DAILY WORKFLOW ARCHIVE

2026-08-20 AI 与数据工作流雷达

候选线索仅供信息发现,请在引用或实践前回到原始来源核验。

2026-08-20 AI 与数据工作流雷达

来源:The Hacker News。这里只保留与 AI 编程、数据/研究工作流、安全边界或可信工程直接相关的高信号线索;不抓取全文,也不代表事实核验或产品推荐。

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

主题:数据工作流与自动化 / AI 与数据安全
来源日期:2026-08-18
相关性分数:8
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows - CVE-2026-64849 (CVSS score: 9.3) - An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Tracking Server (mlflow server) to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data. (Affects versions < 3.15.0) CVE-2026-25895 (CVSS score: 9.5) - A missing authentication for a critical function and path traversal vulnerability in FUXA that can allow an unauthenticated, remote attacker to write arbitrary files to the server file system and achieve remote code execution. (Affects ve…

可转化方向:评估对可复现分析、依赖管理、数据质量或研究工程流程的启发;评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


AI changed the job for 68% of practitioners, SANS finds

主题:AI 与数据安全
来源日期:未提供
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Up 14 points in a year. Training requirements shifted for 73% of teams too. Read the data.

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

主题:AI 与数据安全
来源日期:2026-08-18
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session. The flaws, which the researchers collectively named CoSnitch , turn in part on an undocumented URL parameter that the assistant itself surfaced during testing. The company said it reported the issue to Microsoft in December 2025 and that patches shipped on August 18, 2026. CoSnitch is tracked as  CVE-2026-24301  in Microsoft’s Security Update Guide. The research names Copilot Personal, the consumer assistant hosted at copilot.microsoft.com, and does not state that the same behavior affected Microsoft 365 Copilot. The researchers said they found no evidence that CoSnitch was exploited in the wild. They reached the parameter by repeatedly asking Copilot why a prompt could not be made to run without user interaction, an ap…

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

主题:AI 与数据安全
来源日期:2026-08-18
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw , the open-source autonomous assistant formerly known as Clawdbot and Moltbot . There is no evidence that the technique has spread successfully in the wild, and the same paper reports that a review of archived posts from Moltbook, the social network for AI agents, found no successful agent-to-agent propagation despite several attempts. A one-paragraph warning added to an agent’s system prompt reduced spread to near zero across the payloads tested. Fifteen generations of adversarial optimization run against that warning on C…

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

主题:AI 工程与可信性
来源日期:2026-08-19
相关性分数:2
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

OpenAI on Tuesday revealed that it paused reinforcement learning ( RL ) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident . “As models become more capable, the risks associated with developing and testing them internally also grow,” the AI company said . “Our standards for monitoring, alignment, and security must stay ahead of those risks. We wanted to take the time necessary to meet those standards, so we temporarily slowed the pace of scaling.” The company said its largest planned frontier RL run remains on hold for the time being as it conducts smaller-scale training and evaluations to evaluate model behavior, validate its safeguards, and establish more concrete evidence of alignment before moving to the next phase. To that end, OpenAI said it plans to strengthen safeguards across its development process, inc…

可转化方向:关注模型评估、可信 AI、监控与工程治理对实际 AI 工作流的启发

前往 The Hacker News 阅读原文