AI Infrastructure Expansion and Security Threats Escalate Simultaneously
인프라/플랫폼 | Thu Aug 13 2026 00:00:00 GMT+0000 (Coordinated Universal Time) | 6 sources
Meta's investment in AI infrastructure workforce, LiteLLM supply chain attack, and Zoom AI bug hunting highlight simultaneous infrastructure and security issues.
Analysis
[Meta & NABTU] signed partnership to train AI infrastructure construction workforce [1]
- Investment in skilled trade workers for AI data center construction
- Community investment through Future Is For Everyone Fund
- Integration with America's Workforce Academy and registered apprenticeship programs
- Collaboration with 14 unions representing 3.2 million workers in North America
[LiteLLM] suffered massive credential leak from supply chain attack [2]
- Credentials from Microsoft
- Amazon
- Cisco
- Samsung
- Salesforce exposed
- Access keys from 2
- 500 organizations stolen within 40 minutes
- 434
- 000 CI/CD pipeline credentials leaked
- Caused by infection of Trivy vulnerability scanner
- Perpetrated by teen-centered hacker group TeamPCP
[Zoom] released urgent patch for screen sharing vulnerability discovered by AI [6]
- Vulnerability found using public AI model in under 20 prompts
- Device takeover possible during screen sharing without interaction
- Affects all platforms including Windows
- macOS
- Linux
- iOS
- Android
- Flaw in real-time annotation protocol was the cause
- Patches deployed on both server and client sides
[Google Chrome] introduced DBSC protection feature to prevent account takeover [3]
- Combines session cookies with signing keys from TPM/Secure Enclave
- Attackers cannot sign even if they steal cookies
- Supported from Windows 147 and macOS 150 versions
- Currently activated for a limited set of users
[Pass-ta-key] disclosed passkey extraction attack targeting Windows Google Password Manager [4]
- Disclosed by Palo Alto Networks researcher Arie Olshtein
- Full extraction of all passkeys stored in GPM on infected Windows devices
- FIDO 2 specification does not mandate TPM storage
- macOS
- iOS
- and Android also use local storage but are protected by app permissions
[Known Agents] published AI bot traffic ecosystem metrics across 5,000 websites [5]
- AI-related share of bot traffic rose 11 percentage points to 28%
- 98.5% compliance rate with robots.txt rules
- AI chat referrals at 0.1% level of human visits
- Detailed classification including AI Agent
- Assistant
- Coding Agent
Sources
- [1] NABTU and Meta Announce New Partnership to Invest In Skilled Trades for the AI Era - Meta AI Blog
- [2] Terabytes of credentials leaked in massive supply-chain attack - Ars Technica AI
- [3] Chrome adopts what may be the best protection yet against account takeovers - Ars Technica AI
- [4] New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica AI
- [5] Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot - Hacker News
- [6] A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call - Wired AI