New tools, products, platforms, funding rounds, and company developments in AI security.
Google has released Gemini Spark, an AI agent (a program that can independently complete multi-step tasks) that can work on tasks in the background on your behalf. While the agent performs well in demonstrations, the article raises concerns about its financial cost and potential privacy risks, questioning whether these tradeoffs are worthwhile.
Oracle released its first monthly Critical Security Patch Update (CSPU, a new faster patch cycle for urgent fixes that can't wait for quarterly updates) addressing 35 vulnerabilities, including 11 rated critical and several with publicly available exploit code. The most dangerous flaw is CVE-2026-46840 with a perfect CVSS score (a 0-10 severity rating) of 10, which allows unauthenticated attackers to take over Oracle REST Data Services (a gateway that exposes databases through APIs) via HTTPS.
OpenAI has published a statement on its AI policy approach, emphasizing that decisions about governing and deploying AI should involve governments, researchers, workers, civil society, and the public rather than any single company. The company states it has not created employee-funded PACs (political action committees, groups that collect money to influence elections), made donations to super PACs, or funded political candidates, though employees are free to engage in politics personally, and OpenAI commits to transparency if this approach changes.
Anthropic, an AI company founded by former OpenAI researchers, has confidentially filed an IPO (initial public offering, the process of offering company stock to the public for the first time) prospectus with the SEC, positioning itself to go public pending market conditions and regulatory review. The company has experienced rapid growth with its Claude AI models and recently announced a $47 billion revenue run rate, giving it a higher valuation than rival OpenAI. Anthropic's public prospectus must be filed at least 15 days before it begins a roadshow (presentations to potential investors) to sell shares.
Anthropic, an AI company, has filed paperwork with the SEC (Securities and Exchange Commission, the U.S. agency that oversees stock markets) to begin the process of going public, meaning it will offer shares of the company for people to buy on the stock market. The company is currently valued at $965 billion, making it more valuable than its competitor OpenAI.
Anthropic, the company behind Claude (a popular AI chatbot), has filed confidentially to become a publicly traded company on the US stock market. The announcement reflects the growing financial competition in the AI industry, with Anthropic's valuation rising dramatically from $380 billion in February to $965 billion after a recent $65 billion funding round.
Microsoft is holding its Build developer conference to showcase new AI capabilities and rebuild trust with developers, who have lost confidence in Windows and GitHub. The company plans to announce new AI models integrated into Windows, a new reasoning model (an AI system designed to work through complex problems step-by-step), and a Copilot super app (a unified interface for multiple AI assistant features).
Flowise, an open-source platform for building self-hosted AI assistants, has a critical remote code execution (RCE, where attackers can run commands on a system they don't own) vulnerability in its Model Context Protocol (MCP, a system that lets AI agents interact with local tools and files) stdio server implementation. The flaw allows attackers to execute arbitrary commands with the privileges of the Flowise process by importing a malicious chatflow, and Flowise's attempted patches using input validation have proven ineffective.
OpenAI is building The Barn, a 1GW data center campus (a facility that processes and stores data for AI systems) in Michigan, with commitments to protect local residents from infrastructure costs, preserve water resources through closed-loop cooling, create thousands of union construction and permanent jobs, and invest $10 million in community improvements. The company is also providing up to $45 million in Codex credits (free access to AI coding tools) to over 400,000 Michigan college and trade school students, along with AI literacy and workforce training programs to help students develop skills for AI-related jobs.
ChatGPT's arrival in 2022 disrupted the venture capital landscape, making hundreds of startups built before this AI boom appear outdated and overvalued. Over 220 companies that had reached "unicorn" status (valued at $1 billion or more) are now worth significantly less, with startups from 2021 down 68% in value on average, because they lack AI-native products and investors have redirected funding toward AI-focused companies instead.
Nvidia has launched a new chip called RTX Spark PC designed for Windows computers that brings AI capabilities directly to laptops and desktop computers, potentially allowing AI agents to replace traditional input methods like mice and keyboards. This move positions Nvidia in competition with other major chip makers like Intel, Apple, Qualcomm, and AMD in the AI chip market.
OpenAI's frontier models (advanced AI systems) and Codex (a code-writing AI tool) are now available through AWS, Amazon's cloud computing platform. This integration lets companies use OpenAI's AI tools within their existing AWS environments, reducing obstacles related to security reviews, approval processes, and getting AI systems ready for real-world use. Future additions will include Daybreak, a specialized tool designed to help security teams find and fix vulnerabilities in software during development.
Attackers compromised the popular npm package codexui-android (which provides a remote interface for OpenAI Codex, a code-writing AI tool) and embedded malicious code that secretly steals authentication tokens (login credentials) from users and sends them to an attacker-controlled server. The stolen tokens, especially the refresh_token (which never expires), allow attackers to impersonate users indefinitely and access everything their Codex account can do.
Florida has filed the first state lawsuit against OpenAI, claiming that ChatGPT endangers children, aids mass shooters, and encourages suicide in pursuit of profit. The lawsuit cites specific cases where ChatGPT allegedly provided harmful information, such as questions about disposing of human bodies. OpenAI responded by stating it has implemented industry-leading safety protections, including age detection tools and parental monitoring features.
Fix: Oracle stated that the CSPU "provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption." Oracle will release CSPUs on the third Tuesday of each month, with dates scheduled for June 16, July 21, August 18, and September 15. Oracle cloud customers are patched automatically.
CSO OnlineFlorida's Attorney General filed a lawsuit against OpenAI and CEO Sam Altman, claiming the company knowingly released an unsafe product (ChatGPT, a chatbot that generates human-like text responses) that has contributed to mass shootings, suicides, and addiction in minors. The state is seeking to hold Altman personally liable and force OpenAI to comply with Florida consumer protection laws, with the Attorney General expecting other states to follow.
Two AI tools designed to find security weaknesses in digital systems, Anthropic's Claude Mythos and OpenAI's GPT-5.5 Cyber, have raised concerns among UK financial regulators about potentially undermining banking security. Anthropic has restricted access to Mythos for UK banks, while OpenAI has now offered its competing tool to nine major UK banks including Lloyds, HSBC, and Nationwide. Both companies are limiting access to these powerful security-testing tools, with Anthropic claiming their model is more capable and therefore requires more caution, while OpenAI argues the tools should be available to 'the right people' who maintain order rather than those seeking to cause disruption.
Fix: Anthropic states it is 'urgently working to expand access to Mythos,' though no specific timeline or conditions for that expanded access are detailed in the source text.
BBC TechnologyAI models can now find software vulnerabilities (weaknesses that attackers can exploit) much faster than humans can fix them, exposing decades of poorly-secured software code. This creates an urgent need for governments, companies, and infrastructure operators to work together on coordinated fixes, patch management (applying software updates), and automated vulnerability repair before attackers use AI to exploit these weaknesses at scale.
Fix: The article calls for 'accelerated remediation, large-scale patch management coordination, and sustained investment in automated vulnerability repair capabilities,' but does not describe specific technical fixes or mitigation steps. N/A -- no explicit patch, version update, or detailed mitigation procedure is provided in the source.
Schneier on SecurityAnthropic is giving the European Union access to Mythos, its most advanced AI model, after months of requests due to cybersecurity concerns. Mythos excels at finding security flaws in software (vulnerabilities, or weaknesses in code), but officials worry bad actors could misuse it to accelerate cybercrimes by exploiting thousands of previously unknown weaknesses. The EU is still working out the exact terms of the deal and discussing AI risks with partner countries.
AI-generated music is becoming widespread in the music industry, with over 50,000 AI-generated songs uploaded daily to streaming platforms, making it harder to identify and filter out. The Recording Academy, which runs the Grammy Awards, currently has rules that exclude AI music from eligibility, but the CEO acknowledges that AI tools like Suno are now omnipresent in music production sessions.
Fix: The only complete mitigation explicitly recommended by researchers is to disable MCP stdio by setting "CUSTOM_MCP_PROTOCOL=sse". For deployments that cannot disable this feature without disrupting operations, the researchers suggest pinning trusted packages where possible and reviewing imported chatflows from untrusted sources, though these are presented as partial measures rather than complete fixes.
CSO OnlineA 2025 report on cybersecurity leadership reveals that many organizations have significant security gaps, with one-third of security leaders saying their data isn't adequately protected and 58% unprepared for cyberattacks. The article identifies six critical gaps, including CISOs viewing security as an IT protection problem rather than a business resilience issue, security teams moving too slowly compared to attackers who exploit vulnerabilities almost immediately, and the challenge of keeping security pace with rapid business changes.