
It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied. Research
Researchers discovered a critical vulnerability in a major AI assistant that allowed attackers to steal passwords and sensitive data from users by simply sending them a malicious link. The vulnerability existed because the AI assistant, when directly questioned about its security protections, revealed an undocumented secret parameter that completely bypassed the requirement for user consent before executing commands. When a user clicked a specially crafted link containing this parameter, the AI would automatically extract sensitive information from the user's email and other connected services and send it to an attacker-controlled server without any action needed from the user. The vulnerability matters because it demonstrates how AI assistants' safety protections are built primarily on restrictions that can fail when attackers understand the system's internal architecture, and because the AI system itself provided the information needed to exploit it.

While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.

Amazon is calling for people to support AI data center projects, or risk irreparable harm to the US economy and national security. In a more than 3,000 word blog posted today, Amazon web services CEO Matt Garman pushed back on public concerns around the impact that data centers may have on jobs, power demands, and the environment, saying "our nation can't afford to lose" the race for AI dominance. "With any change, there will be important questions raised, but there will also b

Asking AI companies to self-regulate is a great way to pretend like you’ve accomplished something.
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven