New tools, products, platforms, funding rounds, and company developments in AI security.
The article warns that AI models which are allowed to both understand user requests and carry out those requests without human review create a serious security risk. When AI systems operate without oversight (checking and approval by humans), it removes important safeguards that normally protect computer systems from being misused or attacked.
This week's cybersecurity news covers multiple incidents including breaches at telecom and retail companies, a German manufacturer forced into bankruptcy after a six-week cyberattack shutdown, and the discovery of CrashStealer, a new macOS malware (malicious software) that disguises itself as a crash reporting tool to steal user credentials and system data. Additional threats include Iranian actors using cellular and advertising data to track US military phones, and a vulnerability in an AI agent integrated with WhatsApp that allows remote code execution (running commands on a system from afar).
This is a browser-based tool that identifies and highlights clichéd phrases commonly found in AI-generated text, such as "no X, no Y" chains and expressions like "sit with that." Users can paste text into the analyzer to spot these patterns, toggle detection on or off, and navigate through matches, with the tool storing data locally in the browser.
The European Commission ordered Google to give rival AI assistants the same access to Android device features that Google's own Gemini assistant has, including the camera, microphone, screen contents, and the ability to control other apps in the background. Google must implement this by August 1, 2027, in Android 18, with some features (like always-on voice detection) delayed to Android 19 by August 1, 2028. The order also requires Google to share anonymized search data with competing search engines and AI chatbots for a cost-based fee.
This article discusses how businesses should measure the success of their AI investments using a metric called 'Useful Intelligence per Dollar' rather than traditional software metrics like adoption or cost per token (the price charged for processing units of text). The key insight is that true AI value comes from measuring the total cost of completing actual work tasks successfully against the value those tasks create, accounting for factors like human review time, retries, and the likelihood of getting the right answer on the first try.
Moonshot AI, a Chinese startup, released its Kimi K3 model, which it claims performs competitively with leading AI systems from OpenAI and Anthropic, though it still trails their most advanced offerings overall. The model, containing 2.8 trillion parameters (adjustable numbers that determine how an AI model behaves), achieved strong performance on benchmarks despite hardware constraints in China. This release reflects intensifying competition between U.S. and Chinese AI companies, as Chinese models are becoming cheaper alternatives and gaining adoption among Western businesses.
Microsoft CEO Satya Nadella criticized Anthropic's Fable AI model for being "editorially controlled," saying it refuses too many user requests and doesn't function like a proper creation tool. Anthropic has acknowledged the issue, stating that its safeguards for Fable flag a slightly higher fraction of harmless requests than intended, and the company said it was trying to reduce false positives when it released Fable 5 in June.
A flaw in Anthropic's Claude Chrome extension allows a malicious extension to trigger Claude's predefined AI workflows by simulating user clicks, potentially abusing Claude's access to Gmail, Google Docs, Google Calendar, and Salesforce. The vulnerability exists because the Claude extension accepts JavaScript-generated click events without verifying they came from a real user by checking the Event.isTrusted property (a browser flag that distinguishes genuine user actions from programmatically created ones). An attacker would need to trick a user into installing a malicious extension that can then execute these workflows without the user's knowledge.
Alphabet's Gemini 3.5 Pro AI model is delayed by months because the company wants to improve its performance, especially its ability to generate software code, which fell short of internal expectations. The delay comes as competitors like OpenAI and Meta have released newer AI models that outperform Google's current offerings at code generation, causing Alphabet's stock to drop 4%.
This newsletter covers various business and economic news items, including Fed statements on inflation, United Airlines' earnings warning about high fuel costs, and UnitedHealth Group's investment of $1.5 billion in artificial intelligence to improve operational efficiency. The content does not focus on AI security issues or technical vulnerabilities.
Google is renaming its AI note-taking app from NotebookLM to Gemini Notebook, though it will continue operating as a separate application. The app, originally called Project Tailwind when announced in May 2023, has added features over time that use AI to help organize and summarize notes, including converting them into AI podcasts and video clips.
Google introduced Gemini 3.5 Flash Cyber, a lightweight AI model specialized in finding, validating, and fixing software vulnerabilities (flaws in code that attackers could exploit). The model is being released through a limited-access pilot program exclusively to governments and trusted partners via CodeMender (Google's code security agent) to help defenders fix vulnerabilities before attackers can use them, while restricting access to prevent misuse.
The European Union ordered Google to open Android (its mobile operating system) to rival AI assistants like competitors to Gemini, giving them equal access to apps and system services to increase competition. Google warns this could create security risks, while security experts worry that multiple AI agents with deep system access could break traditional security models where the operating system controls what different programs can do.
This podcast features an interview about agentic AI (AI systems that can autonomously plan and execute tasks) and governance challenges in cybersecurity. The discussion includes the MindStone Agent, an open-source project that adds persistent memory and identity to AI assistants, and demonstrates how autonomous AI agents can coordinate incident response (the process of identifying and fixing security breaches) and recovery with minimal human oversight.
Google Cloud has built an agentic defense platform (a system that uses AI agents to automatically handle security tasks) that incorporates technology from Wiz to detect and fix threats from AI-based attacks. The approach aims to automate both finding and responding to threats faster than attackers can operate.
Fix: Google must create a Qualified AI Assistant Programme that uses independent Trusted Certification Authorities (TCAs) to certify third-party AI assistants for access to restricted features, and must accept these certifications without adding extra conditions. Google can set reasonable and non-discriminatory terms for the TCA programme but must get Commission approval two months before any changes. For the six unrestricted features (microphone input, hotword detection, camera, screen contents, location, and sensors), Google cannot decide who is allowed to access them, though it can require process isolation and encryption. Google can request the Commission move a feature to the restricted list by filing a reasoned request showing good cause.
The Hacker NewsSenior executives are using shadow AI (unapproved AI tools not officially authorized by their company) at nearly twice the rate of lower-level employees, even though most know it creates security and data privacy risks. The problem stems not from ignorance but from executives choosing speed over compliance, and from approved tools being less useful than mainstream alternatives.
Fix: According to the source, IT leaders should focus on "providing secure AI tools that people actually want to use" through "executive alignment, clear governance, and providing secure AI tools that people actually want to use." Additionally, organizations need to "pair governance with usability" and ensure that "the secure path the easiest path" by providing approved tools that "grant users full access to the necessary systems and data, eliminating the need to choose between a capable but ungoverned tool and a safe but limited one."
CSO OnlineAgentic AI (artificial intelligence systems that can independently plan and take actions to accomplish goals) presents significant security risks that organizations need to address, regardless of external attackers. The article argues that the security challenges posed by agentic AI are substantial enough to require a fundamental rethinking of how organizations approach AI safety.
Over one million emails have used a technique called text salting (hiding extra characters or text that humans don't see but can confuse AI systems) to bypass AI-based email security filters, allowing phishing emails (messages designed to trick people into revealing sensitive information) to reach inboxes undetected. The research shows that AI and LLMs (large language models, which are AI systems trained on massive amounts of text) are surprisingly weak against this evasion method.
AI agents can perform multi-step tasks across multiple systems without individual human approval for each step, which creates identity and authorization challenges. When agents operate without proper managed identity (a secure way to identify an agent) and least-privilege RBAC (role-based access controls, which limit what each agent can do), they may access or modify sensitive data beyond their intended permissions. Organizations are deploying these agent capabilities faster than their security models can evolve, leading to risks like unauthorized data access, unintended modifications, and gaps in auditability (the ability to track who did what).
Fix: The source recommends treating every agent as a first-class principal: give it a lifecycle-managed identity, assign explicit roles, scope its permissions tightly, and scope tool usage to a preconfigured tools manifest or configuration. The text also states that implementing multiple controls is intended to help reduce potential impact of agent actions while making privilege decisions explicit and supporting accountability. However, the source does not provide specific technical implementation steps, version numbers, or detailed patches beyond these architectural principles.
Microsoft Security BlogTeens are increasingly using AI tools like ChatGPT for learning and productivity, and denying them access would leave them unprepared for a defining technology of their time. OpenAI has implemented protections specifically for teens, including automated guardrails (safety rules that trigger automatically), age prediction, parental controls, and learning features like Study Mode (a tool that guides students through problems step-by-step with questions rather than just giving answers) to help them benefit from AI safely.
Fix: OpenAI has introduced several protections for teens: (1) automatic age-appropriate experience adjustments when the system estimates a user is under 18, (2) Study Mode designed with teachers and learning experts to encourage active engagement through guided questions and structured explanations rather than direct answers, (3) Parental Controls allowing parents to enable Study Mode by default for linked teen accounts, (4) education-focused starter prompts for common learning tasks, (5) interactive learning experiences for math and science topics, and (6) a pronunciation feature using audio for language learning.
OpenAI Blog