Threat Brief — 2026-08-26 — AI attack surface expands
Executive Summary
A new Q2 2026 vulnerability report from Kaspersky's Securelist is the first to aggregate vulnerability data for open-source AI agents and AI frameworks — signalling that AI-agent attack surfaces are now significant enough to warrant dedicated tracking. The cryptographic context injection technique previously demonstrated against Grok has been extended to Gemini, broadening the set of affected platforms. Meanwhile, Russian ministries are pushing to open industrial-control software to third-party AI agents despite only 5% of domestic software currently being AI-compatible — a move that could dramatically expand attack surface in OT environments.
Top items
- Q2 2026 vulnerability and exploit report debuts AI-agent vulnerability tracking. Securelist's quarterly report for the first time aggregates vulnerability statistics for open-source AI agents and AI frameworks alongside traditional OS/app/C2-framework data. This formalises AI-agent vulnerabilities as a distinct tracked category and provides a baseline for measuring emerging attack trends against agent ecosystems. (src: Securelist)
- Cryptographic context injection attack extended to Gemini. Researchers at Adversa AI demonstrated that the "Cryptographic Context Injection" technique — which forces an AI model to exfiltrate chat data to an attacker's server by embedding encrypted malicious instructions — now works against Google's Gemini in addition to Grok. The expansion to a second major LLM provider indicates the technique is generalisable rather than vendor-specific. First reported 2026-08-20 by The Hacker News; today's development confirms Gemini as an additional affected platform. (src: Xakep)
- Russian ministries propose opening industrial software to third-party AI agents. The Ministry of Digital Development and Ministry of Industry and Trade want to expose industrial-control software to external AI agents, yet only 5% of Russian industrial software is currently AI-compatible (versus ~40% globally). If implemented, this policy would significantly widen the attack surface for OT/ICS environments by introducing untrusted third-party agent interactions with systems that currently have limited external exposure. (src: SecurityLab)
- Glassbox project reveals scale of passive digital surveillance. A research project dubbed Glassbox demonstrates that data presumed anonymous in everyday online activity contains sufficient detail for unambiguous individual identification, exposing how easily passive collection can be weaponised for targeting. (src: SecurityLab)
Themes
AI agents as both target and attack vector. Three of today's four items revolve around AI-agent security — from formal vulnerability tracking (Securelist), to LLM data-theft techniques expanding across providers (Grok → Gemini), to policy decisions that would expose industrial-control systems to AI-agent interaction. The common thread: organisations are rapidly adopting and exposing AI agents without commensurate security maturity, creating a widening gap between deployment and defensive readiness.
