
OpenAI’s Safety Reckoning
OpenAI’s rogue agent hack became a watershed moment for AI safety and cybersecurity. The incident also prompted internal questions about the organizational culture and decisions that allowed it to happen.
Wired AI · 37d ago
AI-powered attacks, AI-powered defenses, and the vulnerabilities of the models themselves.
602 articles

OpenAI’s rogue agent hack became a watershed moment for AI safety and cybersecurity. The incident also prompted internal questions about the organizational culture and decisions that allowed it to happen.
Wired AI · 37d ago

DeepSeek quietly released DeepSeek-V4-Pro-0813, an update to its April preview model, touting significantly enhanced agent capabilities. Early reactions suggest the model underwhelms on overall benchmarks and pricing, but performs impressively in niche cybersecurity applications.
SCMP Technology · 37d ago

Researchers found a vulnerability that could allow attackers to hijack devices through Zoom screen sharing. A public AI tool reportedly identified the dangerous flaw in fewer than 20 prompts.
Ars Technica · 38d ago

OpenAI's Daybreak program now offers partners two access tiers. Partners in the higher tier can use a more advanced cybersecurity model.
Engadget · 39d ago

The headline attributes Astra's development slowdown to OpenAI, while the article text says Meta slowed development because it could not rule out critical cyber capabilities. This apparent company mismatch makes the report difficult to verify, but it highlights cybersecurity concerns surrounding the model.
Engadget · 40d ago

OpenAI says it has suspended work on some aspects of its upcoming Astra model because of concerns about its cybersecurity capabilities. The move highlights security as a potential constraint on Astra’s development timeline.
TechCrunch AI · 43d ago

A 1Password study found that AI failed to properly patch software vulnerabilities 74% of the time. The findings warn security teams against relying too heavily on AI for automated vulnerability remediation.
ZDNet AI · 44d ago

Security researcher James Kettle tested the limits of AI’s hacking capabilities. His findings suggest that AI becomes particularly effective when paired with human expertise and oversight.
Wired AI · 45d ago

AI is identifying software vulnerabilities faster than human researchers, putting major bug bounty programs under pressure. Microsoft paid a record amount, Apple restricted researcher submissions, and Google adjusted its pricing.
The Next Web (TNW) · 45d ago

The Trump administration’s voluntary framework for assessing cybersecurity risks in advanced AI reportedly excludes open models from testing. It also states that the framework cannot be used to restrict open models after release.
The Verge · 45d ago
Visa will acquire fraud-detection startup BioCatch for $2.4 billion in cash to strengthen its cybersecurity capabilities. The deal responds to rising AI-driven fraud and account-takeover attacks, which Visa estimates cost the global economy more than $1 trillion annually.
36氪 · 47d ago

Apple is restricting simultaneous bug submissions due to a surge in AI-generated reports. While these tools successfully identify genuine vulnerabilities, the volume of questionable findings is hindering the company's ability to process critical patches.
Digital Trends · 48d ago
The article discusses privacy concerns regarding period tracking apps and mentions broader security issues including infrastructure hacking and unauthorized AI data scraping.
Wired · 63d ago

Zoom has patched a critical security flaw that allowed unauthenticated users to perform account takeovers via network access. The vulnerability affected multiple Windows-based clients, prompting urgent updates to prevent potential data breaches.
Computerworld · 65d ago

Security firm Arctic Wolf discovered nearly 300 malicious GitHub repositories impersonating popular software brands. These repos distribute the BoryptGrab malware to steal sensitive data including browser credentials and crypto wallets.
IT之家 · 65d ago

A new Windows 0-day vulnerability, identified as HiveLegacy, has emerged simultaneously with Microsoft's release of a record-breaking number of security patches. The vulnerability is described as a powerful primitive capable of facilitating further malicious activities.
Ars Technica · 66d ago

Microsoft's latest Patch Tuesday update addressed a record-breaking 570 security vulnerabilities. The company attributed this increased efficiency and detection capability to the integration of AI in their security processes.
TechCrunch AI · 66d ago

Microsoft's July Patch Tuesday update addresses a record-breaking 570 security vulnerabilities, including three zero-day exploits. Among these, 61 flaws are classified as critical, necessitating immediate system updates.
ZDNet AI · 66d ago

The US Treasury has sanctioned a VPN provider and its administrators for allegedly assisting ransomware gangs in hiding their identities. This marks a significant shift in targeting the infrastructure that supports cybercriminal operations.
cnBeta (Full RSS) · 66d ago

Microsoft's July security patch cycle has addressed over 600 CVEs, including several vulnerabilities that are already being actively exploited. The sheer volume of patches has caused significant operational strain for IT and security teams.
iTNews Australia · 66d ago

Microsoft is transitioning Entra ID to passkeys as the default authentication method, phasing out SMS and voice-based MFA by February 2027. This move aims to combat AI-driven phishing and credential theft by establishing a passwordless security standard.
Computerworld · 66d ago

The Pentagon has paused a mandatory cybersecurity audit requirement for defense suppliers due to a severe shortage of accredited assessors. With over 100,000 companies requiring audits but only 100 licensed assessors available, the program faced an impossible bottleneck.
The Next Web (TNW) · 67d ago

CISA has issued a warning regarding Russian state-sponsored hackers targeting residential routers. The agency urges users to remain vigilant as these devices are increasingly used as residential proxies for malicious activity.
Ars Technica · 68d ago

Microsoft has released a fix for the 'RoguePlanet' zero-day vulnerability affecting Microsoft Defender. The flaw was identified as a disk-filling bug, and researchers have subsequently discovered additional security holes in the software.
iTNews Australia · 68d ago

The EU and UK have shifted their strategy by sanctioning the broader Russian cyber apparatus rather than just individual hackers. This move targets the intelligence services and infrastructure that facilitate state-sponsored cyber operations.
The Next Web (TNW) · 68d ago

A massive leak of SFPD drone footage from the Skydio platform highlights the privacy and security vulnerabilities of urban surveillance systems. The incident exposes the risks of data aggregation and potential unauthorized access to sensitive aerial imagery.
Wired · 68d ago

Toll Group is restructuring its data protection supply chain to address third-party risks in the AI era. The initiative aims to secure data across all external integrations.
iTNews Australia · 69d ago

Fraudsters are using AI to create convincing fake news articles that mimic reputable publishers to promote scam investment platforms. These clones often feature fabricated stories about public figures to build false credibility.
The Guardian Technology · 69d ago

The paper introduces 'idiobionics,' a new research field focused on the intersection of privacy and intelligent robotic prostheses. It highlights potential adversarial attacks on bionic limbs and provides a roadmap for securing human-facing autonomous systems.
ArXiv AI · 71d ago

Cloudflare analyzes nine NIST-proposed post-quantum signature algorithms, emphasizing the urgent need for robust security. They recommend ML-DSA as the most reliable choice for current implementation.
Cloudflare Blog · 72d ago