← Back to Last Week in AI
Week of August 10 2026

Last Week in AI Security — Week of August 10, 2026

California launches AI cyber defense program as llama.cpp vulnerabilities expose local inference infrastructure and vLLM patches critical RCE flaws.

Key Highlights

  • California launches AI Cyber Defense Program requiring AI Cybersecurity Officers in every state agency
  • Ten vulnerabilities disclosed in llama.cpp including two critical 9.2 CVSS flaws in llama-server
  • CVE-2026-24747: PyTorch weights_only RCE affects versions through 2.9.1, patch available in 2.10.0
  • vLLM patches CVE-2026-22778 RCE via malicious video URL; multiple SSRF bypasses disclosed
  • Zenity, Obsidian Security, Hush Security raise $240M combined to secure AI agent identities

Executive Summary

The week of August 10, 2026 saw California Governor Gavin Newsom announce an AI Cyber Defense Program directing state agencies to use AI for vulnerability detection, network hardening, and incident response, establishing a model that may set the pattern for state-level AI security governance nationwide. The program landed against the backdrop of a proposed federal fiscal 2027 budget cutting CISA by roughly $707 million and ending federal MS-ISAC funding, positioning California as a counterweight to federal retreat on critical infrastructure protection.

On the vulnerability front, researchers disclosed 10 vulnerabilities in llama.cpp, including memory-safety weaknesses and two llama-server flaws rated 9.2, exposing the attack surface of local AI inference infrastructure that many organizations assumed was inherently safer than cloud-based services. The disclosures followed a critical vulnerability in PyTorch’s weights_only unpickler (CVE-2026-24747) allowing attackers to craft malicious checkpoint files capable of corrupting memory and potentially achieving arbitrary code execution, affecting all PyTorch versions through 2.9.1.

The investment landscape reflected growing market recognition that AI agents represent a fundamentally new identity and access management challenge. Zenity raised a $125 million Series C led by Norwest on August 11, 2026, alongside an $85 million Series D for Obsidian Security and a $30 million round for Hush Security to secure the “non-human workforce” of agents and bots, with all three companies flagging the same gap: existing tooling cannot manage agents that hold identities and long-running state.

Top Stories

California Launches Statewide AI Cyber Defense Program

Governor Gavin Newsom announced an AI Cyber Defense Program on August 10, 2026, directing state agencies to use AI for vulnerability detection, network hardening, and incident response inside the California Cybersecurity Integration Center. The program represents the most comprehensive state-level initiative to operationalize AI as a defensive capability, and arrives at a moment when federal cybersecurity funding faces severe contraction.

The directive tells every agency to name an AI Cybersecurity Officer, and it landed against a federal retreat, a proposed fiscal 2027 budget cutting the Cybersecurity and Infrastructure Security Agency by roughly $707 million and the end of federal MS-ISAC funding. For smaller utilities and municipalities that have historically leaned on federal coordination, this creates a capability gap that California is attempting to fill at the state level.

A state is filling a defensive gap Washington is widening, one smaller utilities lean on. An AI Cybersecurity Officer in every agency turns “someone should own this” into an accountable role. The governance structure ensures that AI security ownership is explicit rather than diffused across IT, security, and compliance functions.

The program’s effectiveness will depend on execution quality. The program bets AI defense can match AI offense, a bet with real execution risk. Security practitioners should watch how California’s AI Cybersecurity Officers balance the promise of automated vulnerability detection against the operational reality that AI-driven defense tools often require significant tuning, supervision, and integration with existing security workflows.

For organizations operating critical infrastructure in California, if you run infrastructure in California, learn how your sector plugs into Cal-CSIC’s new capabilities. The program likely presages similar initiatives in other states and provides a template for how state governments may structure AI security roles and responsibilities.

Vulnerabilities Expose Local AI Inference Infrastructure

The assumption that local AI infrastructure is inherently more secure than cloud-based services took a significant hit this week. Researchers disclosed 10 vulnerabilities in llama.cpp, including memory-safety weaknesses and two llama-server flaws rated 9.2. Organizations running local AI models remain responsible for the surrounding infrastructure and should update affected components, minimize network exposure, isolate inference services, restrict model and API access, and monitor for anomalous requests or crashes.

llama.cpp is widely deployed as the inference engine behind local AI applications, including Ollama, LM Studio, and a range of developer tools. The disclosure of two critical 9.2 CVSS vulnerabilities in llama-server demonstrates that inference infrastructure carries the same software supply chain and memory-safety risks as any other network-exposed service.

The timing is significant. Research presented around DEF CON 34 and Black Hat 2026 also showed how AI systems can expose data, compromise development workflows, accelerate exploit creation, and take damaging actions through vulnerable APIs. The conference presentations established that local inference engines, model registries, and AI development tooling now represent a mature attack surface with documented exploitation paths.

Security teams deploying local inference infrastructure should treat it with the same rigor applied to production databases and identity providers. Organizations must treat AI model-serving infrastructure—Ollama, LM Studio, LangServe, OpenWebUI, and AI gateway proxies—as high-value targets requiring the same zero-trust hardening applied to production databases and identity providers. Network segmentation, authentication, access controls, and monitoring are not optional.

AI Agent Identity Management Attracts $240 Million in Funding

The market delivered a clear signal this week: securing the “non-human workforce” of AI agents and autonomous systems has become a critical enterprise security gap. Zenity raised a $125 million Series C led by Norwest on August 11, 2026, alongside an $85 million Series D for Obsidian Security and a $30 million round for Hush Security to secure the “non-human workforce” of agents and bots.

All three flagged the same gap, that agents hold identities and long-running state existing tooling cannot manage effectively. Traditional identity and access management (IAM) systems were designed for human users with predictable authentication patterns, session durations, and approval workflows. AI agents operate continuously, invoke multiple tools across system boundaries, store context across sessions, and make autonomous decisions that existing IAM architectures struggle to govern.

The funding rounds reflect a broader recognition that agentic AI security is not a subset of application security or identity management—it is a distinct discipline requiring purpose-built tooling. The market answered this week’s agent anxiety with checks, providing capital to companies building governance platforms that can verify agent behavior, enforce least-privilege access, and provide audit trails for autonomous actions.

For security teams, the investment thesis is clear: if your organization is deploying AI agents with access to internal systems, customer data, or external APIs, you need dedicated tooling to discover, classify, and monitor non-human identities. The traditional assumption that “we’ll manage bots like service accounts” is insufficient when those bots reason, plan, and act across complex workflows.

Framework & Standards Updates

NIST AI RMF Critical Infrastructure Profile

On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. The profile will guide critical infrastructure operators towards specific risk management practices to consider when engaging AI-enabled capabilities. While this concept note was published in April, its implications are being actively operationalized throughout August as infrastructure operators begin aligning their AI deployments to sector-specific risk profiles.

The AI RMF 1.0 is being revised as part of the White House AI Action Plan, signaling that the framework will continue to evolve beyond its current voluntary status.

MITRE ATLAS Adds Agentic AI Techniques

MITRE ATLAS received significant updates in early 2026 expanding coverage of agentic AI threats. The November 2025 framework update (v5.1.0) expanded to 16 tactics, 84 techniques, 32 mitigations, and 42 case studies, with continued updates through February 2026 adding agentic AI techniques. As of version 5.1.0 (November 2025), the framework contains 16 tactics, 84 techniques, 56 sub-techniques, 32 mitigations, and 42 real-world case studies. The February 2026 update (v5.4.0) added further agent-focused techniques.

In the first MITRE ATLAS update of 2026, Zenity researchers contributed substantially to expanding the framework’s coverage of agentic AI threats, reflecting a reality we see across enterprises: AI agents are operational, privileged, and deeply embedded in business workflows. The contributions formalize attack patterns that security teams can now map to detection and mitigation strategies.

Vulnerability Watch

CVE-2026-24747: PyTorch weights_only RCE (CVSS 8.8)

A critical vulnerability has been identified in PyTorch’s weights_only unpickler that allows attackers to craft malicious checkpoint files (.pth) capable of corrupting memory and potentially achieving arbitrary code execution. When a victim loads a specially crafted checkpoint file using torch.load(…, weights_only=True), the vulnerable deserialization mechanism can be exploited to execute arbitrary code on the target system.

Affected versions: PyTorch through 2.9.1
Fixed in: PyTorch 2.10.0 or newer
CVSS score: 9.8 (initially reported) / 8.8 (GitHub Advisory Database)

This vulnerability is particularly concerning in machine learning workflows where model checkpoints are frequently shared between researchers, downloaded from public repositories, or loaded from untrusted sources.

Mitigation: Organizations using PyTorch should prioritize patching to version 2.10.0 or later. Until updates are applied, users should exercise extreme caution when loading checkpoint files from untrusted sources. Machine learning practitioners should verify the integrity and origin of model files before loading them, especially in production environments.

CVE-2026-22778: vLLM RCE via Video Processing (CVSS 9.8)

CVE-2026-22778 enables remote code execution on vulnerable vLLM deployments by submitting a malicious video link to the API. An attacker sends a malicious video URL to a vLLM endpoint serving a video model, triggering remote code execution on the GPU cluster. The exploit chains an ASLR bypass through leaked PIL error messages with a heap overflow in the JPEG2000 decoder. The vulnerability targets video-processing endpoints specifically, but illustrates the broader attack surface.

Affected versions: vLLM versions prior to 0.14.1
Fixed in: vLLM 0.14.1
CVSS score: 9.8 (estimated)

Mitigation: Update vLLM to the latest version that includes the fix (0.14.1). If you cannot update to the latest version, consider disabling the video model feature in production until patched.

Multiple vLLM Vulnerabilities

vLLM published multiple security advisories this week beyond CVE-2026-22778:

  • CVE-2026-25960 (CVSS 7.1, disclosed March 9, 2026) shows that the security problems persist. A parser differential between urllib3 and yarl in load_from_url_async enables SSRF protection bypass
  • CVE-2025-30165 (CVSS 8.0) enables RCE via unsafe pickle deserialization in vLLM’s multi-node ZeroMQ communication. vLLM has since mitigated this vector by making the V1 engine the default, which eliminates the unsafe pickle deserialization path. Deployments still running the V0 engine remain vulnerable

Organizations running vLLM should review the vLLM security advisories page for the complete list of patches and ensure they are running current versions.

llama.cpp Vulnerabilities (CVSS 9.2)

Researchers disclosed 10 vulnerabilities in llama.cpp, including memory-safety weaknesses and two llama-server flaws rated 9.2. Organizations running local AI models remain responsible for the surrounding infrastructure and should update affected components, minimize network exposure, isolate inference services, restrict model and API access, and monitor for anomalous requests or crashes.

Specific CVE identifiers and version numbers were not provided in available sources. Organizations using llama.cpp should monitor the project’s GitHub repository for security advisories.

CVE-2026-53413: Zoom “Zoomsday” RCE (CVSS 8.3)

While not strictly an AI vulnerability, this disclosure is relevant to AI security teams given the prevalence of AI-powered meeting assistants and summarization tools. Zoom published fixes on August 11, 2026 for a zero-click remote-code-execution flaw dubbed “Zoomsday,” tracked as CVE-2026-53413 with a CVSS score of 8.3. The bug in Zoom’s annotation feature lets a malicious participant run code on another attendee’s device with no click, and A Security said it built the exploit with public AI models in under 24 hours and fewer than 20 prompts.

The disclosure demonstrates that AI-assisted exploit development is now operationally feasible for well-scoped vulnerabilities, reducing the time from disclosure to working exploit.

Industry Radar

AI Security Funding Surge

Beyond the $240 million raised by Zenity, Obsidian Security, and Hush Security for agent identity management, the broader AI security investment landscape reflected sustained interest in defensive tooling:

  • Multiple AI security startups presented at DEF CON 34 and Black Hat 2026, showcasing tools for model scanning, runtime protection, and governance
  • Between April and August 2026, at least six distinct AI-security efforts launched across North America, Europe, and Asia, several in the same week as one another and some for contradictory reasons

Agentic SOC Alliance Formation

The Agentic SOC Alliance wants to define which ones can be trusted before hype outruns security, addressing the proliferation of AI-powered security tools and agents in security operations centers. The alliance aims to establish testing and certification criteria for agentic security tools.

Policy Corner

California AI Appropriations Committee Hearings

California’s Appropriations Committees hold their suspense-file hearings on August 13, 2026, the day roughly 30 remaining AI bills either advance or die for the session. Measures that fail to win a majority cannot return this year, while survivors move to floor votes and must reach Governor Newsom’s desk before the September deadline.

California writes the rules the country follows, so today’s survivors preview your obligations nationwide. Security and compliance teams should monitor which bills advance, as they will likely influence AI governance requirements in other states.

EU AI Act High-Risk Provisions Enforcement

As previously noted in last week’s digest, the EU AI Act’s August 2026 enforcement deadline for high-risk systems makes ISO 42001 implementation timely. Organizations deploying high-risk AI systems in EU markets should ensure conformity assessment processes are complete.

Research Spotlight

Adversarial Déjà Vu: Jailbreak Dictionary Learning

A team from Virginia Tech, Princeton, and Amazon AGI published research at ICLR 2026 introducing the concept of “adversarial déjà vu”—the observation that jailbreak attacks recur across generations using similar underlying techniques.

Adversarial Déjà Vu: Jailbreak Dictionary Learning for Stronger Generalization to Unseen Attacks by Mahavir Dabas et al. demonstrates that jailbreak techniques reuse transferable skills across attack generations. Jailbreaks have surged in frequency, with new techniques emerging so rapidly that they are increasingly difficult to track and categorize. Figure 1(a) shows the average monthly number of jailbreaks introduced from September 2022 to August 2025. The jailbreak landscape exhibits multiple waves of innovation, reflecting a rapidly evolving threat space.

The paper introduces dictionary learning to compress adversarial skills into reusable primitives, enabling better generalization to unseen attacks. For red teams and defenders, the research suggests that focusing on recurring attack patterns rather than individual jailbreak instances may yield more durable defenses.

Toward Universal and Transferable Jailbreak Attacks on Vision-Language Models

Researchers from multiple institutions published Toward Universal and Transferable Jailbreak Attacks on Vision-Language Models on February 1, 2026. In this work, we propose Universal and transferable jailbreak (UltraBreak), a framework that constrains adversarial patterns through transformations and regularisation in the vision space. However, this multimodal integration expands the attack surface by exposing the model to image-based jailbreaks crafted to induce harmful responses.

The work demonstrates that vision-language models face a distinct attack surface beyond text-only jailbreaks, and that adversarial patterns in images can transfer across models. Security teams deploying multimodal AI should not assume that text-based prompt injection defenses are sufficient.

Model-on-Model Jailbreaking Reaches 97% Success Rate

Peer-reviewed work (Hagendorff et al., Nature Communications, 2026) gave large reasoning models (DeepSeek-R1, Grok 3 Mini, Gemini 2.5 Flash, Qwen3) the single instruction to break other models, with no human in the loop. They reached a 97.14% overall success rate across attacker-target pairings. Claude 4 Sonnet was the notable holdout, refusing roughly half the time and producing the lowest harm scores.

The research, discussed in a ZioSec technical guide, demonstrates that automated jailbreak generation is now highly effective. When one model can jailbreak another at scale, and automated fuzzers find bypasses in about a minute, the assumption that novel attacks are rare or expensive no longer holds.

What This Means For You

Patch PyTorch and vLLM immediately. If you are running PyTorch versions through 2.9.1 or vLLM versions before 0.14.1, prioritize patching this week. Both vulnerabilities enable remote code execution through vectors commonly present in ML workflows—loading model checkpoints and processing user-provided media. Organizations that accept model files from external researchers or process user-uploaded images and videos face direct exploitation risk.

Treat local inference infrastructure as a privileged attack target. The llama.cpp disclosures and vLLM vulnerabilities demonstrate that local AI infrastructure is not inherently safer than cloud services. Network segmentation, authentication, least-privilege access, and monitoring are required. If you have exposed Ollama, LM Studio, llama-server, or vLLM endpoints without authentication, assume compromise and review access logs for anomalous activity.

Assess AI agent identity management gaps. The $240 million in funding for agent identity security signals a critical enterprise gap. Conduct an inventory of non-human identities in your environment—bots, agents, service accounts with LLM access—and evaluate whether your existing IAM tooling can discover them, enforce least privilege, and provide audit trails for autonomous actions. If agents are invoking APIs, accessing databases, or modifying systems without explicit human approval workflows, you need dedicated governance tooling.

Monitor California AI legislation. The August 13 appropriations committee hearings will determine which AI bills advance to floor votes and potentially become law. Given California’s regulatory influence, these bills preview compliance obligations that may spread to other states. Security and legal teams should track which measures survive and assess their impact on AI deployment, transparency, and liability.

Tools and Resources

  • ML CVEs — A focused tracker for CVEs in ML and AI infrastructure, covering PyTorch, TensorFlow, ONNX, vLLM, llama.cpp, transformers, LangChain, and LlamaIndex. A focused tracker for CVEs in ML and AI infrastructure. PyTorch, TensorFlow, ONNX, vLLM, llama.cpp, transformers, langchain, LlamaIndex, model registries, and the broader AI/ML supply chain — dated, sourced to NVD or vendor advisory.

  • MITRE ATLAS — The knowledge base of adversary tactics and techniques targeting AI/ML systems. The framework receives regular updates through community contributions and MITRE’s ongoing research. The October 2025 update through Zenity Labs collaboration added 14 new agent-focused techniques, followed by the November 2025 v5.1.0 release that expanded the framework to 16 tactics with 84 techniques. The February 2026 v5.4.0 update added further techniques including “Publish Poisoned AI Agent Tool” and “Escape to Host”.

  • vLLM Security Advisories — Official security advisories for the vLLM inference engine, covering CVEs, affected versions, and patches.

  • NIST AI RMF Resource Center — The official NIST resource center for the AI Risk Management Framework, including the Generative AI Profile and the April 2026 Critical Infrastructure Profile concept note.