< ciso
brief />
AI and Security Pulse Banner

All news in category “AI and Security Pulse”

1447 articles · page 50 of 73

ChatGPT Mobile Gains Thinking-Time Toggle for Plus Users

🤖 OpenAI is rolling out a mobile update that lets ChatGPT Plus subscribers select the Thinking time toggle, often called the model's 'juice', to enable longer, higher‑compute responses on mobile. Until now, Android devices routed Thinking requests through Standard Thinking, which uses less compute and cannot sustain long reasoning. On desktop, users could already switch between Standard Thinking and Extended Thinking, with Extended using more compute for complex queries. The rollout is gradual, the toggle is limited to ChatGPT Plus (the Go tier does not include it), and OpenAI also introduced new desktop formatting blocks and mini editor toolbars for richer task-specific outputs.
read more →

Microsoft Copilot Rolls Out GPT-5.2 Smart Plus Mode

🚀 Microsoft is rolling out GPT-5.2 to Copilot on web, Windows, and mobile as a free upgrade that will coexist with the existing GPT-5.1 model. The new option appears as a 'Smart Plus' mode and uses a 'Thinking' variant designed for more complex, multi-step tasks. OpenAI positions GPT-5.2 as its strongest model family yet, improving productivity for spreadsheets, presentations, coding, document understanding, image work, and tool use.
read more →

Top 5 Real-World AI Security Threats Revealed in 2025

🔒 2025 exposed major, real-world risks across the AI ecosystem as rapid adoption of agentic AI expanded enterprise attack surfaces. Researchers documented pervasive Shadow AI and vulnerable vendor tools, AI supply-chain poisoning, credential theft (LLMjacking), prompt-injection attacks, and rogue or misconfigured MCP servers. These incidents affected popular frameworks and cloud services and resulted in data breaches, remote-code execution, and costly fraud.
read more →

Traditional Security Frameworks Fail Against AI Threats

🔒 Traditional security frameworks like NIST CSF, ISO 27001, and CIS Controls were designed for legacy IT assets and do not map cleanly to AI-specific risks. Recent incidents — including the December 2024 Ultralytics compromise, ChatGPT memory-extraction flaws across 2024, and August 2025 malicious Nx packages — show organizations can meet compliance yet remain exposed. The article argues security teams must adopt AI-tailored controls such as prompt validation, model integrity verification, semantic DLP, and AI-focused red teaming.
read more →

OpenAI May Prioritize Sponsored Content in ChatGPT

📰OpenAI is exploring a new ad format for ChatGPT — 'sponsored content' — that could be prioritized within model responses and shown in a sidebar or carousel. References to the feature appeared in an Android beta and in mockups reported by The Information. An OpenAI spokesperson confirmed the company is researching ads and said any approach would be designed to respect user trust.
read more →

ChatGPT adds formatting blocks to match task UIs today

📝 OpenAI has introduced 'formatting blocks' in ChatGPT, adjusting how the interface presents generated content to match the specific task users are performing. The update adds a compact editor toolbar that appears when text is highlighted in newer rich-text areas, such as email composition or writing drafts. Drafts are now shown as formatted documents users can edit inline, similar to Word or Gmail, rather than as plain chat messages. The feature is rolling out gradually and OpenAI plans to add support for additional formats over time.
read more →

OpenAI Tests 'Skills' for ChatGPT, Mirroring Claude

🛠️ OpenAI is testing a new ChatGPT feature called Skills, modeled on Anthropic's Claude Skills. Reports say the capability — codenamed 'hazelnuts' — will appear as slash commands and include a dedicated Skills editor plus an option to convert a custom GPT into a skill. Claude's Skills are folder-based instructions that can be composable, portable, efficient, and can include executable code; OpenAI's implementation appears to follow a similar design. Timing is unclear, but a January 2026 rollout is currently suggested.
read more →

Urban VPN Proxy Intercepts AI Chats Across Platforms

🔒 A recent analysis by koi.ai, highlighted by Bruce Schneier and Boing Boing, reports that the Urban VPN Proxy browser extension is surreptitiously intercepting conversations across multiple AI services. The extension embeds dedicated executor scripts for ten AI platforms and captures every prompt, every response, conversation identifiers, timestamps, session metadata, and the specific model or platform used. Harvesting is enabled by default via hardcoded flags and runs continuously in the background regardless of whether the VPN is active; there is no user-facing toggle and the only effective remediation is to uninstall the extension.
read more →

NIST Funds MITRE to Establish Two AI Security Centers

🔒 NIST is investing $20m to fund two new AI security research centers run by nonprofit MITRE: the AI Economic Security Center for US Manufacturing Productivity and the AI Economic Security Center to Secure US Critical Infrastructure from Cyber Threats. The centers will develop technology evaluations and advancements to protect US AI leadership, counter adversarial AI uses, and reduce risks from insecure systems. NIST says the effort will drive applied science breakthroughs and support commercialization of new technologies.
read more →

AI Fix Ep. 82: AI Says Santa Isn't Real, Plus Waymo Woes

🎄 This Christmas episode of The AI Fix examines whether chatbots agree that Santa Claus exists, testing responses from popular conversational AIs and Google's seasonal features. The hosts discuss a string of Waymo robotaxi incidents that sparked PR headaches, Microsoft's reduced ambitions for Copilot amid low usage, and research suggesting future programmers may rely more on psychological prompt design than traditional coding. Hosts: Graham Cluley and Mark Stockley.
read more →

MiniMax-M2 Now Deployable via SageMaker JumpStart Support

🚀 MiniMax-M2 is now available on SageMaker JumpStart, enabling immediate deployment of this efficient open-source MoE model in minutes. The model combines 230 billion total parameters with 10 billion active parameters to deliver a compact, fast, and cost-effective option optimized for coding and agentic tasks while preserving strong general intelligence. Customers can deploy via SageMaker Studio or the SageMaker Python SDK and follow AWS best practices for production use.
read more →

Agentic AI Forces a New Identity and Authentication Crisis

🔒 Many enterprises are racing to deploy autonomous agentic AI without establishing robust identity and authentication controls, creating an identity crisis for CISOs. Experts warn that fewer than 5–10% of organizations assign formal agent identities (for example via PKI) before wider release, leaving deployments vulnerable to hijacking and prompt-injection. Because agents routinely communicate with one another, a compromised agent can cascade malicious instructions across legitimate agents before revocation, and current vendor solutions and kill switches are incomplete or absent.
read more →

Fighting AI With AI: Cybersecurity's Inevitable Battle

🤖 Trend Micro's Rachel Jin warns that the rapid evolution of AI is outpacing static security controls and forcing defenders to embrace automation and context-aware defenses. She notes LLMs update frequently and attackers leverage that pace to craft tailored phishing, automate tasks and scale operations. Jin stresses that visibility into AI usage, agents and infrastructure is essential and recommends an AI security blueprint to map risk, consolidate tooling and prioritize scarce budgets.
read more →

Scammers Use AI to Forge Art Documentation and Certificates

🖼️ Fraudsters are using AI and large language models to create highly convincing fake invoices, appraisal certificates and certificates of authenticity for artworks, making forgeries harder to detect. Brokers and appraisers, including Marsh, report that chatbots can invent plausible experts and documentation or hallucinate false references that owners accept as real. Insurers and valuation firms are now deploying AI-based metadata analysis and anomaly detection to flag manipulated provenance and guide human review.
read more →

CrowdStrike: Training GenAI Models at Scale, Distributed

🛡️ CrowdStrike outlines its methodology for training security-focused GenAI models at scale using the Google Cloud Vertex Training Cluster and an infrastructure-as-code approach. The team leverages Slurm for workload scheduling, modular data pipelines with synthetic augmentation, and a mix of parallelism strategies (data, tensor, pipeline, sequence/expert) to match model size and hardware. They optimize across GPU architectures (H100, B200) using high-performance attention kernels like Flash Attention and NCCL for inter-node communication to improve throughput, support extended contexts, and manage memory via gradient checkpointing and observability tooling.
read more →

IT's 2025 Verdict: AI Gains, Layoffs and Mixed Security

🤖 The editorial teams of Computerwoche, CIO and CSO reflect on a turbulent 2025 shaped by the rapid rise of AI, economic uncertainty and geopolitical friction. They call out major flops such as widespread AI‑justified layoffs (Surfshark estimates 200,000+ jobs lost) and the growing use of AI by cybercriminals, while noting positive trends: pragmatic CIOs focusing on data quality, innovative change management like Mobilezone, and sizable sovereignty investments such as Schwarz IT.
read more →

Managing Agentic AI Risk: Lessons from OWASP Top 10

🛡️ The OWASP Top 10 for Agentic Applications identifies the most critical security risks from AI agents—systems that access data, invoke tools, and act autonomously—and offers CISOs practical threat taxonomies, mitigation strategies, and example threat models. Contributors prioritized data-driven, real-world issues discovered during research, including many agentic deployments unknown to IT and security teams. The list is designed to be consumable and directly actionable for threat modeling, governance, and security architecture.
read more →

Science-Backed Approach to Building Mission-Ready SOC Agents

🔒 CrowdStrike outlines a science-backed framework for training, validating, and hardening AI agents to perform analyst-grade triage and response in the SOC. The post emphasizes using expert-annotated data, reproducible benchmarking, continuous human feedback, scalable heterogeneous architecture, strict guardrails, and adversarial testing. CrowdStrike cites over 98% decision accuracy for Charlotte AI Detection Triage and Agentic Response agents and highlights time-savings and auditable recommendations to accelerate investigations while preserving human oversight.
read more →

AI and Security in Financial Services: Secure Design

🔒 The post argues that financial institutions must treat cybersecurity as the foundation for safe AI adoption, centering on three imperatives: understand the AI–cybersecurity nexus, harness AI to accelerate detection and response, and adopt Secure AI by Design. It highlights AI-driven SOCs that distill billions of events into actionable incidents and cites customer outcomes such as dramatic reductions in MTTR and large-scale threat prevention. The author also describes new AI-specific risks to data, models and agents, and calls for enterprise governance, risk-tiered inventories, strict access controls and coordinated policy to enable innovation while managing systemic risk.
read more →

Check Point Launches AI Security Training Courses Globally

🔐 Infinity Global Services (IGS) has launched its first dedicated AI security training courses, the initial release in a growing AI services portfolio. The programs offer expert-led instruction and hands-on labs to help security teams, developers, and leaders defend against AI-driven threats and implement AI securely across operations and product development. IGS also plans upcoming offerings in AI red teaming, governance, and implementation consulting to extend defensive and advisory capabilities.
read more →