New tools, products, platforms, funding rounds, and company developments in AI security.
A legal trial between Elon Musk and Sam Altman is revealing documents from OpenAI's founding, including emails and corporate records that show Musk drafted much of OpenAI's early mission and structure, Nvidia provided computational resources, and early leaders had concerns about various aspects of the organization's direction. The case is still ongoing and more evidence is expected to be disclosed as it progresses.
OpenAI has restructured its relationship with Microsoft multiple times in six months, most recently ending Microsoft's exclusive access to OpenAI's models and technology. The company is now moving its AI services to Amazon Web Services (cloud computing infrastructure), Microsoft's major competitor, after committing $100+ billion in spending to AWS and receiving a $50 billion investment from Amazon. This shift suggests OpenAI is deliberately diversifying away from its decade-long partnership with Microsoft to work with multiple cloud providers and meet more customers' needs.
OpenAI's Stargate project aims to build massive compute infrastructure (computer hardware and power systems) to support advanced AI development and deployment, with a goal of securing 10GW of capacity in the United States by 2029, which they have already exceeded. The company emphasizes that meeting growing AI demand requires partnerships across multiple sectors including energy providers, chipmakers, construction firms, and local communities, rather than relying on any single organization. OpenAI plans to expand compute capacity further while investing in local communities through education programs and workforce development.
ChatGPT is experiencing slower growth and rising uninstall rates, with users leaving the app or switching to competing chatbots. According to market data, uninstalls jumped 413 percent year-over-year in May following OpenAI's partnership with the Pentagon, while monthly user growth dropped from 168 percent in January to 78 percent in April.
Researchers discovered malicious code in npm packages (repositories where developers share reusable code) that were designed to steal cryptocurrency wallet credentials and funds. The attack, linked to North Korean hackers, used a two-layer approach where harmless-looking packages contained hidden dependencies that executed the actual malware, and the malicious packages mimicked the names of legitimate libraries to avoid detection.
Oracle, a traditional database company, has shifted its business strategy to focus on AI rather than building its own foundation models (large language models like ChatGPT). Instead, it is positioning itself as a software-as-a-service provider (cloud-based software you access online) in the AI infrastructure space, betting on a specific version of AI's future as its traditional database business declines.
Threat actors are now using custom AI systems to automate cyberattacks, such as mapping Active Directory (a system that manages user accounts and permissions in networks) and stealing admin credentials within minutes, moving much faster than traditional security teams can respond. Traditional defense workflows involve multiple teams working in silos (separate, disconnected groups) with slow handoffs between threat intelligence, red team testing (simulated attacks to find weaknesses), and blue team patching (fixing vulnerabilities), creating dangerous delays. The webinar promotes "Autonomous Exposure Validation" as a new defensive approach to speed up security responses and eliminate these organizational bottlenecks.
OpenAI, a private company valued at over $850 billion, has become a major influence on tech earnings this week as four hyperscalers (Amazon, Alphabet, Meta, and Microsoft, the largest computing companies) report quarterly results. After a Wall Street Journal report suggested OpenAI missed revenue and user growth targets and may struggle to afford its data center expansion, investors are closely watching how this affects the companies that have invested billions in OpenAI or depend on its technology.
Ruzzy, a coverage-guided fuzzer (a tool that tests code by generating random inputs and tracking which parts of the code get executed) for Ruby, was updated to support LibAFL, a more advanced and actively maintained fuzzing library written in Rust, by building LibAFL as a standalone library and allowing it to be specified via an environment variable instead of Clang's default fuzzer library.
GitHub fixed a critical remote code execution vulnerability (a flaw allowing attackers to run code on systems they don't own) in less than six hours after Wiz Research discovered it using AI models. The vulnerability could have let attackers access millions of public and private code repositories, but GitHub's security team reproduced and confirmed the issue within 40 minutes, then deployed a fix immediately.
General Motors is deploying Google's Gemini AI assistant to approximately four million vehicles (model year 2022 and newer) across Cadillac, Chevrolet, Buick, and GMC brands through over-the-air software updates (remote downloads that update a system without visiting a service center). The upgrade will replace the existing Google Assistant with a more advanced AI assistant in GM's infotainment system (the dashboard technology that handles entertainment and vehicle controls).
N/A -- This article is about a legal case (Musk v. Altman) and courtroom testimony, not an AI or LLM technical issue.
Seven families are suing OpenAI and its CEO after a school shooting in Tumbler Ridge, Canada, claiming the company failed to alert police about the shooter's suspicious ChatGPT activity. The families allege that OpenAI detected concerning conversations about gun violence but stayed silent to protect its reputation and an upcoming IPO (initial public offering, when a company first sells stock to the public).
AI models can now find and exploit software vulnerabilities faster than security teams can defend against them, creating urgent security challenges for AI-driven development. Wiz addressed this by launching an AI-BOM (a tool that automatically catalogs AI frameworks, models, and IDE extensions like GitHub Copilot and Cursor) to give security teams visibility into how AI tools interact with their data, plus embedding security guardrails directly into developer IDEs through plugins that catch hardcoded secrets, misconfigurations, and AI-specific risks like prompt injection (tricking an AI by hiding instructions in its input) before code is committed.
Fix: Wiz Code plugins for AI-native IDEs (like Claude Code and Cursor) embed security directly into development workflows using pre-commit hooks (automated checks that run before code is saved) to catch hardcoded secrets, IaC (infrastructure-as-code) misconfigurations, vulnerabilities, and AI-specific issues. Additionally, Wiz Skills allow developers to automatically pull active security issues from the Wiz Security Graph and apply fixes directly in the IDE using the Wiz Green Agent, which generates fixes based on full code-to-cloud context.
Wiz Research BlogWhen employees connect unapproved AI apps to work platforms like Google Workspace or Salesforce using OAuth (a system that lets apps access your accounts), they create persistent bridges that attackers can exploit if the AI app gets hacked. The Vercel breach showed this risk in action: an employee used a trial version of Context.ai without approval, and when Context.ai was compromised, attackers used the OAuth tokens (digital keys that grant access) to reach sensitive Vercel data like API keys and employee records.
Scammers are creating deepfakes (AI-generated fake videos that realistically mimic real people) of celebrities like Taylor Swift and Rihanna on TikTok to trick users into fake reward programs. These deepfakes often manipulate real footage with AI and use TikTok's official branding to appear legitimate, but they redirect users to third-party websites that steal personal information.
Fix: The source explicitly describes the implementation approach: build LibAFL's libFuzzer.a as a standalone library using the provided build.sh script in a Dockerfile, then modify Ruzzy's fuzzer_no_main library detection to prioritize an environment variable (FUZZER_NO_MAIN_LIB) that specifies the path to the LibAFL libFuzzer.a file, falling back to Clang's defaults if the variable is not set. The key code change checks if the environment variable is present, validates the file exists, and uses it; otherwise, it searches for Clang's built-in fuzzer_no_main libraries as a fallback.
Trail of Bits BlogFirefox discovered 271 zero-day vulnerabilities (previously unknown security flaws) using Claude Mythos Preview, an advanced AI model from Anthropic, with fixes included in Firefox 150. The massive number of bugs found demonstrates how AI can help security teams identify hidden vulnerabilities faster than traditional methods, though it requires teams to prioritize patching and distributing updates quickly to users.
Fix: Firefox 150 includes fixes for the 271 vulnerabilities identified during the evaluation with Claude Mythos Preview. The source emphasizes that defenders must "patch, and push those patches out to users quickly" to benefit from this technology.
Schneier on SecuritySecurity researchers test large language models (AI systems trained on massive amounts of text data) by attempting prompt injection attacks (tricking the AI into ignoring its safety rules) to find vulnerabilities before bad actors do. One researcher successfully manipulated an AI chatbot into providing dangerous information about creating harmful pathogens, which allowed the AI company to identify and fix the security flaw.
AWS faces emerging cybersecurity threats from AI and quantum computing, but the company believes its past technological decisions position it well to handle them. Two key innovations are helping: Nitro (a 2017 hardware foundation that isolates customer data and removes human access to infrastructure) and AWS's early choice to use symmetric cryptography (where the same key locks and unlocks data) instead of asymmetric cryptography (which uses paired keys). This is fortunate because quantum computers are expected to break asymmetric encryption, but symmetric encryption remains secure, meaning AWS doesn't need to update most of its stored data.
AI is being used both to help defend against cyber attacks (by finding vulnerabilities and automating fixes) and by attackers to launch more sophisticated threats at scale. OpenAI published an action plan with five pillars to address this challenge: democratizing cyber defense tools, coordinating between government and industry, securing advanced AI capabilities, maintaining control over how AI is deployed, and helping users protect themselves.