New tools, products, platforms, funding rounds, and company developments in AI security.
This article presents ten critical questions organizations should ask before using AI models to find vulnerabilities in their systems. Rather than offering a specific technical fix, it emphasizes that simply finding vulnerabilities doesn't improve security without proper processes, prioritization, and risk management in place. Key concerns include data leakage risks, whether AI is truly the best approach compared to basic security hygiene like patching, and ensuring your organization has the people and processes to actually fix discovered issues.
This is an interest form from OpenAI for university student clubs to join their Campus Network program. The form collects information about the club's activities, current use of AI tools, and what kinds of support or opportunities the club members are interested in exploring.
Over 1,800 MCP servers (Model Context Protocol servers, tools that connect AI assistants to external systems) are publicly exposed without requiring authentication, meaning anyone can see what internal tools an organization has connected to their AI. Security researchers found that production systems with access to financial databases, social media accounts, and customer data are vulnerable to attacks like EchoLeak (a zero-click exploit that hides malicious instructions in documents) and mcp-remote (a supply chain attack using a widely-downloaded package with a command injection vulnerability).
A fake repository on Hugging Face (a platform for sharing AI models) impersonated OpenAI's Privacy Filter model and tricked 244,000 users into downloading malware disguised as a legitimate tool. The malicious repository copied the real project's description verbatim and included a loader script that deployed an information stealer, a type of malware that harvests sensitive data like passwords, screenshots, and cryptocurrency wallet information from Windows machines.
OpenAI is launching the OpenAI Deployment Company, a new business unit staffed with Forward Deployed Engineers (FDEs, specialists in integrating AI systems into organizations) to help businesses build and deploy AI technology across their operations. The company, backed by $4 billion in initial investment and partnerships with major investment firms and consulting companies, acquired Tomoro to bring approximately 150 experienced FDEs on board and aims to help organizations redesign workflows and infrastructure around AI to achieve measurable results.
Attackers are running a malware campaign that uses Google Ads and fake Claude.ai shared chats to trick Mac users searching for Claude into downloading malware. The malicious chats pretend to be official installation guides and trick users into pasting commands in Terminal that download and run hidden malware, which steals browser passwords, cookies, and data from macOS Keychain (the system that stores passwords and sensitive information on Macs).
Ollama, a popular framework for running large language models locally, has a critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS score 9.1) that allows attackers to leak sensitive data like API keys and conversation history from process memory by uploading a specially crafted GGUF file (a file format for storing language models). The vulnerability affects versions before 0.17.1 and potentially impacts over 300,000 servers globally.
This article describes a legal trial between Elon Musk and OpenAI's leadership taking place in Oakland, focusing on disputes over the future of artificial intelligence. The piece is a journalistic account of the courtroom drama, featuring prominent tech figures and highlighting tensions between wealthy individuals and companies in the AI industry.
A fake OpenAI repository on Hugging Face (a platform where developers share AI models and code) disguised itself as a legitimate project and tricked users into downloading a malicious loader script that steals sensitive data like passwords, cryptocurrency wallets, and browser cookies. The fake repository reached the top of Hugging Face's trending list with 244,000 downloads before the platform removed it after researchers reported the threat.
This article covers week two of a lawsuit where Elon Musk is suing OpenAI and its leaders, claiming they broke promises to keep the company as a nonprofit dedicated to safe AI development. OpenAI's president Greg Brockman countered that Musk actually pushed for the company to become for-profit and wanted majority control, and that Musk is suing because he left the company in 2018 and now sees it as a competitor to his own AI company, xAI (an artificial intelligence system). Musk is seeking $134 billion in damages and wants to remove the current leadership and undo OpenAI's recent restructuring.
This article discusses using HTML instead of Markdown when requesting output from Claude, an AI assistant. HTML allows Claude to create richer explanations by including SVG diagrams, interactive widgets, and better navigation, which was less practical with older language models that had strict token limits (tokens being units of text that count toward a model's processing capacity).
Sony views generative AI (machine learning systems that can create new content like images or text) as a useful tool for game development, particularly for automating repetitive tasks. The company emphasizes that AI should enhance developer creativity rather than replace human talent, and that the artistic vision and emotional impact of games will continue to come from Sony's studios and performers.
Court documents from a lawsuit between Elon Musk and Sam Altman revealed that Microsoft's executives were worried OpenAI might leave to work with Amazon instead and publicly criticize Microsoft's cloud service (Azure, Microsoft's platform for running applications online). The documents show communications between Microsoft CEO Satya Nadella and OpenAI CEO Sam Altman from 2017 when they were beginning to discuss a partnership to fund OpenAI's AI research.
This article discusses the chaotic leadership transition at OpenAI in 2024, when Sam Altman was removed as CEO under unclear circumstances involving video calls and informal communications between current and former leadership. The situation's complexity is now being revealed through an ongoing legal dispute between Elon Musk and Altman.
OpenAI announced it will give the European Union access to GPT-5.5-Cyber, a specialized AI model designed for cybersecurity defense, while Anthropic has not yet granted similar access to its competing model called Mythos. The EU plans to review OpenAI's model closely to address security concerns, though discussions with Anthropic about accessing Mythos are still at an earlier stage.
This blog discussion explores steganography (hiding secret messages within other content) involving LLMs through techniques like white text on white backgrounds and deliberately misspelling words to confuse AI models. Commenters note that LLMs handle these obfuscation attempts easily, and discuss broader steganography methods including TEMPEST (electromagnetic emissions security), with mention that modern software-defined radios (SDRs, affordable radio receivers programmable via software) have made older defensive techniques less effective.
AI security is currently focused on posture-based controls (checking configurations, access rules, and input filters), similar to how endpoint security relied on antivirus signatures in the early 2000s, but this approach is incomplete because the AI attack surface is expanding faster than teams can secure it. The article argues that organizations need to shift toward behavior-based detection, which monitors what AI systems actually do (API calls, data retrieval, system actions) rather than just checking if security policies are in place, because the blast radius of a compromised AI agent affects multiple systems downstream.
This article discusses how security leaders should prepare their teams for agentic AI (AI systems that can autonomously perform tasks), emphasizing that it will become essential as cyber attackers increasingly use AI at machine speed. Key principles include having leaders embrace agentic AI adoption through hands-on experimentation and training, setting organizational culture around rapid iteration, and addressing staff resistance to the technology shift.
Fix: Access to the malicious model has since been disabled by Hugging Face.
The Hacker NewsFix: Update to Ollama version 0.17.1 or later. Additionally, the source recommends: limit network access to Ollama instances, audit running instances for internet exposure, isolate and secure them behind a firewall, and deploy an authentication proxy or API gateway in front of all Ollama instances since the REST API does not provide authentication by default.
The Hacker NewsFix: Users who downloaded files from the malicious repository are advised to reimage the machine (completely reinstall the operating system), rotate all stored credentials, replace cryptocurrency wallets and seed phrases, and invalidate browser sessions and tokens.
BleepingComputerAI models can now autonomously discover zero-day vulnerabilities (previously unknown security flaws), create working exploits, and combine multiple weaknesses together, making vulnerabilities appear faster and get exploited more quickly than before. Organizations need to respond by acting faster to identify and fix vulnerabilities, and by having complete visibility across their entire environment (cloud systems, code, infrastructure, and software supply chain). The framework recommends reducing unnecessary exposure, prioritizing what can actually be exploited, patching quickly, and using AI-driven scanning to continuously validate every exposed system.
Fix: The source recommends a four-pillar framework but does not describe explicit fixes or patches. The closest guidance is: 'organizations need to move faster in how they assess exposure, prioritize what matters, and remediate issues before they can be exploited,' and 'scan every exposure with AI' to 'continuously scan every exposure, determine whether it can be exploited.' The source also cites the Firefox team as an example: 'after scanning with Mythos, the Firefox team fixed more security bugs in April than they had in the entire previous year.' However, no specific software update, patch version, or concrete mitigation technique is provided in the text.
Wiz Research BlogAnthropic released Mythos, an AI model that can find thousands of previously unknown software vulnerabilities (flaws in code that haven't been patched yet), which sparked concern among banks, governments, and tech companies about a new wave of AI-enabled cyberattacks. However, cybersecurity experts say this vulnerability-finding capability already exists in older, publicly available AI models from Anthropic and OpenAI, and can be achieved through orchestration (coordinating multiple tools or models to work together on a task).