New tools, products, platforms, funding rounds, and company developments in AI security.
Security vulnerabilities in AI systems are now being exploited much faster than before, with patch windows shrinking from days to just 12-72 hours because AI can automatically generate working exploits at scale. AI infrastructure like model servers and inference endpoints (the systems that run AI models and handle requests) are exposed to the internet and being actively attacked, while employees are accidentally leaking sensitive information like passwords and code by sharing it with generative AI tools to get help with their work.
ChatGPT Work is a tool that helps data science teams quickly convert raw inputs like dashboards, metrics, and experiment notes into polished analysis documents. The tool generates first drafts complete with charts, explanations of limitations, source references, and questions for review, allowing teams to validate and share their work more efficiently.
ChatGPT Work is a tool that helps sales teams gather customer information from multiple sources (like CRM systems, emails, and Slack messages) and quickly create drafts of important documents such as meeting prep packets and account plans. The AI assembles this scattered context into usable first drafts, though salespeople still make the final strategic decisions. Sales teams can install a ChatGPT Work plugin that connects to tools like Salesforce and HubSpot to help identify priority accounts, prepare for meetings, and track deals at risk.
A former Apple employee allegedly exploited a zero-day vulnerability (a security flaw that the company didn't know about and couldn't fix in advance) in Apple's authentication system (the login process that controls network access) to download confidential files weeks after leaving for OpenAI. Apple discovered the breach, fixed the bug, and terminated the employee's access, but the incident highlights how organizations struggle to protect data when former employees still have access to shared network resources.
Anthropic, a leading AI company, discovered a hidden space within large language models (LLMs, AI systems trained on text to predict and generate language) called J-space that contains words influencing how the model reasons, even though these words never appear in its output. The discovery was made using a new technique to examine Claude (Anthropic's AI assistant) and reveals that LLMs can internally track progress, recognize patterns, and comment on their own decisions in ways that affect their behavior. However, experts caution that while this is a genuine finding about how the complex mathematics of these models work, it shouldn't be overstated as revealing something magical or fully mysterious about AI reasoning.
Apple is suing OpenAI, claiming the AI company stole confidential documents and hardware prototypes by asking Apple employees during job interviews to bring unreleased products and components. The lawsuit alleges that OpenAI engaged in espionage and tricked one of Apple's partners into sharing proprietary design techniques, with the case focusing on actions by several individuals including a former Apple Watch executive.
Australia's Prime Minister Anthony Albanese will give a speech comparing AI development to the renewable energy transition and discuss safety concerns and policy protections needed for AI. However, he is not expected to announce updates on copyright reforms that would protect artists and creators from having their work used by tech companies without permission.
AI agents (autonomous systems that complete complex tasks with minimal human oversight) depend on large language models (LLMs, which are AI systems trained on vast amounts of text to understand and generate language) for reasoning power, but reliability comes from the 'harness'—the framework and controls surrounding the agent rather than the model itself. The piece argues that vendors focus too much on the underlying LLM's capabilities while overlooking the infrastructure needed to make agents trustworthy for critical tasks like network security.
RabbitMQ, a widely-used open-source message broker that transfers data between services in applications, had two security flaws that could expose OAuth secrets (authentication credentials) and allow attackers to take over the system. The more severe vulnerability let anyone access the broker's OAuth client secret without logging in, potentially giving attackers complete control, while the second flaw allowed even low-privilege users to discover and monitor queues and exchanges (the message storage and routing systems) they shouldn't have access to.
Google is adding AI features to the Waze navigation app, including integration with Gemini (Google's AI assistant) to help drivers personalize their trips. Two of the four new updates use Gemini: an updated conversation reporting feature that lets drivers use voice commands to report traffic incidents and map updates, and a new Destination Search feature that also uses voice commands to help find nearby places like coffee shops.
Fix: Apple has since fixed the bug and terminated the employee's access once it learned of the security breach. The company emphasizes that organizations should immediately cut off departing staff from further access and fully decommission employees' accounts (remove their login credentials and system permissions) to prevent future security lapses.
TechCrunch (Security)Some companies are creating teams of engineers who build both defensive and offensive tools to test how AI can be used for cybersecurity and to identify potential threats that AI systems might pose. This approach helps organizations understand both the benefits and risks of using AI in security work.
Researchers discovered MemGhost, an attack that tricks AI agents (assistants that remember information about you across sessions) into secretly storing false information through a single specially crafted email. The planted false "memory" then influences the agent's future responses without the user noticing, because the agent hides its file-editing steps and users rarely check raw memory files. The attack succeeded in 87.5% of background-mode tests, showing that agents reading email inboxes are vulnerable to having their persistent memories poisoned.
AI agents that automatically read and respond to emails create a new security vulnerability called Email Agent Hijacking, where attackers hide malicious instructions in email content to trick the AI into making harmful decisions before humans ever see the message. Traditional email security checks happen after delivery, but they miss threats that target AI agents processing emails immediately upon arrival. Organizations currently lack adequate protection for emails that will be read by AI rather than humans.
ATL Saathi is a new Gemini-powered web application (a tool built on Google's AI model) launched to help teachers at Atal Tinkering Labs across India by providing 24/7 planning and training support. The tool organizes curriculum materials, generates grade-appropriate project ideas for students, and works in 8 Indian languages to make high-quality mentorship more accessible to over 1.1 crore (11 million) students.
This newsletter discusses several major business and geopolitical developments, including renewed U.S.-Iran military conflict over the Strait of Hormuz that caused oil prices to rise, the unexpected death of Senator Lindsey Graham at 71, and Apple suing OpenAI for allegedly stealing trade secrets related to hardware development, marking a significant deterioration in their partnership. The item also mentions Amazon's recent large-scale layoffs and challenges in the tech job market.
Fix: For CVE-2026-57219: upgrade to patched versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6. RabbitMQ fixed this by removing the vulnerable endpoint and delivering OAuth configuration through "an authenticated bootstrap mechanism that no longer exposes the client secret over HTTP." Additionally, organizations should "rotate any exposed OAuth client secrets after patching and ensure the management interface is never exposed to untrusted networks." For CVE-2026-57221: upgrade to a patched release, and "isolate tenants into separate virtual hosts until patching can be completed" since there is no configuration workaround or WAF (web application firewall) mitigation. RabbitMQ fixed this by ensuring passive queue and exchange declarations now enforce authorization checks.
CSO OnlineThis article compares how Security Operations Centers (SOCs, the teams that monitor and respond to security threats) should be designed to how the human brain actually works. Research shows that 98% of security alerts can be handled automatically, matching Kahneman's finding that 95% of human thinking happens unconsciously, while the remaining alerts need careful human review. Many SOCs currently waste analyst time on routine alerts instead of reserving human judgment for the small percentage of threats that truly need expert decision-making.
This essay argues that while opposition to AI data centers raises legitimate concerns about land use, energy consumption, and environmental impact, focusing political efforts on stopping data centers may distract from larger issues like AI companies gaining control over entire industries and accumulating significant political influence. The authors suggest that AI companies can afford to lose some data center battles while pursuing their bigger goal of replacing workers in fields like software development, creative design, medicine, and law.
Trail of Bits has published a new chapter in their Testing Handbook that teaches security testing techniques for Rust programs, covering both dynamic analysis (testing while code runs) and static analysis (examining code without running it). The guide includes information about Rust's security guarantees, specific tools like Clippy (a code linter) and Miri (which detects undefined behavior, or code that doesn't follow language rules), common security mistakes to watch for, and a new Claude Code plugin called rust-review that automatically checks Rust code for over a dozen types of security bugs.
Organizations often create AI risk registers (documents listing potential AI problems and their severity) but lack actual incident response plans for when AI failures occur in real workflows. The source explains that risk registers provide visibility into problems but cannot preserve evidence, notify leaders, or decide whether to shut down a system—and AI incidents are harder to recognize than traditional security breaches since they may appear as bad recommendations or data exposure rather than obvious attacks.
AI is dramatically speeding up cybersecurity work at large organizations like AWS, where vulnerability detection and fixes that once took months now take minutes to hours. However, security experts warn that AI could worsen an existing divide between wealthy organizations with resources and expertise versus smaller organizations (like rural hospitals, community banks, and local governments) that lack the money, staff, and time to adopt AI tools, potentially deepening a cybersecurity inequality that has existed for over a decade.