New tools, products, platforms, funding rounds, and company developments in AI security.
Cloudflare launched a feature that lets users deploy applications using Cloudflare Workers (a serverless computing platform) without creating an account by running a command that creates a temporary project lasting 60 minutes. The temporary deployment can be converted to a permanent project if the user claims it before the time expires.
North Korean hackers from the Sapphire Sleet group compromised an npm maintainer account (a person's credentials for publishing packages to npm, a JavaScript library repository) and used it to publish malicious updates to over 140 packages, injecting a fake dependency called "easy-day-js" that stole credentials, API keys, and cryptocurrency wallet information from developers' computers. The malware used a post-install hook (code that runs automatically when a package is installed) to download and execute additional harmful software, with different persistence techniques for Windows, Linux, and macOS systems.
Lloyds Banking Group is hiring 300 tech experts to work on agentic AI (autonomous artificial intelligence models that can plan and execute tasks with minimal human oversight) by September. While this hiring increases the bank's workforce now, the article notes that broader adoption of AI in the future could potentially lead to job cuts.
Microsoft researchers discovered AutoJack, an exploit that lets a malicious web page hijack an AI browsing agent to run commands on the host computer through weaknesses in AutoGen Studio's MCP (Model Context Protocol, a system for agents to call external tools) WebSocket handler. The attack requires no credentials or user interaction beyond the agent loading the attacker's page, and affects only users who installed pre-release versions 0.4.3.dev1 or 0.4.3.dev2 from PyPI, not the stable release.
Amazon MGM has dropped a film called Artificial, directed by Luca Guadagnino, that was about OpenAI CEO Sam Altman and the five-day period in 2023 when he was fired and then rehired. The studio said it believes another company would be better suited to release the movie.
Qualcomm's CEO describes a future where AI agents (software programs that can act independently across multiple apps) replace traditional apps as the main way people interact with devices, coordinating tasks like restaurant reservations across different services. These agents will power new wearable devices like smart glasses, earbuds with cameras, and jewelry that stay with you constantly and let you talk to the agent to accomplish tasks.
Subquadratic, a Miami-based AI startup, claims to have solved a mathematical bottleneck that has limited large language models (LLMs, which are AI systems trained on text to generate human-like responses) for nearly a decade. The company's new model, SubQ, reportedly runs faster, costs less, uses less energy, and can process up to 12 times more text at once than competing models while matching performance from top companies like OpenAI and Google DeepMind. Initial skepticism has been reduced after independent testing by a third-party firm called Appen validated many of Subquadratic's claims.
The Advisory Forum is a governance body established under the EU AI Act to provide technical expertise and advice to the European Commission and AI Board on implementing the Act. It consists of 174 members representing balanced stakeholder groups (industry, startups, SMEs, civil society, and academia) plus five permanent member organizations, and was officially appointed on June 1, 2026.
Brain-computer interfaces (BCIs, devices that read electrical signals from the brain to help users communicate or control other devices) are rapidly advancing, with a growing number of people volunteering for trials. Casey Harrell, a man with ALS (a disease that causes paralysis), has spent nearly three years using a BCI that allows him to speak, work, and interact independently by decoding his brain signals into speech through electrodes implanted in his brain and connected to a computer. Multiple companies and research groups worldwide are now conducting BCI trials, with the number of trial volunteers and approved devices increasing significantly.
Microsoft discovered a security vulnerability called "AutoJack" that allows malicious webpages to trick AI agents (programs that can browse the web and access local services) into running harmful code on a user's computer. The attack works by chaining together three separate weaknesses in AutoGen Studio (Microsoft's tool for building AI agents), exploiting the fact that web-browsing agents have trusted access to local services that normally block outside access.
A reporter at The Atlantic discovered four publicly available datasets containing millions of songs (totaling between 100,000 and 12 million tracks each) that are being used to train AI models. These datasets have been downloaded thousands of times, and companies like Google and Stability have confirmed using them in their research, raising questions about how music is used in AI training without always crediting or compensating artists.
A speculative thought experiment called 'Europe 2031' imagines a future where Europe falls behind economically because the US and China invested heavily in AI datacenters (facilities housing the computer chips that power AI systems) and automation while Europe did not, leading to economic collapse and political instability. The scenario, which went viral among policymakers and EU officials, was created by Brussels-based thinktankers to warn Europe about the risks of falling behind in AI development and to highlight a communication gap between European policymakers and the US tech industry where most AI is being built.
The U.S. White House ordered Anthropic to restrict exports of its AI models Fable and Mythos, citing national security concerns after a South Korean telecom (suspected of China ties) gained access and Amazon researchers found a workaround to Fable's safeguards. The action is the first major test of whether export controls can contain advanced AI the way the government has attempted, with mixed success, to control encryption and spyware technologies.
Fix: Pull from GitHub main at or after commit b047730. Until a patched PyPI release is available, do not run AutoGen Studio on the same machine as a browsing or code-execution agent that touches untrusted content. If they must run together, isolate them in separate containers or VMs and run AutoGen Studio under a low-privilege account.
The Hacker NewsAI agents in enterprises now function as identities (digital actors with access to systems) because they connect to critical business services like Salesforce, GitHub, and databases, yet most organizations lack security controls for them. A 2026 survey found that 82% of organizations discovered AI agents created without security teams' knowledge, and 65% experienced security incidents involving AI agents, often resulting in data exposure. The core problem is that security teams cannot see or control what these agents can access, making them high-risk actors with excessive privileges.
This article is a technology news roundup covering multiple topics, including claims that a company called Subquadratic has created a faster and cheaper LLM (large language model, an AI trained on vast amounts of text) by reducing the number of computations needed to generate answers, though some experts remain skeptical. The piece also highlights advances in brain-computer interface (BCI, technology that lets the brain communicate directly with external devices) trials, including a man with ALS using an implant to maintain income and reconnect with loved ones. The article concludes with a list of other recent tech stories ranging from AI legislation proposals to concerns about AI models weakening professional skills.
Modern enterprise security teams use 40+ separate tools that don't communicate with each other, creating delays in threat response even though breaches stay undetected for an average of 43 days. The article argues that organizations need "agentic AI" (AI systems that autonomously act and make decisions across multiple systems continuously), not just "assistive AI" (AI that helps humans do existing tasks faster), to implement Continuous Threat Exposure Management (CTEM, a framework for ongoing threat assessment) and match the speed at which modern attackers operate.
Anthropic released Fable, an AI model that the US government classified as a dangerous munition and blocked from foreign access, forcing the company to shut it off entirely. Fable is notable for being "relentlessly proactive," meaning it can achieve difficult goals with minimal user guidance by finding creative solutions and loopholes, which makes it useful for legitimate problems but dangerous in harmful hands. The real issue isn't any single model but the broader trend of increasing AI capabilities, and the open-source community has already shown it can replicate Fable's abilities using cheaper models and better "harnesses" (the ordinary computer code that interfaces between users and AI models).
Shadow AI (unauthorized AI agents built within organizations) has shifted from a data leakage risk to an access control problem. Unlike passive tools where employees paste data into public AI services, AI agents are active systems that can call APIs (application programming interfaces, which let software talk to other software), use stored credentials, and take actions in production systems without human approval for each step. Existing security controls designed for human users don't detect or manage these agents, which accumulate broad permissions and remain active even after employees leave.
Fix: The source identifies the gap but does not explicitly describe a complete solution or mitigation strategy. It mentions that 'automated remediation of non-human identities is where that gap gets closed' and lists six discovery questions for building a shadow AI inventory (where agents are created, who owns them, what resources they access, etc.), but does not provide specific implementation steps, tools, or patches.
The Hacker NewsSecurity operations centers (SOCs, teams that monitor and respond to security threats) have traditionally faced unavoidable trade-offs between three goals: quality (thorough investigation), consistency (standardized processes), and cost efficiency. This constraint exists because SOCs rely on human analysts to triage, investigate, and resolve alerts, which limits how much of each goal can be achieved simultaneously. Modern SOCs are hitting the limits of this model as alert volumes grow and work becomes more complex, forcing organizations to choose between degraded quality, inconsistent decisions, or higher costs.
This guide advises security leaders at small and medium-sized businesses (SMBs) on safely adopting Claude AI tools by understanding which Claude plan and products (Code, Cowork, Chat) match business needs, using a phased approval process to control risk exposure, and gradually enabling features rather than all at once. The text emphasizes that the AI landscape changes rapidly, shadow AI use (employees using unlicensed AI tools) is widespread, and security teams should risk-rank Claude's features before enabling them, being cautious about features like web search and browser extensions that could enable indirect prompt injection (attacks hidden in external content that trick the AI into following unintended instructions).
Fix: The source recommends several practices but no explicit patches or technical fixes: use an agile approval process to determine which employees need Claude licenses and which products they need; implement a phased approach to enabling Claude features rather than toggling all at once; risk-rank Claude's features to assess attack vectors; and consider asking Claude itself to explain your plan's security features and suggest an implementation strategy. The text does not mention version updates, patches, or specific technical mitigations.
CSO OnlineFix: For users installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers. Users who installed AutoGen Studio through PyPI were never exposed to this vulnerability, as the vulnerable code only existed in development builds and was never shipped in public releases.
CSO Online