Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt injections, the Malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other … Read more

Your Period Tracker Is (Probably) Spying on You

Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that … Read more

You Can Now Sound the Alarm on AI Behaving Badly

Writing AI Lab each week means I occasionally encounter AI models that behave badly and bizarrely. Usually, there’s nothing to be done about it, save for sharing those tales with you. But that could change soon. A group of AI researchers has set up a crowdsourced websiteFlaw Reporting for AI (FLARE-AI), for reporting and tracking … Read more

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

As a security researcher who specializes in finding web vulnerabilities, he decided to poke around Front Gate’s web domain for bugs. He quickly found what looked like a SQL injection vulnerability—a common flaw that allows a hacker to input commands into a text field on a website, causing them to run on the site’s backend … Read more

OpenAI Has New AI Models. Here’s Why You Can’t Use Them

OpenAI is delaying the public release of its next generation of AI models, GPT-5.6, at the request of Trump’s White House, the company confirmed on Friday. OpenAI said it would first share the models with a small set of customers, which will be pre-approved by the US government. It will then work with the administration … Read more

I Met With China’s Top AI Experts. They’re Freaking Out, Too

Just over a week ago, I attended a major artificial intelligence conference in Zhongguancun, Beijing’s bustling high-tech district. It was packed with fascinating sessions touching on everything from recursive self-improvement—the idea that models can tweak their own code and advance indefinitely—to humanoid robots. And it featured a few legends of computing, including Whitfield Diffie, co-inventor … Read more

Meta Exposed Data Internally From Its Controversial Employee-Tracking Program

Meta left potentially Sensitive information collected from employee laptops accessible to anyone inside the company, according to an internal security notice seen by WIRED and three current employees familiar with the issue. The data, which was collected as part of a divisive initiative to train artificial intelligence models, is believed to include keystrokes, mouseclicks, and … Read more

Meta Pauses Employee-Tracking Program Following Internal Data Leak

Meta is pausing a divisive employee tracking program after an internal security issue exposed potentially sensitive data collected through the initiative to other workers. “We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while … Read more

OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos

As fears about AI hacking capabilities grow, OpenAI on Monday made a slew of cybersecurity-focused announcementsincluding an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and other institutions to give them “trusted access” to the company’s latest cybersecurity-focused models, and releasing its Codex Security scanner as an app plug-in. As … Read more

World Cup Scams Are Getting Harder to Spot

You got a World Cup ticket. It arrived in your inbox with a QR code, professional branding, and a confirmation email that looked like the real thing. Unfortunately, it wasn’t. For years, spotting a scam was relatively simple. A suspicious email address, broken English, or an obvious typo were often enough to raise suspicion. But … Read more