> daily_signal(2026_08_12)

One analyst took over any Zoom call with under 20 AI prompts. The same week, researchers pulled passwords from a chatbot, a studio swapped its writer for ChatGPT, and an AI built a superbug killer.

PickBits Daily Signal · Wednesday, August 12, 2026

By Mark Pickering · 8 min read · August 12, 2026

// tl;dr

The Zoom story is the one that got me today. One person, fewer than twenty prompts on public AI models, a full takeover of the app half of us sit in all day, built in under a day. We said back in the spring that AI had crossed from writing code to finding and chaining the holes on its own, and this is that bill coming due. Two of the other three stories are the same move pointed somewhere else: the "private" reasoning three big labs sell you handed back out with real passwords in it, and a game studio quietly trading its writer for ChatGPT and telling no one. The last one breaks the pattern, and it is the good one. Someone pointed the same tools at a superbug our antibiotics gave up on, and they worked.

Today: A Security turned public AI models into a zero-click Zoom exploit in under a day, Alexander Panfilov's team pulled 62 API keys and 33 passwords out of ChatGPT, Claude and Gemini's "encrypted" reasoning, a former Saber Interactive lead writer said ChatGPT replaced her with no Steam disclosure, and Stanford's Evo models designed 16 phages that kill drug-resistant E. coli.

1. One analyst, fewer than 20 AI prompts, and a zero-click takeover of every Zoom call. Zoom has already shipped the fix.

The meeting software your whole company lives on can be taken over with no click, and the fix only helps the machines that install it.

A security firm called A Security pointed publicly available AI models at Zoom and, in its own words, used fewer than 20 prompts and under 24 hours to build a working zero-click remote-code-execution chain. Two of the flaws carry the weight: CVE-2026-53413, a buffer overflow, and CVE-2026-53415, a use-after-free, both in Zoom's screen-annotation feature. An attacker who joins or hosts a meeting can run code on every participant's machine with no click required, which means stealing data or switching on a camera and microphone. Zoom shipped fixes in client 7.1.5 and 7.0.6 and VDI client 7.0.11 and 6.6.15; every version behind those stays exploitable until it is updated.

The reason this leads is not the annotation bug. It is A Security's own framing: this class of capability, it says, "would previously have only been available to nation-state threat actors." One analyst with off-the-shelf models did in a day what used to take a specialized team months. That line is the whole story, and it has nothing to do with Zoom in particular. It is true of every piece of software you run.

Screenshot of CSO Online's August 11, 2026 report on Zoom's zero-click annotation flaws
csoonline.com · August 11, 2026
Why this matters: The bug is patched; the point is not the bug. A Security's own line is that this class of work used to belong to nation-state teams, and one analyst with public models did it in a day. That is not going back. The exploit was never the expensive part anymore. The gap between a fix shipping and a fix installed is, and that gap is now the whole attack surface. Action this week: Push the Zoom client to 7.1.5 or 7.0.6, and VDI to 7.0.11 or 6.6.15, across every managed endpoint, then turn on forced auto-update so the laggards can't sit there unpatched. Restrict who can annotate or host in sensitive meetings until you have confirmed everyone is current, because the flaw lives in screen annotation. The question I keep coming back to, watching this arc since the spring when we covered AI shifting from a coding assistant into an autonomous flaw-chaining agent, is a plain one about time: how many days does it take you to force an update across the fleet, and is that number written down anywhere. Get it answered before the next one lands.

csoonline.com: Zoom zero-click RCE flaws allow attackers to compromise meeting participants (August 11, 2026)
thehackernews.com: Zoom annotation flaws could let meeting participants run code on each other (August 2026)
securityweek.com: Zoom patches zero-click code execution vulnerability (August 2026)

2. Researchers pulled 62 API keys and 33 passwords out of the "encrypted" reasoning ChatGPT, Claude and Gemini hide from you.

The "private" thinking inside ChatGPT, Claude and Gemini isn't private, and researchers pulled 62 API keys and 33 passwords back out of it.

OpenAI, Anthropic and Google all wrap their reasoning models' step-by-step thinking in "encrypted" blocks, sold as a way to protect intellectual property. A team led by Alexander Panfilov, working with MATS Research, the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems, showed the encryption is mostly theater. The reasoning blocks are fully portable across sessions, users and models within a single provider, and a smaller model can be jailbroken to transcribe a larger one's hidden thoughts. To show the stakes, they scanned roughly 7,000 publicly shared agent traces and reconstructed the reasoning inside them, surfacing 62 live API keys, 33 passwords and other secrets, alongside oddities like self-referential "scheming" language and a stray buttermilk-marinade recipe.

The blunt takeaway for anyone who uses these tools: anything you or your agents put into a reasoning model can be pulled back out of the "private" thinking, and every published agent log is now a place those secrets can surface. This is not one vendor's bug. It reproduces across OpenAI's o-series, Anthropic's Claude and Google's Gemini, which makes it a design choice all three made. The paper is arXiv:2608.09867; the group documents it at stolen-thoughts.com.

Screenshot of The Decoder's August 11, 2026 story on leaked passwords in AI reasoning
the-decoder.com · August 11, 2026
Why this matters: We saw a version of this before, when shared Claude conversations carrying sensitive data started turning up in ordinary Google searches. This is the same lesson one layer deeper: the "encrypted" reasoning is a lockbox with a copy of the key printed on the side. It replays across sessions and users, a smaller model can transcribe a bigger one's hidden thoughts, and the researchers pulled real credentials out of 7,000 public logs to prove it. The step nobody at the three vendors has taken is the simple one: telling you plainly that "encrypted" here does not mean private. Action this week: Rotate any API key or password that has already gone through an agent session, and stop pasting live secrets into a prompt, because there is no delete button for a reasoning trace someone else can replay. Scrub chain-of-thought and trajectory logs before you publish a dataset or share a trace export. My own read is that "private" quietly stopped meaning private a while ago, and the only thing you can really do is assume the box leaks and act like it. Track the paper, arXiv:2608.09867, for the vendor responses, because this is a design flaw, not a one-vendor patch.

the-decoder.com: "But marinade" and leaked passwords are what researchers found in ChatGPT's hidden reasoning (August 11, 2026)
arxiv.org: Replayable encrypted reasoning across OpenAI, Anthropic and Google models (arXiv:2608.09867, August 2026)
blog.cryptographyengineering.com: Fooling around with encrypted reasoning blobs (May 2026)

3. A game's former lead writer says ChatGPT replaced her mid-project. Its Steam page says nothing about AI at all.

A studio swapped its lead writer for ChatGPT over her manager's objection, and the people buying the game were never told.

Stella Sacco, the former lead writer on Saber Interactive's driving game Rideshare Stimulator, said on Bluesky that she was replaced by ChatGPT partway through development, and that the in-game passenger voices are AI too. By her account her own manager argued against the swap, but executives above him pushed it through, reasoning that "gamers love new tech" and that it would make "great marketing." Saber denies it, saying no writer was replaced by AI "for Rideshare or any other game," while confirming that it does use AI to generate passenger dialog "as the number of passengers in the game is infinite."

The accountability hook sits in a third fact both sides skip past: the game's Steam page carries no generative-AI disclosure, even though Valve requires developers to disclose AI content that ships in a game. Whether or not a single writer was formally "replaced," a substitution made over a manager's objection and shipped to players without the disclosure the storefront's own rules demand is a clean test of who decides and who gets told.

Screenshot of PC Gamer's August 11, 2026 report on Saber Interactive and ChatGPT
pcgamer.com · August 11, 2026
Why this matters: The question here is not whether ChatGPT can write a passenger's throwaway line. It is who decided, and who got told. By Sacco's account the call was made over her manager's objection by executives who liked the marketing angle, and the game shipped with a Steam page that says nothing about AI, even though Valve's own rules require the disclosure. Whether or not one writer was formally "replaced," a swap made above a manager and hidden from buyers is a failure no amount of "but the AI is good" can fix. I keep coming back to this on these stories. It was never about whether the tool is good enough. It is about who got a say. Action this week: Check the AI-disclosure field on a game's Steam page before you buy, and report an undisclosed one to Valve, because the rule only bites when players actually file. If you run a creative team, write down now where your line sits on disclosing AI in shipped work, so it is a policy and not a hallway argument after the fact. I will be watching one thing: whether Valve makes Saber update that page, which would confirm that the omission, not the swap, is the enforceable part.

pcgamer.com: Saber Interactive denies replacing a writer with ChatGPT on its new driving game, but says it will use AI (August 11, 2026)
gamesradar.com: Saber Interactive replaced me with ChatGPT midway through development, claims former lead writer (August 11, 2026)
thegamer.com: Rideshare Stimulator replaced its lead writer with ChatGPT, no Steam AI disclosure (August 11, 2026)

4. Stanford's AI designed 16 working viruses from scratch that kill a drug-resistant superbug.

AI just designed a virus that kills a superbug our antibiotics gave up on.

In a study published in Science on August 6, Stanford's Brian Hie and bioengineering graduate student Samuel King used the genome language models Evo 1 and Evo 2, which predict the next nucleotide instead of the next word, to design bacteriophage genomes from scratch, seeded from the natural phage ΦX174. Of nearly 300 synthesized candidates, 16 proved viable against antibiotic-resistant E. coli, and some were fitter than the natural phage. As a cocktail, the 16 AI-designed phages "rapidly overcome resistance in E. coli that is immune to native ΦX174."

That last part is the point. Bacteria out-evolve any single phage eventually, so a genetically diverse, machine-designed cocktail is a plausible new weapon against antimicrobial resistance, a slow crisis almost nobody has been paying to solve. It is also why this closes the edition rather than leads it: the same capability raises real biosecurity questions. The researchers kept human-infecting viruses out of the training data, and Hie released Evo 2 as open-source on the argument that naturally occurring pathogens still pose the greater risk. Phage therapy remains experimental and unapproved, but AI just opened up options for it that nature never explored.

Screenshot of Medical Xpress's August 6, 2026 report on Stanford's AI-designed phages
medicalxpress.com · August 6, 2026
Why this matters: For anyone who has watched a routine infection turn untreatable, this one actually matters. Bacteria out-evolve any single phage, which is why phage therapy has always been fragile; a machine that can design a diverse cocktail of them from scratch changes what is possible, and the Stanford cocktail already broke resistance that had beaten the natural virus. Keep it in proportion, though: this is running in a lab dish, not announced as a product and not funded into a trial. Action this week: Watch AI-designed phage cocktails as an emerging countermeasure, but treat phage therapy as still experimental and unapproved, because the distance between 16 viruses in a dish and a treatment a doctor can prescribe is still long. Follow the Arc Institute's Evo 2 releases to see whether this tooling reaches academic and public-health labs and not just well-funded pharma. My own read is that the biosecurity worry is real and the researchers took it seriously by keeping human-infecting viruses out of the training data, and that open-sourcing the model is the harder call, one I would rather see argued in the open than settled quietly.

medicalxpress.com: AI designs viruses that kill antibiotic-resistant E. coli (August 6, 2026)
eurekalert.org: Stanford and Arc Institute scientists use AI to design bacteriophages against E. coli (August 2026)
implicator.ai: Stanford and Arc Institute build 16 AI-designed viruses that kill E. coli (August 2026)

» What to watch this week

Tomorrow's signal lands here.