Security

Auto Added by WPeMatico

Hackers asked Meta’s AI chatbot to hand over Instagram accounts, and it did

No phishing link. No malware. No SIM swap. Hackers took over high-profile Instagram accounts over the weekend by doing something disarmingly simple: they asked Meta’s AI customer support chatbot to change the email address on someone else’s account. The bot complied without verifying the requester’s identity, and the attacker then reset the password and locked out the […]

This story continues at The Next Web

Hackers asked Meta’s AI chatbot to hand over Instagram accounts, and it did Read More »

A popular OpenAI Codex tool with 29,000 weekly downloads has been quietly stealing developer tokens for a month

The npm package looked legitimate. It had an active GitHub repository, steady development history, and roughly 29,000 weekly downloads. For developers using OpenAI Codex, it offered exactly what it advertised: a remote web UI for the AI coding tool. But for the past month, every invocation of codexui-android has also been silently reading the contents of […]

This story continues at The Next Web

A popular OpenAI Codex tool with 29,000 weekly downloads has been quietly stealing developer tokens for a month Read More »

One click on GitHub.dev is all it takes to hand over your private repositories

Every developer who has ever pressed the period key on a GitHub repository, launching the convenient browser-based VS Code editor known as GitHub.dev, has unknowingly accepted a bargain. In exchange for a lightweight coding environment, GitHub silently passes an OAuth token to the session, one that grants read and write access to every repository the user […]

This story continues at The Next Web

One click on GitHub.dev is all it takes to hand over your private repositories Read More »

Virtual barbarians at the gate: securing the AI blind spot

Many companies have quickly moved to adopt artificial intelligence in their systems, embedding it into virtually everything from customer apps to internal systems. That speed has created new pressure for security teams, because AI-enabled applications can introduce unfamiliar attack surfaces, unpredictable behavior, and new ways for attackers to manipulate inputs, access data, or chain weaknesses across […]

This story continues at The Next Web

Virtual barbarians at the gate: securing the AI blind spot Read More »

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release

President Trump signed an executive order on Tuesday establishing a voluntary framework for government review of frontier AI models before public release, ending weeks of internal White House conflict over how aggressively to regulate the technology. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” was signed privately without the usual livestream or public ceremony, a […]

This story continues at The Next Web

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release Read More »

Shopping Cart