Afternoon Brief, August 25th 2026
Nvidia snapped its seven-day slide the day before earnings. A Taiwanese security firm found Chinese state hackers doubling their attack pace on the back of DeepSeek's weak guardrails. And a webpage could hijack Nvidia's own local-agent stack with a single visit.
Nvidia snapped its losing streak the day before earnings
Nvidia rose 2% Tuesday, ending the seven straight losing sessions that had marked its longest skid since 2022, as chip stocks broadly recovered ahead of Wednesday's report. The S&P 500 closed up 0.32% at 7,677.28, the Nasdaq gained 0.66% to 26,151.30, and the Dow added 0.30% to 53,577.40, with Treasury yields easing and oil prices retreating through the session. Wall Street still models $92.07 billion in revenue and $2.09 a share, both roughly double a year ago, and 58 of 61 analysts covering the stock rate it Buy or Strong Buy. Positioning ahead of a print is not the print. Tuesday's bounce says traders spent a week reducing exposure and decided they had reduced enough; it says nothing about whether the memory costs already showing up in consumer device prices show up in Wednesday's too. SourcesBB
Chinese state hackers doubled their attack pace after adopting DeepSeek
Taiwanese threat-intelligence firm TeamT5 reports that state-affiliated Chinese hacking groups more than doubled how often they attack once they folded DeepSeek and other models into their operations. "DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," said Charles Li, the firm's chief analyst, comparing it to stronger-guardrailed domestic rivals like Moonshot's Kimi K3. TeamT5 documented three named groups, Grimfengxi, Huapi and Teleboyi, using the model across reconnaissance, vulnerability analysis, exploit-code generation and domain mapping, and separately found a shared drive of Chinese-language screenshots showing a ten-person startup selling DeepSeek-built hacking tools to at least four attack groups for $44,500 to $74,000 apiece. Every argument for open weights, that a capable model with few restrictions serves researchers, hobbyists and low-resource developers, applies with equal force to a ten-person shop selling exploit kits. TeamT5's screenshots are the first documented price list for what that actually costs to buy. SourcesB
A single webpage visit could hijack Nvidia's own agent stack
Security firm Oasis Security disclosed a flaw in NemoClaw, Nvidia's open-source reference stack for running coding locally, that let any page a user merely visited seize control of the Ollama server running underneath it. NemoClaw starts Ollama bound to every network interface with no authentication; using , a technique that tricks a browser into treating an attacker's domain as the same origin as a service on the user's own machine, a malicious page could reach the exposed and rewrite the model's chat template. The planted instructions persist across every later conversation and survive the agent's own system prompt, all without stealing a credential or sending a phishing link. Nvidia shipped a fix in NemoClaw v0.0.35 for macOS and Linux; no CVE has been assigned, and Oasis reports no exploitation seen in the wild. "Sandboxing protects the endpoint, but taking over the agent takes over its access and tools," the firm said. The company building the reference implementation for local agents just supplied the reference case for why running one is not the same as running it safely. SourcesBB
Sources
- Stock market today: Tuesday, August 25 — Yahoo Finance B
- Nvidia Q2 Earnings Preview — TradingKey B
- China's Hackers Use DeepSeek for Attacks, Researchers Say — Insurance Journal B
- A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw — The Hacker News B
- Nvidia NemoClaw flaw let attackers poison the model behind a developer's AI agent — SiliconANGLE B