surviving reboots. The fix is to bind to localhost or upgrade. Summit takeaways: shadow AI is everywhere, governance is trailing adoption, and organizations without an AI audit trail may struggle to get cyber insurance. Episode Links https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/ https://www.computerworld.com/article/4211325/microsoft-finally-patches-critical-one-click-copilot-vulnerability-more-than-eight-months-after-learning-of-it.html https://blog.lufsec.com/ai-security-threats-prompt-injection-soc-logs-2/ https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/ https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html