ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
19:23 · August 20, 2026 · Hacker News AI Section

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs
Summary
This threat roundup examines a cluster of developments at the intersection of AI safety, privacy-preserving computation, and offensive tooling. OpenAI is previewing Private Safety Processing for frontier models under zero-data-retention deployments, allowing automated misuse detection to run on customer-controlled infrastructure or on encrypted customer keys while returning only narrow safety signals. Google has released HEIR, an open-source compiler toolchain that converts ordinary AI models into equivalents capable of inference directly on homomorphically encrypted inputs, removing the need to decrypt data during processing.
Alongside these defensive advances, the roundup notes the public launch of Kriminal AI, a clearnet service that supplies uncensored model access by routing queries across multiple providers including Grok, Claude, and Llama variants. The service, which charges between roughly thirteen and one hundred dollars per month, markets itself explicitly as free of the refusal mechanisms present in mainstream offerings. China’s Z.ai has introduced GLM-5.3, whose reported performance in automated vulnerability discovery is presented as evidence of growing dual-use capability in large models.
The remainder of the roundup covers conventional vulnerabilities that affect operational technology and development platforms, including unauthenticated remote-code-execution flaws in Gogs and n8n, alongside regulatory action requiring Apple to harmonize App Tracking Transparency consent flows across the European Union.
Why it matters
The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.











