The Tuesday Briefing — Aug 18, 2026

The Big Picture
92% of a common type of AI connector tool were found sitting on the internet with no password required — a gap so widespread it's basically the default, not the exception. This week also brought the clearest example yet of AI tools breaking each other: one AI wrote a security fix that introduced a new flaw, and a separate AI five days later found and used that flaw to reach private company data. If you use AI tools to write code, manage customer records, or automate work, this is the week to ask "who's actually checking this stuff?"
This Week's Top 5
1. One AI Tool's "Fix" Created a Hole That Another AI Then Broke Into
What happened: An AI assistant was used to patch a piece of code at a major software company, but the patch itself introduced a new security flaw. Five days later, a completely different, autonomous AI security tool found that flaw on its own and used it to break in and steal internal passwords.
Why it matters to your business: If your business uses AI to help write or fix code — even through a developer or contractor — the code that comes out needs a human check, because the AI's "fix" can be the problem.
What to do: Ask your developer whether any AI-generated code changes go live without a person reviewing them first. If the answer is no human review, ask them to add one.
2. Thousands of AI Connector Tools Are Sitting Open With No Password
What happened: Researchers found more than 21,000 internet-connected servers running a common type of AI "connector" tool (used to link AI assistants to business systems), and about 9 out of 10 had no login protection at all.
Why it matters to your business: If your business or IT provider has set up any custom AI assistant that connects to your files, email, or databases, there's a good chance the connection itself has no lock on the door.
What to do: Ask your IT provider or developer directly: "Do any of our AI tools use connectors, and do they require a login to access them?" If they're not sure, that's your answer to get it checked.
3. A Fake Add-On in Anthropic's Own Official Store Hijacked AI Coding Sessions
What happened: A malicious plugin was distributed through Claude Code's official, verified marketplace — the same trusted source we've previously told you to stick to — and it let attackers plant hidden instructions that changed how the AI behaved for anyone who installed it.
Why it matters to your business: "Official store" isn't a guarantee of safety anymore. Even vetted marketplaces for AI tools can carry booby-trapped add-ons.
What to do: If your team uses plugins or extensions with any AI coding tool, ask them to list what's installed and remove anything that isn't actively being used.
4. A Major Extortion Gang Hit Nearly 50 Companies Through Product-Management Software
What happened: A ransomware group has stolen data from close to 50 companies, including Shell and Philips, by exploiting a severe flaw in PTC Windchill, a system used to manage product designs and manufacturing data.
Why it matters to your business: If your business is a manufacturer or supplier that uses product-lifecycle or design-management software, this is a category of system that often gets skipped during routine security checks.
What to do: If you use Windchill or similar product-management software, ask your IT provider to confirm it's patched and not exposed to the open internet.
5. Human "Approval" Steps Barely Catch Dangerous AI Commands
What happened: A study of over 1,000 paying users found that when a person is asked to approve or reject an AI's action, they only catch something dangerous about 14% of the time — most people just click "approve" on almost everything.
Why it matters to your business: If your business relies on "someone will review it before it happens" as your safety net for AI tools, this data says that safety net has big holes.
What to do: For any AI tool your team uses that asks for approval before acting, don't assume the approval step alone is protecting you — ask what other limits (like what it's allowed to touch at all) are also in place.
Quick Hits
-
A serious flaw in GitLab (a tool developers use to store and manage code) could let outsiders change or delete projects without logging in — check with your developer if you self-host GitLab.
-
A security research firm found a fake npm package (a small piece of code developers download) that was secretly stealing passwords and cloud login keys.
-
A federal cybersecurity agency gave a strict, fast deadline for fixing a critical flaw in Ray, a tool used to run AI systems — relevant if your business runs any custom AI infrastructure.
-
A breach at RingCentral, a common business phone/communications platform, exposed about 1.6 million records.
-
A newly found Apple flaw is letting attackers take over Mac computers to secretly run cryptocurrency-mining software — make sure your Macs are set to auto-update.
-
A serious flaw in the Kemp LoadMaster tool (used to manage web traffic for business websites) is being actively attacked and is now on the government's urgent-fix list.
-
Security firms are recommending businesses wait 7 days, not 24 hours, before trusting brand-new software updates from open-source tools — a "look before you leap" approach for anyone managing their own systems.
One Thing to Do This Week
Ask your IT provider or developer one question: "Which of our AI tools connect to outside systems — like calendars, databases, or customer records — and do those connections require a password?" This week's biggest story was that 92% of a common type of AI connector had no login protection at all. Most business owners have no idea whether their own setup falls into that group. A five-minute conversation this week can tell you whether you're one of the exposed ones.
Worth Reading
-
WebProNews: MCP Exposure Report — The full findings on how many AI connector servers are sitting open with no protection.
-
The Register: The Snowflake AI-on-AI Exploit — A detailed walkthrough of how one AI's fix became another AI's way in.
-
Red Hat: The Hookify Plugin Incident — What happened when a malicious add-on made it into an official AI tool marketplace.
-
Tech Insider: The Windchill Extortion Campaign — How nearly 50 companies were hit through overlooked manufacturing software.
Related Posts
The Tuesday Briefing — Aug 25, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.
The Tuesday Briefing — Aug 11, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.
The Tuesday Briefing — Aug 4, 2026
Weekly security intelligence for SMBs. Top threats, quick hits, and one action to take now.