Klue Breach Shows How SaaS OAuth Tokens Became a Salesforce Risk
Klue’s June security incident let attackers use a legacy integration credential to obtain OAuth tokens and pull Salesforce CRM data from connected customer environments. The breach is a practical warning for teams that treat SaaS integrations as trusted background plumbing instead of monitored, scoped access paths.
Five Eyes Warns Frontier AI Could Compress Cyber Risk Into Months
Five Eyes cyber agencies warned on June 22 that frontier AI could transform offensive and defensive cyber operations on a months-long timeline. The guidance turns AI-enabled cyber risk into a board-level resilience issue, with practical pressure on patching, identity controls, legacy systems, incident response, and defensive AI use.
NVIDIA Halos Turns Robot Safety Into a Full-Stack AI Platform
NVIDIA Halos for Robotics gives robot makers a shared safety stack for physical AI, combining IGX Thor compute, Halos OS, sensor infrastructure, outside-in safety agents, and an inspection lab for certification. Agility Robotics is the first public adopter, bringing parts of the system into Digit humanoid deployments for factories, warehouses, and logistics operations.
LiteLLM Exploit Puts AI Gateways on a June 22 Patch Deadline
CISA’s June 22 remediation deadline for CVE-2026-42271 puts LiteLLM AI gateways on the security team’s priority list. The flaw affects MCP test endpoints, can expose model-provider credentials, and may become unauthenticated RCE when chained with a Starlette host-header bypass.
Samsung’s ChatGPT Rollout Shows Enterprise AI Moving Past the Ban Era
Samsung Electronics is giving ChatGPT Enterprise and Codex to all employees in Korea and its global DX division, turning a once-risky consumer AI tool into governed workplace infrastructure. The rollout is one of OpenAI’s largest enterprise deployments and a useful marker for how big companies are moving from blanket bans to controlled AI access.
Amazon’s Trainium Talks Push AWS Chips Beyond the Cloud
AWS is in early talks to sell Trainium AI chips for use in other companies’ data centers, a shift that could move Amazon from cloud-only accelerator provider toward a more direct role in the AI chip market. The opportunity is real, but so are the constraints: Trainium capacity is already tight, Nvidia still owns the broadest software ecosystem, and selling racks outside AWS could weaken the cloud bundle that makes custom silicon so valuable to Amazon.
Apple Opens iOS App Stores and Payments in Brazil Under CADE Deal
Apple’s CADE agreement opens iOS app distribution and payments in Brazil through alternative app marketplaces and outside payment options, but the new rules keep Apple in the loop through notarization, marketplace authorization, child-safety requirements, and fresh commission terms.
DeepMind’s AI Control Roadmap Makes Agent Security a Runtime Problem
Google DeepMind’s AI Control Roadmap treats powerful internal AI agents as systems that need monitoring, access limits, response plans, and shutdown paths. The framework is a signal for enterprises moving from chatbots to tool-using agents: alignment claims are no longer enough if the agent can touch code, data, infrastructure, or security workflows.
CISA Puts FortiSandbox Exploits on an Emergency Patch Clock
CISA added two Fortinet FortiSandbox command-injection flaws to its exploited-vulnerabilities catalog on July 16, giving federal agencies until July 19 to remediate. Security teams should patch affected FortiSandbox systems, restrict management access, and review logs and connected credentials if exposure existed before the upgrade.
AryStinger Botnet Turns Old Routers Into Attack Proxies
Security researchers say AryStinger has compromised more than 4,300 legacy routers, turning aging home and small-office gear into proxy and reconnaissance infrastructure. The campaign is a reminder that end-of-life routers are not just slow or outdated; they can become someone else’s attack platform.