A timing side channel in global KV-cache sharing lets unprivileged tenants reconstruct other users' prompts, PII, and system instructions from vLLM, SGLang, and similar inference frameworks. Multiple CVEs have been assigned; patches are in progress.
A timing side channel in global KV-cache sharing lets unprivileged tenants reconstruct other users' prompts, PII, and system instructions from vLLM, SGLang, and similar inference frameworks. Multiple CVEs have been assigned; patches are in progress.
Researchers found that encrypted chain-of-thought blocks returned by OpenAI, Anthropic, and Google's reasoning APIs used a shared global key, letting weaker models decode stronger models' hidden reasoning and exposing 704 real privacy artifacts in published developer logs.
Novee Security disclosed CVE-2026-54316 at Black Hat USA 2026: a zero-privilege GitHub issue can reach CI runner secrets across Claude Code, Gemini CLI, and OpenAI Codex. The Claude Code variant eventually exfiltrated secrets one character at a time via Hugging Face download counters. A separate Gemini CLI flaw scored CVSS 10.0.
ESET discovered PromptSpy in February 2026 — the first known Android malware to query a live generative AI API at runtime. It uses Google Gemini to parse on-screen UI state and issue gesture instructions that keep the malware alive on infected devices.
Anthropic has deployed machine-readable watermarks in all Claude outputs globally as of August 2, 2026, implementing two marking methods to satisfy EU AI Act Article 50(2) transparency requirements — right as the enforcement window opens.