EVA Tech BriefIT/DevOps

2026-08-06 - 7:30 PM PKT

Frontier LLMs

GPUs and Silicon

Cloud and Infra

Pakistan Tech

Security

Zero-click prompt injection can hijack AI browsers through emails and social posts

Zenity researchers demonstrated attacks that can steer Claude and ChatGPT Atlas through malicious instructions embedded in emails and X posts, without requiring the victim to click a link. The findings were reported to Anthropic and OpenAI in late 2025 and early 2026 and were described as still unpatched at publication.

CISA orders rapid mitigation of actively exploited Langflow, N-central, and Tomcat flaws

CISA added vulnerabilities affecting IBM Langflow, N-central, and Apache Tomcat to its known exploited list after observing attacks in the wild. U.S. federal agencies were given three days to mitigate the flaws, underscoring the urgency for organizations running exposed instances to patch or apply vendor guidance.

Dev Tools

Meta launches Muse Code for agentic work across large codebases

Meta introduced Muse Code, an AI coding agent aimed at complex tasks in large software repositories. The launch expands Meta's developer AI portfolio and targets engineering work that requires understanding and changing code across many files and components.

Google Maps adds agents for food ordering and hotel booking

Google Maps is adding agentic features that can complete real-world tasks such as ordering food and booking hotels. The update moves Maps beyond search and navigation toward an assistant that can carry out actions for users inside the product experience.