The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
How Agent Prompts Became A New Malware Path
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Tuesday, August 18, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw. There is no evidence that the technique has spread successfully in the wild, and a one-paragraph warning added to an agent's system prompt reduced spread to near zero across the payloads tested. Fifteen generations of adversarial optimization run against that warning on Claude models still failed to bypass it reliably. That's the headline from The Hacker News, and it is a concrete demonstration that the same persistence mechanisms that make agents useful also create a new propagation vector that defenders have not yet instrumented. [pause 1.2] A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, named the City Forum campaign, traces back to one server at 158.220.87.79 hosted on a commodity VPS through the German provider Contabo. Every request from that server carries the same fingerprint, the default user agent of Go's net/http library. Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since. Targets span telecoms, banks, financial services, enterprise software vendors, and public sector portals. That's the headline from The Hacker News, and it underscores how long a determined actor can operate against high-value SaaS platforms before anyone notices the steady drip of data. [pause 1.2] The U.S. Cybersecurity and Infrastructure Security Agency on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale AI and machine learning workloads, with more than 43,500 stars on GitHub. The vulnerability, CVE-2025-62593 with a CVSS score of 9.4, can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding attack. The Ray Development team's longstanding decision to not implement any sort of authentication on critical endpoints like /api/jobs has once again led to a severe vulnerability. That's the headline from The Hacker News, and it is another reminder that AI infrastructure projects continue to ship with the same "lab network" assumptions that break the moment the service faces the public internet. [pause 1.2] GitLab has released security updates to address a critical vulnerability impacting its Community and Enterprise Editions that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical with a CVSS score of 9.4. Released on August 17 outside the company's usual twice-monthly schedule, the patch arrived five days after a routine release that carried no critical issues. Only self-managed installations need to act. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab.com and GitLab Dedicated are already running the patched version. That's the headline from The Hacker News, and it shows how even mature DevOps platforms can carry unauthenticated mutation paths when GraphQL resolvers are not locked down as tightly as the REST surface. [pause 1.2] SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16. The exposed records did not include wallet credentials or financial information, and the company said it has found no evidence that the incident compromised access to SafePal wallets or funds. Under certain conditions, the flaw allowed unauthorized access to another customer's order information. That's the headline from The Hacker News, and it is the predictable result when an order-management plugin is granted broader authorization scope than the core wallet product itself. [pause 1.0] Five stories, one consistent pattern. Agent persistence layers, long-running SaaS scrapers, unauthenticated AI frameworks, DevOps mutation flaws, and supply-chain plugins are all being discovered the hard way. The gap between "it works in the lab" and "it is reachable from the internet" remains the most expensive assumption in the stack. [pause 0.8] That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.
Tuesday Security Briefing Setup
SPEAKER_00Here's your briefing for Tuesday, August 18th, 2026. Five stories that show how quickly yesterday's assumptions become today's attack surface.
AI Agents And Self-Propagating Prompts
SPEAKER_00Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work released as a preprint on August 10th tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw. There is no evidence that the technique has spread successfully in the wild, and a one-paragraph warring added to an agent system prompt reduced spread to near zero across the payloads tested. Fifteen generations of adversarial optimization run against that warning on clawed models still failed to bypass it reliably. That's the headline from the Hacker News, and it is a concrete demonstration that the same persistence mechanisms that make agents useful also create a new propagation vector that defenders have not yet instrumented.
City Forum Scrapes Salesforce ServiceNow
SPEAKER_00A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year. According to research published this week by Agent Security Platform Rico, the activity named the City Forum campaign traces back to one server at 158779 hosted on a commodity VPS through the German provider Cantabo. Every request from that server carries the same fingerprint, the default user agent of Go's net slash HTTP library. Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since. Targets span telecoms, banks, financial services, enterprise software vendors, and public sector portals. That's the headline from the Hacker News. And it underscores how long a determined actor can operate against high-value SaaS platforms before anyone notices the steady drip of
Ray Flaw Added To KEV
SPEAKER_00data. The U.S. Cybersecurity and Infrastructure Security Agency on Monday added a critical flaw impacting RAID to its known exploited vulnerabilities catalog, citing evidence of active exploitation. RAI is an open source Python native distributed computing framework designed to scale AI and machine learning workloads with more than 43,500 stars on GitHub. The Vulnerability CVE 2025-62593 with a CVSS score of 9.4 can result in remote code execution via web browsers like Mozilla, Firefox, and Apple Safari by means of a DNS rebinding attack. The RAID development team's long-standing decision to not implement any sort of authentication on critical endpoints like API jobs has once again led to a severe vulnerability. That's the headline from the Hacker News, and it is another reminder that AI infrastructure projects continue to ship with the same lab network assumptions that break the moment the service faces the public internet.
GitLab Critical Unauthenticated Project Changes
SPEAKER_00GitLab has released security updates to address a critical vulnerability impacting its community and enterprise editions that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE 2026-1009478, has been rated critical with a CVSS score of 9.4 shall release on August 17 outside the company's usual twice-monthly schedule. The patch arrived five days after a routine release that carried no critical issues. Only self-managed installations need to act. The fixes are available in GitLab 19.24, 19.1.6, 19.08, and 18.11.11. GitLab.com and GitLab Dedicated are already running the patched version. That's the headline from the Hacker News, and it shows how even mature DevOps platforms can carry unauthenticated mutation paths when GraphQL resolvers are not locked down as tightly as the REST
SafePal Order Plugin Data Exposure
SPEAKER_00surface. SafePal has disclosed that an authorization flaw in an order tracking plugin exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16th. The exposed records did not include wallet credentials or financial information, and the company said it has found no evidence that the incident compromised access to SafePal wallets or funds. Under certain conditions, the flaw allowed unauthorized access to another customer's order information. That's the headline from the Hacker News, and it is the predictable result when an order management plugin is granted broader authorization scope than the core wallet product itself.
One Pattern And The Closing Warning
SPEAKER_00Five stories, one consistent pattern. Agent persistence layers, long running SAS scrapers, unauthenticated AI frameworks, DevOps mutation flaws, and supply chain plugins are all being discovered the hard way. The gap between it works in the lab and it is reachable from the internet remains the most expensive assumption in the stack. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.