Windows 11's New AI Feature Sends Screenshots of Your Apps to Microsoft's Cloud
Microsoft's 'Share with Copilot' taskbar feature is enabled by default and transmits visual snapshots of any open window to cloud servers for AI processing.
Category
Microsoft's 'Share with Copilot' taskbar feature is enabled by default and transmits visual snapshots of any open window to cloud servers for AI processing.
This week in AI security: Chat & Ask AI exposes 300 million messages, Microsoft patches Copilot email vulnerability, and vibe-coded apps prove trivially hackable.
Kaspersky finds DeepSeek, Llama, and ChatGPT all produce password outputs that fail standard strength tests. Prediction capability makes LLMs bad at randomness.
Microsoft Semantic Kernel has back-to-back CVSS 10.0 vulnerabilities enabling remote code execution and arbitrary file writes through AI agent function calls
A CVSS 9.8 flaw in the popular AI inference engine allows unauthenticated remote code execution through malicious video URLs. Patch now if you're running multimodal models.
Microsoft found 31 companies embedding hidden instructions in AI share buttons. One click poisons your assistant's memory, shaping every future recommendation without your knowledge.
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
Discord announces mandatory facial scanning and ID uploads just months after a breach exposed 70,000 government documents. Users are fleeing to Matrix and TeamSpeak.
Researchers discovered that displaying an AI model's reasoning process creates a roadmap for attackers. OpenAI's o1 rejection rate dropped from 98% to under 2%.
ESET discovers Android malware that queries Google's Gemini AI in real-time to navigate infected devices and maintain persistence across any Android version.
A source-by-source audit of eight AI assistants, what they collect, how training defaults differ, and which privacy settings users can change.
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
Check Point demonstrated how web-browsing AI assistants can relay malware commands through legitimate traffic. Microsoft changed Copilot's behavior.
Researchers tricked Google Translate's Gemini-based Advanced mode into answering prompts, including requests for drug and malware instructions.
The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.
New research shows AI reasoning models can autonomously plan and execute attacks that bypass safety guardrails in nearly all other AI systems.
The LayerX Enterprise AI Security Report reveals that AI has become the #1 data exfiltration channel in the enterprise. 82% of those leaking data use personal accounts. Traditional DLP can't stop copy-paste.
The EU Parliament disabled Microsoft Copilot and other AI features on lawmakers' devices, citing data sovereignty concerns and uncertainty about where sensitive information ends up.
Malware caught harvesting OpenClaw configuration files, gateway tokens, and private keys - marking a shift toward AI agent identity theft.
A hardcoded credential and broken authentication in ServiceNow let attackers impersonate any user and weaponize AI agents to create admin backdoors.
Tennessee made it a felony to train AI chatbots that encourage suicide. Virginia is banning AI therapist impersonators. A dozen states have bills moving through legislatures right now.
Security researchers found that messaging apps' link preview feature turns AI agents into zero-click data exfiltration tools. Teams, Slack, Discord, and Telegram are all affected.
ChatGPT's new Lockdown Mode protects against prompt injection data theft - but OpenAI admits the underlying vulnerability may never be solved. Here's what that means for agentic AI.
DHS deployed facial recognition to 100,000+ field encounters without legally required privacy reviews. Internal records show the agency knew the app couldn't verify identities.