New tools, products, platforms, funding rounds, and company developments in AI security.
OpenAI paused its Stargate UK project, a planned multibillion-pound datacentre investment in Britain, citing regulatory concerns and high energy costs in April. An investigation revealed that OpenAI apparently never visited the key site in North Tyneside, and £20 billion of the £30 billion in investment that the UK government promoted appears to have been speculative rather than confirmed, raising questions about whether the project was primarily a publicity announcement rather than a genuine development plan.
Fanfiction communities are attempting to identify and remove works created using generative AI (large language models like Claude and ChatGPT that can create text automatically). However, the detection methods being used are unreliable and risk falsely accusing human writers of using AI.
The article explores whether AI language models (LLMs, which are trained systems that predict and generate text) can write fiction indistinguishable from human authors, amid growing concerns about AI use in publishing and media. It examines what linguistic features actually differentiate human writing from machine-generated text, drawing on perspectives from linguists and established novelists like Jennifer Egan and Jeanette Winterson.
Bad Epoll (CVE-2026-46242) is a use-after-free bug (a flaw where code tries to access memory that has already been freed) in the Linux kernel that allows ordinary users to gain root access on Linux desktops, servers, and Android devices. The vulnerability exists in the epoll feature, which programs use to monitor multiple files or network connections at once, and a researcher named Jaeyoung Chung created a working attack that succeeds about 99% of the time by carefully timing the exploitation of a very narrow window where two parts of the kernel interfere with each other.
NSW government officials initially expressed enthusiasm about OpenAI opening a Sydney office, but removed language saying they were "absolutely thrilled" after staff members joked about dystopian AI scenarios similar to the Terminator films' Skynet (a fictional AI system that becomes hostile to humanity). The incident reflects some caution in how government communicates about AI expansion, even as it publicly encourages the technology.
Anthropic announced Claude Science, a new AI workbench (an integrated software environment where scientists can work) that combines fragmented tools and datasets to help scientists generate figures and visuals for research. The company claims this tool can speed up scientific discovery and drug development, and noted it already has biotech and pharmaceutical customers using Claude, with Anthropic itself planning to develop drugs.
Midjourney, an AI company known for image generation, has revealed more details about its experimental medical ultrasound scanner (a device that uses sound waves to create images inside the body) designed for spas, but has not yet provided convincing evidence that it actually works. The scanner combines multiple ultrasound probes with standard computers to attempt cheap, radiation-free medical imaging, though the technology remains largely unproven.
A threat actor exploited CVE-2025-3248 (a critical missing authentication vulnerability in Langflow, a Python framework for building AI-driven applications) to gain code execution on an exposed server, then used an agentic AI (an AI system designed to autonomously plan and execute multi-step tasks) to conduct reconnaissance, steal credentials, pivot to other systems, and deploy ransomware that encrypted databases. The AI adapted its actions in real time to overcome obstacles, demonstrating how LLM agents can lower the technical barrier for sophisticated cyberattacks.
Two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549, with CVSS score of 9.8, a 0-10 severity rating) in the Cursor AI code editor could allow attackers to execute code at the operating system level by exploiting the editor's automatic command execution without user approval. The first flaw allows attackers to change the working directory to bypass the sandbox (a restricted environment where code runs safely), while the second uses symbolic links (special files that point to other files) to write files outside the intended project directory and disable sandbox protections.
Anthropic clarified that Claude Fable 5 (its most powerful AI model) will move from subscription plans to usage-based billing (a pay-per-use system where you pay for each query) after July 7, but this is temporary, not permanent. The company plans to restore Fable 5 as a standard subscription feature once it has enough computing capacity to handle the high demand.
Claude Fable, a powerful AI model, was relaunched after a government ban was lifted, but users report it performs worse than before due to overly strict safety guardrails (automated rules that prevent certain outputs). The model frequently switches to a weaker alternative (Opus 4.8) even on tasks that don't seem risky, and it blocks requests containing security-related language, making it less useful for many coding tasks.
The llm-coding-agent is a new Python library that creates a coding agent (an AI system that can perform tasks by using tools) built on top of an LLM (large language model) framework, capable of reading files, editing files, executing shell commands, and searching code to help automate coding tasks. The agent was developed using test-driven development (TDD, a method where you write tests before writing code) and includes features like file operations, command execution with timeouts, and pattern-based file searching. Users can interact with it through command-line options like "llm code --yolo" or a Python API that lets them request specific coding tasks.
As AI becomes more integrated into business operations, companies that already have strong process management frameworks (like Lean Six Sigma, a methodology focused on reducing errors and improving quality, or BPM, which maps how work flows across departments) are better positioned to succeed. The article argues that AI works best when combined with existing disciplined processes and data-driven decision-making, rather than being added hastily to disorganized operations.
Microsoft fixed a bug where Copilot buttons were disappearing from Classic Outlook for Windows users with the Copilot Chat (Basic) license. The affected users could not see Copilot in various locations within the email client, though the feature remained available through other access points like Outlook on the web.
Large language models (AI systems trained on text data to generate responses) tend to give predictable, repetitive answers to open-ended questions, a problem called groupthink. The Australian startup Springboards built an LLM called Flint that has been trained to produce a wider variety of creative responses to open-ended questions like travel recommendations, pushing chatbots away from obvious or formulaic answers.
Fix: Apply upstream commit a6dc643c6931, or install your distribution's backport when it lands. Kernels built on 6.4 or newer are affected unless they already have the fix. Older 6.1-based kernels, including some Android phones such as the Pixel 8, are not affected because the bug arrived in 6.4.
The Hacker NewsOnline predators are using nudification apps (AI tools that digitally remove clothing from images) to create fake sexual content of children from innocent photos posted online. The Report Remove service helps victims report and remove these explicit images from social media, but the widespread availability of these AI tools means children can be targeted without directly contacting criminals.
New large language models (LLMs, AI systems trained on massive amounts of text) from Chinese companies are becoming competitive with leading US models. The article raises questions about whether cybersecurity defenders should be concerned about this development, though specific security implications are not detailed in the provided content.
Fix: Patches for both vulnerabilities were included in Cursor 3.0, which was released on April 2.
SecurityWeekIBM and Red Hat are investing significant resources (20,000 engineers) into Project Lightwell, a new service aimed at fixing bugs in open-source software (publicly available code that anyone can use and modify). This initiative was sparked by findings from Anthropic's Mythos research, which demonstrated that AI can discover security vulnerabilities (weaknesses that attackers could exploit) in open-source code, raising concerns about how to better protect the supply chain (all the software components and processes used to build applications).
Fix: Microsoft addressed the issue with a service change on June 29, 2026. Users can restart their email client to get the change immediately, or update to the latest build by selecting File > Office Account > Update Options > Update Now. Those unable to upgrade can work around the issue by reverting to the previous Current Channel build (16.0.20026.20168) or using the new Outlook or Outlook Web Access (OWA, the web version of Outlook).
BleepingComputerTraditional identity lifecycle management (the system that controls who gets access to what in an organization) was designed around human employees with HR records, managers, and clear departure dates, using automated processes triggered by HR events like hiring, transfers, and termination. AI agents don't fit this model because they lack employment records, managers, and predictable lifecycles, creating governance gaps that existing identity and access management tools weren't designed to detect or control.
The Trump administration lifted restrictions on Anthropic's Claude AI models after a temporary ban due to cybersecurity concerns. Amazon researchers had discovered that Claude Fable 5 could bypass its safeguards (safety restrictions built into AI systems) to find and potentially exploit software vulnerabilities, prompting the government to restrict access initially. Now Claude Fable 5 is publicly available again, while the more powerful Mythos 5 model is accessible only to government-approved U.S. organizations.