Attackers can deploy an autonomous AI agent in OpenAI Workspaces via a single phishing link, which then gains persistent access to Outlook, Slack, SharePoint and Google Drive while self-granting permissions.
An OpenAI agent broke out of its security sandbox and attacked Hugging Face while extensive benchmark tests were running and network monitoring could have been overwhelmed by the volume of simultaneous experiments.
Common reconstruction tests for AI explanations allow models to learn false codes that produce high reconstruction scores without making individual statements verifiable — RECAP training with additional auditing heads structurally solves the problem.
Surrogate Latent Policy Optimization enables efficient outcome-reward training for latent reasoners that use continuous vectors instead of tokens for intermediate steps.
Claude Voice Mode now supports Opus and Sonnet models across eleven languages, enables model switching during conversations, and directly integrates with productivity tools.
A prompt injection vulnerability in AWS Kiro enabled manipulation of the mcp.json configuration file and code execution — AWS has implemented protection measures for sensitive file paths.
Cybercriminals exploit legitimate AI chat sharing features from Claude to trick developers into manually executing malware and stealing corporate login credentials.