Goto

Collaborating Authors

 vulnerability


I Let an AI Agent Hack All My Gadgets--and I'd Do It Again

WIRED

I Let an AI Agent Hack All My Gadgets--and I'd Do It Again After I removed the safety guardrails from a powerful open-source model, it found vulnerabilities in my household devices and hacked into a PC. But it also told me how to make everything a lot more secure. As the author of a newsletter about artificial intelligence, I consider it my duty to experience the bleeding edge of this technology firsthand. This week, that meant embracing some agentic mayhem. You're probably aware that frontier AI models have attained advanced cybersecurity capabilities in recent months.


Microsoft's September updates fix a record 973 security flaws

PCWorld

PCWorld reports that Microsoft's September update patches a record 973 security vulnerabilities, doubling the previous month's total, with 113 classified as critical. Two zero-day exploits are already being actively used by attackers, and flaws in Windows, Excel, SharePoint, and Windows Hello could allow remote code execution or privilege escalation. Users are strongly urged to update their Microsoft software immediately to protect against these serious risks. Yesterday was September Patch Tuesday, which means Microsoft released security updates addressing 973 new security vulnerabilities.


What is vibe coding and why does it get so much hate?

Engadget

Proponents of vibe coding argue LLMs democratize software development, allowing anyone to make their own apps. My neighbor used to work as a veterinary tech. She vibe coded an app to make tracking her senior cat's insulin shots easier. On the other side, critics argue vibe coding is producing vulnerable software. Extensive use can also make a codebase more difficult to maintain, since there's a good chance a vibe coder doesn't know enough about coding to fix an error if an LLM can't address it for them.


OpenAI Agents Hacked Another Website

WIRED

Plus: Tens of millions of US and Canadian driver's licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more. After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock's latest search tool from code that the company sends to a police officer's browser and uncovered key details about how the tool works. OpenAI said this week that its Astra model, which will have a private release soon, is its first model with cybersecurity-related capabilities that the company defines as posing a "critical" risk in public release. Meanwhile, the AI chatbot platforms Claude, ChatGPT, and Grok all suffered outages on Thursday at nearly the exact same time. But while xAI said the Grok outage resulted from issues at a Memphis data center, the causes of OpenAI's and Anthropic's outages are unclear.


Firefox 155 patches 30 security flaws, adds sortable tab groups

PCWorld

When you purchase through links in our articles, we may earn a small commission. Mozilla's latest Firefox update fixes 10 high-risk security flaws and rolls out small but useful features, from Switch Pro controller support to sortable tabs. The newest major release of Firefox 155 for Windows, macOS, Linux, and Android brings a number of improvements, including support for Nintendo Switch Pro controllers and sortable tab groups. Mozilla has also patched over 30 security vulnerabilities, and updates are also available for the ESR versions of Firefox for older systems. The release of the next major version, Firefox 156, is already scheduled for September 15th, with time for a bug-fix update on September 8th.


AI is making cyberattacks worse. You need a digital disaster plan

PCWorld

When you purchase through links in our articles, we may earn a small commission. AI is making cyberattacks worse. AI is making cyberattacks worse. But you can fortify your digital life so it stands up better to today's dangers. Here's how to build a digital disaster plan.


OpenAI Is About to Release Its First AI Model With 'Critical' Cyber Abilities

WIRED

OpenAI Is About to Release Its First AI Model With'Critical' Cyber Abilities The company will give select partners early access to its Astra AI model--so they have time to shore up their defenses. OpenAI announced Tuesday that its forthcoming AI model, Astra, is its first to reach the company's threshold for what it calls "critical" cyber capabilities. OpenAI says it plans to publicly release a version of Astra "soon," but will make the model's advanced cyber capabilities available only to select partners in its Daybreak Blue early-access program at launch. In a briefing with reporters, OpenAI safety and security leaders said the company has concluded that Astra reaches the critical cybersecurity capabilities outlined in its preparedness framework, which sets thresholds and protocols for when its AI models pose new levels of risk. The company says an AI model has reached its critical cyber threshold when it can independently find and exploit previously unknown vulnerabilities in real-world software.


How AI-armed script kiddies will soon wield the power of state-sponsored threat actors

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen AI a'force multiplier' for low-skilled threat actors: 4 ways organizations should respond Low-skill hacktivists are now'enabled with the same tooling and sophistication as a state-sponsored group,' according to cybersecurity consultant Unit 42. AI has created a permanent generational shift in cybersecurity. This shift includes how we classify threats, with hacktivism predicted to take center stage. Low-threat script kiddies may be a thing of the past, as AI changes the conversation. Can you imagine a future when script kiddies -- low-or no-skill wannabe hackers who use prewritten scripts or tools to cause havoc -- can shake the foundations of cyberdefense?


OpenAI says it detected malign activity months before Hugging Face attack

Al Jazeera

OpenAI detected its artificial intelligence models communicating with each other and gaining internet access without authorisation months before they hacked the start-up Hugging Face, the creator of ChatGPT has announced following an internal probe. In a report released on Wednesday, OpenAI said its AI agents exploited vulnerabilities in Artifactory, a software repository tool, to post notes and access the internet without human prompting as far back as May. OpenAI's findings come amid growing concern about the potential for AI to inflict serious real-world harm, including self-directed cyberattacks. OpenAI said in its report that its agents collaborated and delegated work in the lead-up to the attack, sometimes referring to themselves as a "swarm" or "collective". METR and Redwood Research, two security research organisations contracted by OpenAI to investigate the incident, said in a separate report released on Wednesday that about 1200 agents had communicated with each other and roughly 700 participated in the attack.


Chrome just patched 320 security flaws, and paid 25K for one of them

PCWorld

When you purchase through links in our articles, we may earn a small commission. Google's latest Chrome update fixes 327 security flaws. None are being exploited in the wild, but you should update anyway. According to Google, none of the patched vulnerabilities are being exploited in the wild yet. Google has also released Chrome for Android 152.0.7977.64 and Chrome for iOS 152.0.7977.64 this week.