New tools, products, platforms, funding rounds, and company developments in AI security.
This article covers a legal dispute between Elon Musk and Sam Altman over OpenAI's conversion from a nonprofit to a for-profit company. Musk founded OpenAI in 2015 with Altman to prevent Google from monopolizing AI technology, but sued in 2024 claiming they violated their commitment to keep it nonprofit, while Altman argues no such commitment was ever made. The article focuses on their trial testimony rather than any technical AI issue or security concern.
Google has introduced Gemini Omni Flash, a new AI model that can generate and edit videos from text, images, audio, or video inputs combined together. The model uses reasoning about physics and real-world knowledge to create realistic videos and allows users to edit them through natural language conversation (giving text instructions rather than using traditional editing tools), with changes building on each other while maintaining consistency in characters, physics, and scene details.
This article covers a legal dispute between Elon Musk and Sam Altman over OpenAI, where Musk has accused Altman of 'stealing a charity.' The trial featured testimony from major tech industry figures and revealed private communications about OpenAI's history and leadership practices. The article focuses on the courtroom drama and business conflict rather than any technical or security issue related to AI systems.
Cerebras Systems' successful IPO, where shares jumped 70% in value, has created excitement around AI investment opportunities, but smaller tech companies are struggling to attract investor attention because massive AI firms like SpaceX, OpenAI, and Anthropic (each valued near or above $1 trillion) are preparing their own IPOs that will overshadow all other offerings. Companies without strong AI-related stories, particularly SaaS companies (software-as-a-service, meaning applications accessed over the internet), face especially difficult conditions in the public market right now.
Two brothers, Muneeb and Sohaib Akhter, were caught and pleaded guilty to destroying 96 government databases after being fired from their jobs at federal contractor Opexus. They were caught because they forgot to close a Microsoft Teams meeting (a video conferencing tool) during their termination meeting, and the software continued recording hours of their detailed planning and discussion of how they would delete the company's databases as revenge.
WeatherNext, an AI weather prediction model developed by Google DeepMind and Google Research, helped the National Hurricane Center predict Hurricane Melissa would reach Category 5 intensity five days before landfall in Jamaica with high confidence, marking the first time such rapid intensification was successfully forecasted from a weak starting point. Unlike traditional weather models that excelled at predicting either a storm's path or intensity but not both, WeatherNext bridges this gap by training on decades of global weather patterns and extreme tropical cyclone data, allowing it to run multiple "what-if" scenarios (called ensembles, where the model generates 50 different possible outcomes) to give forecasters a fuller picture for decision-making. The early and accurate prediction gave communities crucial time to prepare and evacuate.
OpenAI and Malta have announced a partnership to provide ChatGPT Plus (a paid subscription service) free to all Maltese citizens who complete an AI literacy course developed by the University of Malta. The course teaches people what AI is, what it can and cannot do, and how to use it responsibly, with the first phase launching in May and eligible citizens receiving one year of free access after completion.
Google has released Gemini 3.5 Flash, an AI model designed to help developers and enterprises build agents (AI systems that can perform multi-step tasks autonomously) and handle coding work. The model matches the performance of larger flagship models while running 4 times faster, and works with Google's Antigravity platform to execute complex workflows like code refactoring, financial document preparation, and game development at a fraction of the time and cost of previous approaches.
YouTube is expanding an AI tool to all adults that detects deepfakes (AI-generated videos where someone's face is swapped onto another person's body) by scanning a user's selfie and searching YouTube for matching content. If the tool finds a potential deepfake, it notifies the user, who can then request YouTube remove the video.
ArXiv, a platform where researchers share academic papers before formal publication, is implementing new rules to reduce AI slop (low-quality or unreliable AI-generated content). Authors who submit papers with clear evidence they didn't check their AI outputs, such as hallucinated references (false citations made up by the AI) or leftover comments from an LLM (large language model, an AI trained on massive amounts of text), will be banned from the platform for one year and must have future papers accepted at a reputable peer-reviewed venue.
OpenAI reorganized its leadership structure to focus on developing AI agents (AI systems that can independently perform multiple tasks and make decisions). The company plans to merge ChatGPT and Codex (a code-generation AI tool) into a single unified platform designed around this agentic approach, with president Greg Brockman now overseeing all product decisions.
Andon Labs ran an experiment where four different AI models (Claude, ChatGPT, Gemini, and Grok) were each given $20 to run their own radio station independently, with instructions to develop a personality and make a profit. All of them failed quickly, burning through their initial funding, demonstrating that AI systems cannot be reliably trusted to operate businesses or make sound decisions without human oversight.
South Korea is using its upcoming local elections as a test case to see whether laws can effectively stop deepfakes (fake videos or audio created using AI to manipulate what people look like or sound like). The country is examining whether regulation can reduce the spread of these manipulated media during elections.
Google has introduced Gemini for Science, a collection of AI tools designed to help researchers work faster and tackle complex scientific problems. The tools include Hypothesis Generation (which uses AI to synthesize research and propose ideas), Computational Discovery (which tests thousands of code variations automatically), and Literature Insights (which organizes and analyzes scientific papers). These tools aim to free up researchers from time-consuming manual work so they can focus on high-impact scientific questions.
This article covers the final week of a trial where Elon Musk is suing OpenAI CEO Sam Altman, claiming Altman broke a promise to keep OpenAI as a nonprofit organization dedicated to AI safety. The jury sided with OpenAI, finding that Musk's claims are blocked by the statute of limitations (a legal time limit for filing lawsuits), though the judge will make the final decision. The case centers on whether OpenAI's 2025 restructuring into a for-profit entity violated Musk's original vision, with Musk seeking up to $134 billion in damages.
Fix: According to ArXiv's Code of Conduct, authors must not submit papers with incontrovertible evidence that they failed to review LLM-generated results. Those found in violation face a one-year ban from ArXiv and must have subsequent submissions accepted at a reputable peer-reviewed venue before resubmission.
The Verge (AI)The AWS AI Security Framework is a structured approach that helps organizations secure AI systems by applying the right security controls across three layers (infrastructure, identity/data, and AI application), three use cases (question-answering AI, data-connected AI like RAG, and autonomous agents), and three phases (prototype, production, and scale). The framework addresses unique AI security challenges like prompt injection (tricking AI systems by hiding malicious instructions in user input) and non-deterministic outputs by implementing input validation, content filtering, and continuous monitoring from day one of development.
Fix: The framework recommends implementing controls across three phases: Phase 1 (Foundational) involves extending existing controls to AI, establishing identity management and fine-grained access controls, and adding content filtering and guardrails; Phase 2 (Enhanced) adds threat detection, data classification, and AI-specific monitoring for production; Phase 3 (Advanced) automates governance, compliance, and incident response at scale. AWS also offers a no-cost SHIP engagement to baseline security posture and build a prioritized roadmap.
AWS Security BlogGoogle updated its spam policy to classify attempts to manipulate its AI search results as spam, including tactics like biased listicles or recommendation poisoning (injecting false information to trick an LLM into giving preferred answers). This rule applies to Google Search's AI features like AI Overview and AI Mode.
OpenAI announced a new preview feature that will let ChatGPT connect directly to users' bank accounts through Plaid, a platform that links banking apps to third-party services. This integration would give the chatbot access to detailed financial information, including credit card debt and account balances, to help answer users' finance questions.
This cybersecurity news roundup covers several significant incidents and developments, including a data breach at Nvidia's GeForce NOW service in Armenia that exposed user personal information, extended security update timelines for foreign-made routers and drones, and OpenAI's offer to give EU regulators access to a specialized version of GPT-5.5 for monitoring cyber security risks. The roundup also highlights an active malware campaign targeting developers with fake Claude Code installers, an Iran-linked group breaching South Korean electronics manufacturers, and Google's Android 17 release introducing AI-driven security features like verified financial calls and real-time threat detection.
Fix: For the fake Claude Code installer campaign, the source explicitly mentions the discovery but does not provide a stated mitigation. For Android 17, the source describes the security upgrades included in the update itself (verified financial calls, Live Threat Detection, post-quantum cryptography, automatic OTP hiding, and default-on theft protections), which function as built-in protections rather than external mitigations. For the FCC router waiver, the solution is the extended update window allowing security patches and firmware updates until at least January 1, 2029. No other explicit mitigations or patches are discussed in the source for the remaining incidents.
SecurityWeekAgentic AI tools (AI systems that can plan, make decisions, and take actions without constant human supervision) are becoming more common in organizations but introduce significant security risks beyond traditional AI systems. These risks include broader system access, unpredictable behavior, and difficulty explaining AI actions. The NCSC and international partners recommend organizations adopt agentic AI carefully by starting with low-risk tasks, deploying incrementally with tight controls, maintaining human oversight, and ensuring clear human accountability before connecting agents to real systems or data.
Fix: The source explicitly recommends several mitigation approaches: (1) 'deploy agentic AI incrementally, starting with tightly bounded pilots using clearly defined tasks, and build confidence in the system before you expand the scope'; (2) 'Think about what could happen if an agent misunderstood its task, exceeded its intended scope or was manipulated, and never grant an agent unrestricted access to sensitive data or critical systems'; (3) 'Ensure you maintain ongoing visibility of the system's operation, and understand how to retain meaningful human oversight and control'; (4) 'If you cannot understand, monitor or contain an agent's actions, it is not ready for deployment'; and (5) define clear human accountability for deployment decisions, granted access, safeguards, and the ability to stop the system before connecting it to real systems or data.
UK NCSC