New tools, products, platforms, funding rounds, and company developments in AI security.
Companies are shifting away from relying on third-party AI providers because they worry about losing control of their proprietary data and competitive advantage when that data passes through external systems. This movement toward AI and data sovereignty, meaning companies want to build and control their own AI models rather than depend on centralized cloud providers, is now a major business priority, with 70% of executives surveyed believing they need sovereign data and AI platforms to succeed.
Codex, an AI coding assistant, is now available in the ChatGPT mobile app, allowing users to manage and guide AI-assisted coding work from their phones while Codex runs on their laptops or remote machines. The mobile app lets users review outputs, approve commands, answer questions, and provide direction to Codex in real time from anywhere, with a secure relay layer (an encrypted connection system) protecting machines from direct internet exposure while syncing updates between devices.
Agentic AI (systems that can independently plan and take actions to complete tasks) offers significant potential for financial services, but its success depends primarily on the quality, security, and accessibility of its underlying data rather than the sophistication of the AI itself. Financial services companies must establish centralized, well-indexed, and secure data stores that can be searched and managed at scale, while ensuring all data processes are auditable and explainable to meet regulatory requirements and avoid errors like hallucinations (false or made-up information from the AI).
PraisonAI, an open-source framework for building multi-agent AI systems, has a critical authentication bypass vulnerability (CVE-2026-44338, a severity rating of 7.3 out of 10) where its default API server ships with authentication disabled, allowing anyone to access protected endpoints and trigger workflows without permission. Threat actors began exploiting this vulnerability within hours of its public disclosure, scanning internet-exposed instances to confirm they could access the vulnerable endpoints.
PraisonAI, an open-source AI orchestration framework (software that coordinates multiple AI components), had a critical flaw where authentication (verification of user identity) was disabled by default in its API server, allowing anyone on the internet to access AI workflows without permission. Attackers began scanning for vulnerable systems within less than four hours of the vulnerability being publicly disclosed, prompting urgent calls for affected organizations to update immediately.
Elon Musk and Sam Altman, former cofounders of OpenAI, are in a legal dispute over whether Altman and another executive deceived Musk about converting the organization from non-profit to for-profit structure. The article argues that focusing on this personal conflict distracts from deeper problems with AI itself.
PraisonAI, a framework for deploying autonomous AI agents, had a critical authentication bypass vulnerability (CVE-2026-44338) in versions 2.5.6 to 4.6.33 where a legacy Flask API server shipped with authentication disabled by default, allowing unauthenticated attackers to access agent configurations and trigger workflows. Hackers began scanning for and testing this vulnerability within less than four hours of its public disclosure, demonstrating how quickly AI tools are enabling rapid exploitation of newly disclosed security flaws.
OpenAI updated ChatGPT to better recognize warning signs of harm by analyzing context within and across conversations, particularly for suicide, self-harm, and harm-to-others scenarios. The system now uses safety summaries (short notes about earlier safety-relevant context) and improved training to distinguish between safe interactions and rare high-risk situations, allowing ChatGPT to respond more carefully through de-escalation, refusal, or redirection to support resources. These improvements were developed in collaboration with mental health experts over more than two years.
Two brothers fired from a hosting company that served 45+ US government agencies used an AI chatbot to help them delete customer databases and cover their tracks, asking it questions like how to clear system logs from SQL servers. The incident highlights that organizations need stronger controls to prevent insider attacks (damage from current or former employees) and must implement better safeguards to prevent AI tools from being misused for destructive purposes.
Microsoft CEO Satya Nadella worried that OpenAI could become more dominant than Microsoft itself, similar to how Microsoft once overtook IBM in the 1980s. Court testimony revealed that Microsoft invested over $100 billion in OpenAI through investments, infrastructure, and hosting costs, and by the end of 2025, about 45% of Microsoft's cloud business obligations were tied to OpenAI, showing how dependent the company had become on its AI partner.
Microsoft Edge is updating its Copilot AI chatbot to access information from all your open browser tabs, letting you ask questions about tab content, compare products, and summarize articles. Users can choose which features to enable or disable, and Microsoft is replacing the older Copilot Mode (which had agentic features like booking reservations) with this new tab-aware version.
N/A -- This article is about Microsoft's legal positioning in the Musk v. Altman trial and does not discuss any AI/LLM technical issues, vulnerabilities, or security concerns.
A Chinese court ruled that a company wrongfully fired a worker who had been replaced by AI, awarding him over £28,000 in compensation. The case reflects China's attempt to balance rapid AI adoption with worker protections, especially as youth unemployment remains high. Legal experts suggest that while companies can adopt AI technology, they cannot simply fire employees without considering the workers' interests or providing alternatives like retraining.
AI chatbots like Gemini are exposing people's private phone numbers by revealing personally identifiable information (personal details like names and contact info) that was present in their training data, making private contact information much easier for the public to find. Victims have little ability to stop these privacy breaches once their information is already in the AI system.
Fix: The vulnerability has been patched in version 4.6.34. Additionally, users are advised to apply the latest fixes as soon as possible, audit existing deployments, review model provider billing for suspicious activity, and rotate credentials referenced in 'agents.yaml.'
The Hacker NewsFix: Sysdig urged organizations to immediately upgrade to PraisonAI version 4.6.34 or later, which removes the vulnerable legacy API behavior and introduces stronger authentication protections. The researchers also recommended discontinuing use of the legacy "api_server.py" entrypoint entirely. Until an upgrade is possible, defenders were advised to monitor network traffic for requests containing the "CVE-Detector/1.0" user-agent string and suspicious requests targeting /agents, /chat, /api/agents, and related endpoints.
CSO OnlineAI hallucinations are confident but factually incorrect outputs that pose serious security risks, especially in cybersecurity where they can drive automated decisions. Since AI models generate responses based on statistical patterns rather than verified facts, they may cite nonexistent sources or fabricate data while sounding authoritative, potentially leading to missed threats, false alarms, or flawed security decisions. A 2025 benchmark found that most AI models tested were more likely to give a confident wrong answer than a correct one on difficult questions.
Modern AI systems like Anthropic's Claude Mythos Preview are becoming very good at finding software vulnerabilities (weaknesses in code that attackers can exploit), which creates both serious risks and benefits. Attackers could use these AI systems to automatically discover and exploit vulnerabilities in critical systems worldwide, but defenders can use the same technology to find and patch those vulnerabilities before attackers do, ultimately making software more secure long-term.
Fix: The vulnerability was resolved in PraisonAI version 4.6.34. Organizations should update their deployments as soon as possible.
SecurityWeekDeepfake pornography increasingly uses adult content creators' bodies without consent, either by placing other people's faces onto their bodies or by using their work as training data for AI-generated nude images (synthetic sexual imagery created by artificial intelligence). This practice threatens creators' livelihoods, mental health, and safety, as their digital doubles may perform sex acts they never agreed to or be used in scams, while society largely ignores the harm to the bodies being exploited.
Fix: OpenAI implemented safety summaries, which are short, factual notes about earlier safety-relevant context created by a model trained for safety reasoning tasks. These summaries are narrowly scoped, kept only for a limited time, and used only when relevant to serious safety concerns. Additionally, ChatGPT was trained to use this context more carefully to recognize when added caution is needed and respond appropriately by de-escalating, refusing harmful details, or redirecting toward safer alternatives and crisis resources.
OpenAI BlogPalo Alto Networks warns that hackers are increasingly using AI models to find and exploit software vulnerabilities (weaknesses in code that attackers can use), and companies have only 3-5 months to strengthen their defenses before AI-driven attacks become common. Security teams are under pressure as more sophisticated AI models make it easier for attackers to discover previously unknown vulnerabilities faster than companies can fix them.
Fix: Palo Alto Networks announced it will roll out 'virtual patching capabilities' (temporary security measures that block attacks without changing the underlying code) 'very soon.' Additionally, Anthropic limited early access to its Mythos model to a select group of companies, including Palo Alto Networks, CrowdStrike, Amazon, Apple, and JPMorgan, to test and fix vulnerabilities before hackers can exploit them. OpenAI also launched its GPT-5.5-Cyber model and Daybreak cyber initiative to address these threats.
CNBC TechnologyAI chatbots like Google's Gemini and ChatGPT are accidentally revealing people's real phone numbers in their responses, sometimes giving out correct personal information and sometimes generating plausible-sounding but wrong numbers that still reach innocent people. Experts believe this happens because of personally identifiable information (PII, real details about people) in the training data (the information used to teach the AI), though the exact mechanism is unclear. The problem appears widespread and difficult to stop, with privacy removal companies reporting a 400% increase in requests about AI-related privacy concerns over the last seven months.
The 'Mythos Moment' refers to when the speed and volume of AI-assisted cyberattacks exceeded what human security teams could handle. Sweet Security launched Sweet Attack, an agentic AI system (an AI that can plan and execute tasks autonomously) that performs continuous red teaming (security testing where an AI simulates attacker behavior) by maintaining detailed, real-time knowledge of each client's actual infrastructure, rather than relying on theoretical models.
Fix: Sweet Security provides Sweet Attack, which "automatically provides and maintains the full context necessary for Sweet Attack to operate" by continuously indexing runtime data directly from customers' environments, including topology, exposed systems, deployed code, identity paths, and application behavior. The system reevaluates potential attack paths "as soon as any new component appears in the runtime environment," enabling security teams to prioritize which vulnerabilities to fix based on actual exploitability rather than theoretical risk.
SecurityWeek