Security — page 5

Twitch lets streamers opt out of Amazon AI training, two years after it started
Streams, VODs, clips, and chats are fair game for Amazon's generative models by default — creators have to flip a toggle to say no.

Apple builds iPhone photo authentication into iOS 27 beta
Apple Reference Image would embed sensor signatures and capture data at the shutter, letting users prove a photo came from a real iPhone camera.

Researchers build Zoom 'Zoomsday' exploit with fewer than 20 AI prompts
A Security used publicly available AI models to develop a device-hijacking Zoom exploit in a single day; Zoom patched it Tuesday.

Anthropic will watermark Claude-generated text to comply with EU AI Act
Watermarks apply at the model level, travel through copy-paste, and cover every Claude surface including Code and Cowork.

Researchers extract hidden reasoning from Claude, GPT, and Gemini via API trick
The method also recovered API keys and passwords from reasoning traces, and suggests Moonshot's Kimi K3 may have been distilled from US models.

OpenAI expands Daybreak cyber service with new GPT-5.6-Cyber model
The frontier lab splits Daybreak into Blue and Red tiers, with a purpose-trained cyber model available only to trusted partners including Accenture and Crowdstrike.

A Claude agent hacked an Australian gym's booking system to jump the waitlist
OpenClaw's agent, running Claude Opus 4.6, exploited a missing authorization check to cancel another customer's reservation and move its owner from #4 to #3.

North Korean hacking group Kimsuky builds AI tools for cyberattacks
A new report says the state-linked group is now using generative AI to draft phishing lures, write malware, and probe target networks.

AI agents keep escaping their safety sandboxes at OpenAI, Anthropic, Meta
Unreleased models from four labs breached their test environments in recent months, exposing gaps in how frontier AI is evaluated before launch.

OpenAI pauses Astra model over critical cyber capability risk
The company says internal tests of Astra can't rule out zero-day exploit generation under its Preparedness Framework.

Chatbots keep failing users in mental health crises — clinicians want the safety data opened up
13% of Americans report using chatbots for emotional advice, but researchers still can't measure how often the models cause harm.

New Mexico court orders Meta to pay another $567M in child safety case
The fresh judgment brings total penalties to $942M and forces Meta to hide Like counts and cap teen usage at 90 hours a month.

Moonshot's Kimi K3 breaks out of its sandbox to cheat on a security test
Frontier Security says the Chinese open-weight model exploited a sandbox leak and hit GitHub for answers, with weaker guardrails than US rivals.

OpenAI: Apple's own sloppy security sinks its trade-secrets case
OpenAI's motion to dismiss argues Apple let employees use personal iCloud accounts for work and failed to revoke access on departure.

AI moderation misfires hit Reddit, Discord, and Tumblr as false positives mount
Reddit says AI cut harmful-content exposure by 40 percent, but wrongful bans and mass deletions show the limits of automated moderation.

OpenAI moves to dismiss Apple trade secrets suit, calls it 'rotten to its core'
OpenAI's motion says Apple mischaracterized 'generic' product work as trade secrets; the judge hears arguments October 1st.

Zenity researchers hijack OpenAI's Atlas browser to spam WhatsApp, buy on Amazon
Around 20 flaws across AI browsers from OpenAI, Google, Anthropic, Microsoft, and Perplexity let researchers weaponize agentic browsing.

OpenAI agents ran a hidden message board to coordinate a hacking spree
At Black Hat, OpenAI detailed how a swarm of agents traded exploits on an internal package manager for weeks before anyone noticed.

Anthropic's Mythos 5 ran a rogue GitHub supply-chain attack in UK safety tests
AISI recorded 19 unsanctioned live-internet actions across seven frontier models, with Anthropic's Mythos 5 forging sock puppets to push malicious code.

Meta ran more than 50 AI-generated CSAM ads across its platforms for nine months
Tech Transparency Project found paid ads promoting nudify apps, reviewed and approved by Meta, running as recently as this week.

Trump AI testing framework excludes open models, leaves key terms undefined
The voluntary White House guidelines set a 30-day review window but never define 'state-of-the-art' or 'national security risk.'

White House keeps AI cybersecurity framework secret after briefing top labs
OpenAI, Anthropic, Google, Meta, and Nvidia got the details Tuesday. Everyone else, including smaller AI startups, is locked out.

AISI catches Anthropic and OpenAI agents hacking live internet in 122 test runs
Rogue agents from Mythos 5 and GPT-5.6-Sol took 19 unsanctioned actions, including a GitHub social-engineering attempt with fake personas.

Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio
SaferAI found the Chinese open-weight model completed every offensive cyber and dual-use biology task, while Claude Opus 4.7 refused so consistently the benchmark couldn't finish.
Stay ahead of everyone in AI.
The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.
The briefing read inside teams at