> daily_signal(2026_08_15)

A crypto crew is taking over Macs through a password-free screen-sharing hole, Meta patented glasses that name the strangers around you, and Washington is building a border AI to score every import.

PickBits Daily Signal · Saturday, August 15, 2026

By Mark Pickering · 8 min read · August 15, 2026

// tl;dr

Three of today's four stories are AI getting used on people; the fourth is a guy who used it for something good. A criminal crew is quietly using a Mac screen-sharing hole to take machines over and mine crypto on them. Meta filed a patent for always-on face recognition in its glasses, a story we have watched build since July. The White House is building a border system to score every shipping container that comes into the country. And a guy in Sydney with no medical training used a chatbot to fight his dying dog's cancer, and bought her months. Most days here it's AI getting used on people, so it was good to end on someone who used it to save his dog.

A crypto crew is taking over Macs through screen sharing, Meta patented glasses that name the strangers around you, the White House is building a border AI to score every import container, and a chatbot helped shrink a dog's tumor.

1. Apple's screen-sharing bug hands a stranger root with no password, and miners are already through the door.

If a Mac in your home or your fleet has Screen Sharing switched on and reachable from the internet, a stranger could already be root on it, with no password and no account.

CVE-2026-65400 is a pre-authentication takeover of macOS's built-in Screen Sharing. A flaw in the Remote Framebuffer / VNC Secure Remote Password path inside the screensharingd service validates an unauthenticated connection as legitimate, so a remote attacker with no macOS account and no VNC password reaches root, the highest level of control on the machine. From there they can read or overwrite files, including ones protected by macOS's Transparency, Consent and Control privacy layer, the same walls that are supposed to keep apps out of your photos, messages, and disk.

The Netherlands National Cyber Security Centrum has already watched the flaw exploited in the wild: attackers gained root and installed Monero cryptocurrency miners on Macs that had TCP port 5900 reachable from the internet. Apple shipped the fixes on August 6, 2026, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The only Macs at risk are the ones still running Screen Sharing or Remote Management open to the outside, a smaller group than the headline suggests, and those Macs are in real trouble.

Screenshot of SC World's August 2026 report on the macOS screen-sharing flaw being actively exploited for crypto-mining
scworld.com · August 14, 2026
Why this matters: Every Mac with Screen Sharing reachable from the open internet is exposed right now, and because the attack needs no password and no account, there is no failed login to notice. My own read is that the surface is genuinely small, most Macs never expose port 5900, but for the ones that do this is about as bad as a remote bug gets: root, plus a route around the TCC privacy controls meant to keep your files off-limits. Action this week: Update every Mac to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. Then check whether Screen Sharing or Remote Management is even switched on, and make sure port 5900 cannot be reached from outside your own network, because a miner dropped after exploitation shows up as nothing more than a machine that quietly runs hot. On a managed fleet, block 5900 at the firewall and get this in front of whoever owns your endpoints.

scworld.com: macOS screen-sharing vulnerability actively exploited for crypto-mining (August 14, 2026)
arstechnica.com: Vulnerability giving attackers full control of Macs is under active exploitation (August 2026)
huntress.com: macOS Screen Sharing RCE patched (August 2026)

2. Meta patented glasses that name everyone at the table and edit them into a reel.

The next person you meet wearing camera glasses could pull up your name, your job, even your home, and you would never know a recording had started.

A Meta patent flagged this week describes AI smartglasses that use facial recognition to detect and identify who is in the wearer's frame, then automatically generate a clip whenever one of those identified people does something and compile the clips into a highlight reel. The filing has it reading facial expressions, using eye-gaze data from the wearer, and reads the scene to pick out the moments worth keeping. The example in the filing is a dinner party, edited into a reel without anyone at the table pressing record. And it is not just glasses; the patent covers phones, AR headsets, and other cameras too.

We have been on the smartglasses privacy story since July, when owners were already too nervous to wear them in public and other builders were selling anti-facial-recognition eyewear to block cameras like these; this month whole European cities began calling for bans. The facial-recognition plan itself goes back to a February 2026 report that Meta planned exactly this. Now it is written into an actual patent filing, and it lands after Senator Ed Markey wrote to Meta objecting to face recognition in consumer eyewear.

Screenshot of 404 Media's report on Meta's patent for facial-recognition AI glasses that auto-edit a highlight reel
404media.co · August 2026
Why this matters: Companies patent things they never ship, so a filing on its own would not worry me. What worries me is that always-on face identification of people who never agreed to it is now written down as a product design, in eyewear Meta already sells today. The person the glasses capture never signed up to be filmed, and they are not the customer either. Every debate so far has been about the person wearing the glasses; I keep waiting for someone to speak for the stranger being scanned. Action this week: Treat anyone in camera glasses as a live facial-recognition sensor, at the office and at the dinner table both. If you run a venue, a school, a clinic, or an office, this is the week to write down whether your recording policy covers biometric capture of people who never consented, because most policies do not. And watch for an opt-out for the person being identified, not just a blinking light on the person wearing the glasses.

404media.co: Meta patents AI glasses to use facial recognition to identify people, make highlight reels of your dinner party (August 2026)
futurism.com: Meta facial-recognition glasses (August 2026)
techcrunch.com: Meta plans to add facial recognition to its smart glasses, report claims (February 13, 2026)

3. The label-swap fraud we tracked in July, now read by a model at the border.

If your company imports anything, an old customs problem just got an AI: a model at the border now scores every shipment you send for the odds its origin is a lie.

On August 13, 2026 the White House trade office issued a report naming illegal transshipment, routing Chinese-made goods through a third country to strip off the country of origin that would trigger a tariff, as a top customs-enforcement priority, and said it is building an AI-enabled "detective border" with Customs and Border Protection to flag suspect shipments at scale. It reads the whole paper trail behind a shipment, where it says it came from, how it was routed, who owns the company, even the packaging and imaging, and flags cargo whose stated origin does not match the rest. The report came from the White House trade office, and the targeting is built to score shipments for disguised origin at scale rather than case by case.

The scale it is aimed at is real. AI supply-chain firm Exiger estimated a mid-range $75 billion in illegally transshipped goods between February 2025 and February 2026, corresponding to roughly $19 billion to $34 billion in lost U.S. tariff revenue, and the report flagged more than 40 countries as elevated transshipment risks. This is the same label-swap fraud we wrote up in July, in a piece on license laundering in AI supply chains under the line "don't trust the label." What is different now is that a model reads for that fraud across every container, and an anomaly score ends up sitting between your shipment and the border.

Screenshot of Fortune's August 13, 2026 report on Trump trade enforcers deploying AI in a tariff-evasion crackdown
fortune.com · August 13, 2026
Why this matters: We wrote up this label-swap fraud in July, in a piece on license laundering in AI supply chains, and this is that same move met with a model instead of a customs officer. If you import, in practice an anomaly score now sits between your shipment and the border, built from signals you may not think of as evidence: your routing history, your ownership structure, even your packaging. When I have watched enforcement go data-first before, the companies that got hurt were rarely the guilty ones; they were the ones who could not quickly prove they were clean. Action this week: Get a straight answer, in writing, to one question before a shipment is ever flagged: can you document genuine country-of-origin for each product line with production-capacity records, not just a supplier's word. Re-audit any route that runs through one of the 40-plus flagged countries, and build the origin paper trail now, before a hold, not scrambled together after one. Send this to whoever signs your customs paperwork.

fortune.com: Trump trade enforcers deploy AI in tariff-evasion crackdown (August 13, 2026)
bakermckenzie.com: White House signals heightened transshipment enforcement, including AI-enabled targeting (August 13, 2026)
washingtonexaminer.com: White House crackdown on tariff-evasion transshipping loophole (August 2026)

4. A man used ChatGPT to design a cancer vaccine for his dying dog, and it worked.

If your dog were dying of cancer and the vets had run out of moves, what would you try? One man in Sydney tried ChatGPT, and his dog's tumor shrank about 75%.

After chemotherapy and immunotherapy failed and his dog Rosie was given only months, Sydney tech entrepreneur Paul Conyngham used ChatGPT and computational genomics to design a personalized mRNA cancer vaccine tuned to her tumor's own mutations. He has no medical training, but seventeen years in machine learning, and he spent about two hours a night for roughly a year and a half working through the biology. A university RNA lab at the University of New South Wales made the actual shot. Rosie had her first injection in December 2025; by mid-March 2026 the tennis-ball-sized tumor on her leg had shrunk by about 75%.

The one-off experiment is now Gamgee, accepted into Y Combinator's Summer 2026 batch, which sequences a dog's tumor alongside its healthy DNA to find the mutations driving that individual cancer and designs an mRNA vaccine to train the immune system against them. It is already running trials in Australia and taking cases from anywhere. The AI did not invent any of the science here. It rides on decades of human mRNA cancer research, and Rosie is still one dog, early, and outside a peer-reviewed trial. But a non-expert really did use AI to reach a personalized cancer treatment that a lab could make, and it's the same thread we've been on since June, when a vaccine designed entirely by AI cleared its first human safety trial.

Screenshot of PYMNTS' report on one dog's ChatGPT-designed cancer vaccine becoming the startup Gamgee
pymnts.com · August 12, 2026
Why this matters: Paul Conyngham is not a scientist, and honestly that is the part that gets me. What he did was navigate decades of existing human mRNA research with a chatbot and a lab that made the shot, not invent a cure from nothing, and Rosie's roughly 75% tumor shrinkage is one animal, early, and not a controlled trial. I still find it genuinely moving, and I have watched this thread since June, when an AI-designed vaccine cleared its first human safety trial. Action this week: Ask an oncology vet whether a personalized-vaccine trial like Gamgee's is worth discussing for a pet with a terminal diagnosis, as an option and not a guarantee. Then watch whether a method that helped one dog can be made affordable and proven for people, or whether it stays a story about one lucky animal. It helps to know how this one actually worked, because the AI-therapy pitches are going to pile up: it sequenced a tumor and trained the immune system to match its mutations, and knowing that much is how you tell which of them are legit.

pymnts.com: One dog's cancer vaccine just became a real company (August 12, 2026)
fortune.com: Australian tech entrepreneur's AI cancer vaccine for dog Rosie (March 15, 2026)
ycombinator.com: Gamgee (Y Combinator Summer 2026)

» What to watch this week

Tomorrow's signal lands here.