27 Aug, 2026

New CoPhish attack steals OAuth tokens via Copilot Studio agents

A new phishing technique dubbed ‘CoPhish’ weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains. The technique was developed by researchers at Datadog Security Labs, who warned in a report earlier this week that Copilot Studio’s flexibility introduces new, undocumented phishing risks. Although CoPhish relies on social […]

5 mins read

Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions

OpenAI’s Atlas and Perplexity’s Comet browsers are vulnerable to attacks that spoof the built-in AI sidebar and can lead users into following malicious instructions. The AI Sidebar Spoofing attack was devised by researchers at browser security company SquareX and works on the latest versions of the two browsers. The researchers created three realistic attack scenarios where a […]

3 mins read

Google won’t fix new ASCII smuggling attack in Gemini

Google has decided not to fix a new ASCII smuggling attack in Gemini that could be used to trick the AI assistant into providing users with fake information, alter the model’s behavior, and silently poison its data. ASCII smuggling is an attack where special characters from the Tags Unicode block are used to introduce payloads […]

3 mins read

Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities

The latest releases of Cursor and Windsurf integrated development environments are vulnerable to more than 94 known and patched security issues in the Chromium browser and the V8 JavaScript engine. An estimated 1.8 million developers, the userbase for the two IDEs, are exposed to the risks. Ox Security researchers explain that both development environments are built on old software […]

4 mins read

Google’s new AI bug bounty program pays up to $30,000 for flaws

This week, Google has launched an AI Vulnerability Reward Program dedicated to security researchers who find and report flaws in the company’s AI systems. The new bug bounty program focuses on the most impactful issues in the highest-profile AI products, including but not limited to Google Search (on google.com), Gemini Apps (Web, Android, and iOS), […]

2 mins read

Zeroday Cloud hacking contest offers $4.5 million in bounties

A new hacking competition called Zeroday Cloud, focused on open-source cloud and AI tools, announced a total prize pool of $4.5 million in bug bounties for researchers that submit exploits for various targets. The contest is launched by the research arm of cloud security company Wiz in partnership with Google Cloud, AWS, and Microsoft, and is scheduled for […]

3 mins read

ChatGPT Pulse is coming to the web, but no word on free or Plus roll out

OpenAI’s ChatGPT Pulse, which is a tool that gives you personalised updates based on usage patterns, is coming to the web. OpenAI began rolling out ChatGPT Pulse for mobile users on September 25, but it works only when you use $200 Pro subscription. ChatGPT Plus isn’t available on the web, but that will change soon. […]

1 min read

OpenAI is testing ChatGPT-powered Agent Builder

OpenAI is building a tool that will allow you to create your own AI Agents. AI startups are convinced AI agents are the future and OpenAI’s AI Builder could be the Visual Studio moment for building agentic experiences. As spotted on X, OpenAI Agent Builder has a flowchart where you drop small blocks (called nodes) and connect […]

1 min read

ChatGPT social could be a thing, as leak shows direct messages support

OpenAI doesn’t want ChatGPT to remain just a chatbot for interacting with a large language model. OpenAI already has Sora 2, which has a social-media-like feed for AI-generated videos, but OpenAI could go beyond just videos. As spotted on X, ChatGPT is testing support for direct messages. Similar to X, it looks like you will be able to […]

1 min read