Browsing Tag
AI Security
28 posts
Security risks, defenses, and engineering practices for AI systems and models.
Open-Weight AI Cyber Gap Narrows to Months, AISI Finds
The UK AI Security Institute says GLM-5.2 and DeepSeek V4-Pro now trail leading closed AI models on cyber tasks by roughly four to seven months. For defenders, that shrinking gap turns open-weight model policy into an operational security issue, not a distant AI governance debate.
Meta’s Virtue AI Hires Move Agent Security Into the Model Lab
Meta Superintelligence Labs is hiring Virtue AI co-founders Bo Li, Dawn Song, Sanmi Koyejo and other team members. The move brings automated red teaming, runtime guardrails, and agent-action security closer to Meta’s frontier AI work as labs race to make agents safer before they reach billions of users.
Mythos Limits Are Already Pushing AI Cyber Tools Toward Alternatives
Anthropic’s Mythos 5 is returning only for approved U.S. cyber defenders while Fable 5 remains restricted. In the same week, Sakana AI and 360 Security showed why AI cyber capability is becoming a provider-risk and sovereignty problem, not just a model benchmark race.
Anthropic’s Mythos Test Shows Why AI Cyber Defense Is Becoming Classified Work
An Anthropic Mythos test with U.S. intelligence agencies reportedly found vulnerabilities in highly sensitive government systems within hours. The episode sharpens the policy problem around frontier AI: the same models that can help defenders fix critical software can also compress the timeline for attackers.
Dragos EmberAI Puts AI Security Workflows Inside the Control Room
Dragos launched EmberAI, an OT-native AI assistant for industrial cybersecurity teams. The product matters because critical infrastructure defenders need AI that understands plant assets, threat groups, vulnerable equipment, and operational impact rather than treating OT security like ordinary IT alert triage.
OpenAI Daybreak Turns AI Bug Finding Into a Patching Race
OpenAI expanded Daybreak with Patch the Planet, an updated GPT-5.5-Cyber model, Codex Security workflows, and a partner program for vetted security vendors. The move shifts the AI cybersecurity race from finding more bugs to validating, patching, testing, and landing fixes before maintainers are overwhelmed.
DeepMind’s AI Control Roadmap Makes Agent Security a Runtime Problem
Google DeepMind’s AI Control Roadmap treats powerful internal AI agents as systems that need monitoring, access limits, response plans, and shutdown paths. The framework is a signal for enterprises moving from chatbots to tool-using agents: alignment claims are no longer enough if the agent can touch code, data, infrastructure, or security workflows.
AWS AgentCore Turns Enterprise AI Agents Into an Operations Stack
AWS used its New York Summit to expand Bedrock AgentCore, launch AWS Context and AWS Continuum, and push AI agents deeper into enterprise operations. The real story is not another chatbot layer, but a managed stack for grounding, governing, testing, and remediating agent behavior.
SearchLeak Shows How Microsoft 365 Copilot Search Can Become a Data Leak
Varonis disclosed SearchLeak, a patched Microsoft 365 Copilot Enterprise Search vulnerability chain that could turn one trusted-looking Microsoft link into a path for stealing emails, files, calendar data, and MFA codes.
Microsoft AutoJack Research Shows How AI Browsing Agents Can Break Localhost Trust
Microsoft’s AutoJack research shows how an AI browsing agent could turn a malicious webpage into a local remote-code-execution path through AutoGen Studio’s MCP WebSocket surface. The specific issue was fixed before a PyPI release, but the localhost trust problem is bigger than one tool.