The Matthew Chapman Podcast

AI Reasoning Traces Leaked via OpenAI, Anthropic & Google APIs

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 3:44

Here is your briefing for Wednesday, August 12, 2026. Researchers found that hidden reasoning traces passed between API calls at OpenAI, Anthropic, and Google can be replayed and decoded by weaker models in the same family. The attack recovers internal chain-of-thought, API keys, passwords, and even concealed harmful content from public agent trajectories. Across thousands of logged sessions they pulled hundreds of thousands of thinking blocks. Four abuse paths emerged: model distillation, cross-user data theft, bypassing safety filters, and injecting prompts inside opaque reasoning objects. That's the headline from The Hacker News, and it shows the current generation of agent tooling still treats reasoning as just another opaque payload instead of a security boundary. Two malicious LiteLLM packages sat on PyPI for roughly forty minutes in March and harvested cloud credentials, SSH keys, Kubernetes tokens, and database passwords from any system that installed them. CloudSEK recovered attacker loot mapping the exposure to more than two thousand organizations. The campaign appears linked to the earlier Trivy supply-chain compromise. That's the headline from The Hacker News, and it is another reminder that even short-lived malicious releases in the Python ecosystem can produce long-lived operational damage when the packages touch production AI tooling. Threat actors are actively exploiting a directory-traversal flaw in VMware vCenter (CVE-2026-59310, CVSS 9.8) that Broadcom patched last month. Observed activity includes path traversal followed by cron jobs that drop reverse SSH for persistence. The campaign started hitting systems within days of disclosure. That's the headline from The Hacker News, and it is the usual story: critical virtualization infrastructure with network exposure gets owned fast once a public exploit appears. Google announced that its Gemini app has reached one billion users, making it the fastest-growing product in company history. The milestone comes amid continued model releases and heavy marketing, though questions remain about whether growth can be sustained as newer models slow down and competition intensifies. That's the headline from TechCrunch and Ars Technica, and it is a concrete data point on how quickly consumer AI interfaces are moving from novelty to default behavior for a billion people. Adobe released updates for multiple maximum-severity vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The worst include operating-system command injection and eval injection that allow arbitrary code execution, plus authorization bypasses that can lead to denial-of-service or privilege escalation. Several carry CVSS scores of 10.0. That's the headline from The Hacker News, and it is the quarterly reminder that even mature enterprise platforms continue to ship command-injection and authorization holes that require emergency patching. Five stories, one through-line. The agent and API layers we are rushing into production still leak reasoning, secrets, and control when the abstractions are treated as trusted. Supply-chain attacks in AI-adjacent Python packages are producing measurable organizational exposure. Core virtualization platforms remain high-value targets that get compromised shortly after patches drop. Consumer adoption numbers are hitting billion-user scale while the underlying security model lags. And the usual critical enterprise software keeps shipping CVSS-10 holes that force fire-drill updates. The pattern is consistent. Speed and convenience keep winning over verification at the boundaries. The organizations that treat every new integration point as hostile will be the ones still standing when the next wave of these issues lands. That's the briefing. Stay sharp, patch your systems, and we'll see you tomorrow.

Support the show

Wednesday Security Briefing Start

SPEAKER_00

Here is your briefing for Wednesday, August 12, 2026.

API Reasoning Trace Replay Attack

SPEAKER_00

OpenAI, Anthropic, Google API Flaw. Let weaker AI models decode stronger models reasoning. Researchers found that hidden reason traces pass between API calls at OpenAI, Anthropic, and Google can be replayed and decoded by weaker models in the same family. The attack recovers internal chain of thought, API keys, passwords, and even concealed harmful content from public agent trajectories. Across thousands of log sessions, they pulled hundreds of thousands of thinking blocks. Four abuse paths emerged, model distillation, cross-user data theft, bypassing safety filters, and injecting prompts inside opaque reasoning objects. That's the headline from the Hacker News. And it shows the current generation of agent tooling still treats reasoning as just another opaque payload instead of a security

PyPI Malicious Package Credential Harvesting

SPEAKER_00

boundary. Malicious LITA LM releases tied to Trevi Hack may have exposed 2,100 plus organizations, two malicious Lyta LM packages sat on PyPI for roughly 40 minutes in March and harvested cloud credentials, SSH keys, Kubernetes tokens, and database passwords from any system that installed them. CloudSec recovered attacker loot, mapping the exposure to more than 2,000 organizations. The campaign appears linked to the earlier Trevi supply chain compromise. That's the headline from the Hacker News, and it is another reminder that even short-lived malicious releases in the Python ecosystem can produce long-lived operational damage when the packages touch production AI tooling.

VMware vCenter Exploitation For Persistence

SPEAKER_00

Attackers exploit VMware vCenter, vulnerability to gain persistent remote access. Threat actors are actively exploiting a directory traversal flaw in VMware VCenter. CVE 2026-59310, CVSS 9.8 that Broadcom patched last month. Observed activity includes Path Traversal, followed by cron jobs that drop reverse SSH for persistence. The campaign started hitting systems within days of disclosure. That's the headline from the Hacker News. And it is the usual story. Critical virtualization infrastructure with network exposure gets owned fast once a public exploit

Gemini Reaches One Billion Users

SPEAKER_00

appears. Google's Gemini app surges to 1 billion users. Google announced that its Gemini app has reached 1 billion users, making it the fastest growing product in company history. The milestone comes amid continued model releases and heavy marketing, though questions remain about whether growth can be sustained as newer models slow down and competition intensifies. That's the headline from TechCrunch and RS Technica. And it is a concrete data point on how quickly consumer AI interfaces are moving from novelty to default behavior for a billion

Adobe CVSS 10 Patch Emergency

SPEAKER_00

people. Adobe patches three C VSS 10boy Zero Cold Fusion and Campaign Classic flaws. Adobe released updates for multiple maximum severity vulnerabilities in Cold Fusion, Commerce, and Campaign Classic. The worst include operating system command injection and eval injection that allow arbitrary code execution, plus authorization bypasses that can lead to denial of service or privilege escalation. Several carry CVSS scores of 10 boys. That's the headline from the Hacker News. And it is the quarterly reminder that even mature enterprise platforms continue to ship command injection and authorization holes that require emergency patching.

One Through Line And Takeaways

SPEAKER_00

Five stories, one through line. The agent and API layers we are rushing into production still leak reasoning, secrets, and control when the abstractions are treated as trusted. Supply chain attacks in AI adjacent. Python packages are producing measurable organizational exposure. Core virtualization platforms remain high-value targets that get compromised shortly after patches drop. Consumer adoption numbers are hitting billion user scale while the underlying security model lags, and the usual critical enterprise software keeps shipping C VSS 10 holes that force fire drill updates. The pattern is consistent. Speed and convenience keep winning over verification at the boundaries. The organizations that treat every new integration point as hostile will be the ones still standing when the next wave of these issues lands. That's the briefing. Stay sharp, patch your systems, and we'll see you tomorrow.