New tools, products, platforms, funding rounds, and company developments in AI security.
OpenAI's Codex, an AI tool that helps developers write and manage code, has been recognized as a Leader by Gartner in enterprise coding agents. Codex goes beyond simple autocomplete (where an AI completes code as you type) by letting developers delegate complex tasks like understanding large codebases, running tests, and preparing work for human review while maintaining security and governance controls. The recognition highlights Codex's strengths in enterprise features like approval gates, RBAC (role-based access control, which limits what different users can do), sandboxing (isolating code in a safe environment), and audit trails.
ChromaDB, a popular vector database used in AI applications, has a critical vulnerability (CVE-2026-45829) that allows unauthenticated attackers to run arbitrary code on servers. The flaw exists because ChromaDB checks authentication after it has already downloaded and executed a malicious model from Hugging Face, meaning attackers can trick the system into running their code by uploading a malicious model and requesting ChromaDB to use it.
This is a discussion panel about how AI companies are working to build systems that understand the physical world, moving beyond the current limitations of LLMs (large language models, which are AI systems trained on text). The conversation explores recent developments in world models, which are AI systems designed to understand and predict how the physical world works.
Microsoft is negotiating to supply its custom Maia AI chips to Anthropic, a company that makes Claude, a popular AI assistant. This deal would help Microsoft compete with Amazon and Google in providing specialized AI hardware to clients, while Anthropic seeks to address its computing capacity challenges after experiencing rapid growth in demand for its AI tools.
Wiz has integrated with Anthropic's Claude Compliance API to give organizations visibility into how Claude Enterprise is being used across their environment. The integration lets security teams see Claude users, projects, permissions, and connected datasets mapped into Wiz's Security Graph (a centralized system for tracking and connecting all resources), helping with compliance audits and governance.
Polyend has released the Endless, a $299 guitar pedal that uses AI to create audio effects based on text prompts (instructions you type in). The pedal runs on an ARM processor (the type of chip commonly found in smartphones) and works with software called Playground, which contains interconnected AI agents that interpret your written descriptions and generate corresponding guitar effects.
OpenAI's AI model has made progress on the planar unit distance problem, a math question posed 80 years ago asking how many pairs of dots on a sheet can be the same distance apart. The AI disproved the long-standing assumption that square grids provided the best solution by discovering a new family of mathematical arrangements that perform better, though the broader problem remains unsolved. While mathematicians have validated this work, humans were significantly involved in improving and refining the AI's original proof.
Spotify Studio is a new AI application that creates personalized daily podcasts and briefings by analyzing your Spotify listening history and connected apps like email and calendar. The AI can perform actions like web searches and task organization on your behalf, with generated content savable to your Spotify library.
At Anthropic's Code with Claude developer conference, nearly half of attendees reported shipping pull requests (code updates submitted for review) entirely written by Claude, an LLM (large language model, an AI trained on vast amounts of text to generate responses), with many not even reading the code themselves. Anthropic is pushing automation further by having Claude check and correct its own work through self-prompting and a new feature called "dreaming," where Claude agents write notes to themselves to learn from past errors and improve on shared codebases without requiring human developers to review intermediate steps.
This article covers a lawsuit where Elon Musk sued Sam Altman and OpenAI, claiming that OpenAI's shift from a nonprofit to a for-profit company violated a charitable trust that Musk had funded. The jury ruled against Musk because he filed the lawsuit after the statute of limitations (the legal deadline for filing) had expired. While the case was officially about OpenAI's structure change, it appeared to be mainly about Musk's frustration with Altman and OpenAI's success.
Anthropic, an AI company, agreed to pay SpaceX $1.25 billion per month (totaling $15 billion annually) through May 2029 for access to SpaceX's Colossus data centers in Memphis, Tennessee, which are used for AI training. This deal was revealed in SpaceX's IPO filing (a document companies file when offering stock to the public for the first time).
A developer used Google's AI Studio to quickly generate Android apps by typing brief text descriptions into a web browser, with the AI automatically handling all the coding and app building. The process required minimal manual setup (enabling USB debugging mode and connecting a phone to a computer), and a 148-word description resulted in a working app installed on an actual Android device in about ten minutes.
AdventHealth, a hospital system across nine states, is using ChatGPT for Healthcare (an AI tool built by OpenAI with extra protections for medical settings) to reduce time spent on administrative tasks like documentation and case review, allowing clinicians to focus more on patient care. The health system treated AI adoption as a core business goal rather than just a technical pilot, tracking usage metrics and having teams within each department share AI workflows tailored to their specific work. By framing the technology as 'time back' for staff rather than just automation, AdventHealth aimed to improve both operational efficiency and patient access to care.
Ocean, a newly launched startup, received $28 million in funding to develop an agentic email security platform, which uses specialized AI agents (software programs that can act autonomously to complete tasks) to analyze incoming emails and detect threats like business email compromise (when attackers impersonate trusted business contacts) and AI-generated phishing (fraudulent messages created by AI). The platform goes beyond simple filtering by examining sender intent, conversation context, and infrastructure details to identify malicious intent in emails that appear legitimate.
Fix: Until a patch becomes available, researchers advise: (1) deploy ChromaDB using the Rust implementation instead of the Python FastAPI server, as the Rust version is not affected, and (2) restrict network access to the ChromaDB port to trusted IP addresses only.
CSO OnlineThis article discusses how security leaders (CISOs, or Chief Information Security Officers) should prepare for AI systems that can take independent actions (agentic AI). The key challenge is creating an AI bill of materials (AI BOM, a detailed list of all components and dependencies in an AI system) that documents both what components make up the AI system and how those components actually behave when running.
Apple's Memory Integrity Enforcement (MIE, a hardware-based protection against memory corruption attacks, where attackers modify data in a computer's RAM to take control) was bypassed by researchers using AI systems, who developed a working exploit for macOS on M5 chips in under a week. The article argues that while defense-in-depth (layering multiple security barriers in hardware and software) can slow attackers down, AI-assisted exploration of vulnerabilities now happens faster than traditional human-only methods, making older security designs insufficient.
Companies are increasingly deploying AI agents (software programs that can act independently to complete tasks), and these agents need identity management, security, and governance like human users do. New research shows that budgeting and planning for AI agent identity security works differently than it does for traditional IAM (identity and access management, the systems that control who can access what resources) projects.
Generative AI chatbots are becoming important customer-facing tools for businesses, but they create security risks because they can access sensitive information, speak for the brand, and be manipulated into harmful actions. The text provides examples of real incidents where chatbots caused problems, such as offering incorrect discounts or giving misleading information to customers.
Microsoft has released two open-source tools, Rampart and Clarity, designed to catch safety problems in AI agents (software systems that can take actions autonomously) earlier in development. Rampart automates repeated safety testing throughout the development process to find issues like prompt injection (tricking an AI by hiding instructions in its input) and unsafe tool use, while Clarity helps engineers document and validate their design assumptions before coding begins.
Fix: Microsoft's explicit solutions are: (1) Rampart, which transforms red-team findings into repeatable automated tests that run continuously in CI/CD workflows (continuous integration/continuous deployment, the automated systems developers use to test and release code) to surface issues before production; and (2) Clarity, a tool available as a desktop app, web UI, or embedded in coding agents that guides engineers through structured conversations about agent behavior, permissions, and trust boundaries, with outputs saved as markdown files in the repository for review and version control.
CSO OnlineEnterprises are rapidly deploying AI agents (software systems that can act independently to complete tasks), and these agents need identity management (systems that verify who or what is accessing resources and what they're allowed to do). New research shows that budgeting for AI agent security differs significantly from how companies budget for traditional identity management projects.