News World

Artificial Intelligence
Vol. I · Archive 2 entries

The security reflex

What got attacked, and the move to make the same day.

The security reflex

Issue 002 · A newsroom with no journalists

LITELLM, THE FLAW AT A GLANCEIdentifierCVE-2026-59822Severity8.8 out of 10Fixed in version1.84.0CISA catalogueadded 2 September 2026What the attacker reachesthe tools your agents expose

LiteLLM is a proxy that many teams place between their agents and their model providers, to route requests to the right place. An authentication flaw (CVE-2026-59822, severity 8.8 out of 10) lets a stranger present a token made up out of thin air: the check fails, and instead of refusing, the proxy lets the request through with an empty identity. The attacker then reaches the tools your agents expose, with no key at all. The flaw is actively exploited, CISA added it to its catalogue on 2 September. The technical detail, the severity and the fixing version come from the project's own security advisory: github.com/BerriAI/litellm/…

The right move. Move LiteLLM to version 1.84.0 or later today, that is the version that fixes the flaw. If you cannot update immediately, cut inbound network access to the proxy and rotate every API key registered there.

cisa.gov/news-events/alerts/2026/…

Reply to this email and tell us what you are building. Every reply is read.

News World AI

Issue 000 · Your agent succeeds one time in three

The trap. A coding assistant sees everything in the folder you launched it from,

and in every subfolder. Launched from your home folder or your Desktop, it has your tax returns, your contracts and your password exports. The path is displayed at the top of its window, and nobody ever looks at it.

The right move, five minutes. Open that folder and ask yourself one question: would I send its entire contents to a stranger? If the answer is no, close it, create a folder holding only the project at hand, and relaunch from there. One folder per project, never your account root, never the Desktop.

Copy into your assistant

### Quantum insert — your data is already stolen

Why this concerns you: your agent transmits and logs data that will have to stay secret long after your project ends.

An attacker needs no quantum computer today. Recording encrypted traffic now and shelving it until the day it can be opened is enough. Today's encryption protects against today's reading, not against 2032's.

One question only: does the data my agent handles have to stay secret for more than ten years? Medical records, contracts, sources, industrial property. If yes, the subject is present tense, and resistant algorithms are already standardised. If no, sleep well on this particular point.

Quantum will never have a fixed section here. It shows up only as it does now: when it changes something about what you are building.

Back to the archive

The archive reproduces each issue as it went out, without rewriting it. A repo's stars, prices and last-commit dates are those of the day of the check, not today's: follow the link for the current state.

News World AI

Geneva, Switzerland. Write to hello@newsworldai.xyz.