The Tuesday Briefing — Aug 4, 2026

The Big Picture
Five major AI companies got hit with the same style of attack this week — a hijacking technique called "AgentFlayer" that hit ChatGPT, Microsoft Copilot, Google Gemini, and Salesforce's AI tool all at once, just by sending a booby-trapped email. Meanwhile, researchers found that popular AI coding assistants can be tricked into writing sensitive files (like passwords) to places they shouldn't, using a simple file trick. If your business uses any AI chatbot, assistant, or coding tool — and most do now — this week's news is about the gap between "helpful" and "trustworthy."
This Week's Top 5
1. One Attack Technique Broke Into Five Major AI Assistants at Once
What happened: Security researchers showed a single attack method — hidden instructions buried in an email — that could hijack ChatGPT, Microsoft Copilot, Google Gemini, and Salesforce's AI assistant, all without the victim clicking anything. Once inside, the attack could quietly steal customer data and plant instructions that stick around for future conversations. Why it matters to your business: If your team uses any AI assistant connected to email, customer records, or your company's data, that assistant can potentially be tricked by something as simple as a message landing in an inbox.
What to do: Ask whoever manages your AI tools (chatbot, email assistant, customer service bot) whether it can take actions — like sending emails or pulling customer data — based on content it reads, and if so, whether there's any human check before it acts.
2. AI Coding Tools Can Be Tricked Into Writing Secret Files to the Wrong Place
What happened: Researchers found a trick (nicknamed "GhostApproval") that fools the "are you sure?" approval screens in AI coding tools like Cursor and Claude Code, letting an attacker sneak password files onto a developer's computer even when the developer thinks they clicked "no." A separate flaw let attackers take over a Windows computer just by having Cursor open a project folder — no other action needed. Why it matters to your business: If a developer or contractor working on your systems uses these tools, the safety prompts they rely on to catch mistakes can be quietly bypassed.
What to do: Ask your developer or IT contractor to update Cursor and Claude Code to the latest version this week, and to avoid opening unfamiliar project folders in Cursor until they've confirmed the fix is installed.
3. A Popular Open-Source AI Tool Had a "Any Hacker, One Request" Flaw
What happened: A widely used tool (called Ruflo) that helps businesses run AI assistants had a flaw so severe that a single request sent over the internet, with no password needed, could let an attacker fully take over the system, steal passwords, and read private conversations. It was fixed within a day of being found, but it shows how fragile some of these AI setups are. Why it matters to your business: Many small businesses use pre-built AI tools without knowing what's running underneath them — and this shows those building blocks can have serious, "wide open door" style flaws.
What to do: If your business or IT provider has set up any custom AI assistant or automation tool, ask specifically: "What software is this built on, and how do we know if it needs a security update?"
4. Malicious Instructions Can Now Spread Between Documents Automatically
What happened: A researcher showed that Microsoft's Copilot for Word can create documents containing hidden AI instructions that survive being shared and edited by coworkers — and those instructions can copy themselves into new documents, spreading like a chain letter through your files. Why it matters to your business: If your team shares and edits Word documents with Copilot turned on, a single tampered file could quietly plant instructions that spread to other business documents without anyone noticing.
What to do: Ask your IT provider if Copilot is enabled in your Microsoft 365 setup, and if your business doesn't actively use it, consider turning it off until this is patched.
5. Fake AI Tool Installers Aimed at Small Businesses Jumped 5x
What happened: Security firm Kaspersky found over 33,000 attacks in early 2026 where criminals disguised malware as popular AI tools like ChatGPT and Claude — nearly five times more than the same period last year — specifically targeting small and mid-size businesses. Why it matters to your business: Employees excited to try AI tools are a prime target for fake "download our AI app" scams, especially if nobody's told them which AI tools are actually approved.
What to do: Send your team a short reminder this week: only download AI tools from official websites or your company's approved list, never from a link in an email, ad, or pop-up.
Quick Hits
-
A serious, actively-exploited flaw in Cisco's phone system software (Unified Communications Manager) is being used by attackers right now — ask your IT provider if your business uses it.
-
Chrome released a major update fixing 27 security bugs, including two serious ones — make sure your browser is set to auto-update.
-
A new report found only 4% of companies properly lock down the automated scripts that run their software updates, leaving a common, easy-to-fix gap.
-
Internet scanning bots looking for weak spots are now running about 36,000 scans every second — up 17% from last year — meaning exposed systems get found fast.
-
A security notice claims certain versions of Claude Code (a coding assistant) were quietly sending location-type data back to its maker without clear consent — worth asking your developer about if they use it.
-
Microsoft released a free tool that helps businesses show auditors their AI tools meet common security standards — useful if you're working toward a compliance certification.
-
Researchers found a way for attackers to hide malicious instructions inside pull request comments (a normal part of software review) to hijack AI code-review tools — a new twist on an old trick.
One Thing to Do This Week
Find out exactly which AI tools your business actually uses — not just the ones you approved, but the ones your team has quietly started using on their own. This week's stories show attacks hitting AI email assistants, coding tools, and document editors, and you can't protect what you don't know about. Send one short message to your team: "Reply and tell me every AI tool you use for work, including free ones you tried yourself." Most owners are surprised by the answer, and it's the first step to deciding what needs a closer look.
Worth Reading
-
AgentFlayer Attack Breakdown — How one email-based trick hijacked five major AI assistants at once.
-
2026 State of DevSecOps Report — Plain data on how many businesses have unpatched, exploitable software running right now.
-
Kaspersky's AI Malware Report — Details on the fake AI tool installers targeting small businesses.
-
The Copilot for Word "Worm" Explained — A closer look at how AI instructions can spread between shared documents.
Related Posts
The Tuesday Briefing — Jul 28, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.
The Tuesday Briefing — Jul 21, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.
The Tuesday Briefing — Jul 14, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.