Skip to content

Tags

security

6 items
A 3D render of the Chrome logo riding a white cart along a rail, in a room with a window and a plant behind it.
Agentsstrong signal

Gemini Spark vs Claude's browser toolset: whose account, whose risk

Both drive a web browser, both stop before the step that cannot be undone, and their lists of stopping points are nearly the same. The difference is what each assumes about the session it runs in: one is built on the accounts you are already signed into, the other tells you to give it a browser with no credentials in it. That single assumption decides which of the two belongs anywhere near your work.

Google, Anthropicverified

The xAI and Grok logos on a phone screen.
Agentsstrong signal

Encrypting the instruction walks it straight past the guardrail

Researchers at Adversa hid a prompt injection as ciphertext with the key next to it. Grok decrypted it in its own sandbox and sent the user's name, location, and chat history to an attacker's server, without a warning and without asking.

Ars Technicaverified

Black title card reading "Upcoming Next.js August Security Release", with the Next.js mark in the corner.
Toolsmedium signal

Next.js will patch one critical vulnerability on August 26

Vercel published the date before the fix. Versions 16.3.3 and 15.5.24 arrive on August 26 with a full advisory, and the announcement exists so teams can schedule the upgrade instead of discovering it from a CVE feed.

Next.js Blogverified

Agentsmedium signal

Auto mode becomes the default permission mode

Since August 14, auto mode is the default permission mode for new sessions on the Pro, Max, and Team plans. Instead of interrupting at every action, a classifier in the background lets safe actions through and stops risky ones. If you set a default mode yourself, it stays in force until you accept a one-time offer to switch, and a mode an organization mandates does not change automatically. One detail matters for your quota: the classifier calls auto mode makes no longer count against usage limits.

Anthropicverified

Industrymedium signal

OpenAI introduces Private Safety Processing

On August 19, OpenAI released a preview of a system that recognizes abuse patterns across several linked sessions without retaining user content. The idea is that only a narrowly defined safety signal is passed on, without exposing the prompts and responses themselves, which keeps the zero data retention guarantee for paid API customers in force. The target is attackers who split a request across several conversations to avoid detection. The approach is the opposite of Anthropic's policy, which keeps data for 30 days with controlled human review; if you are choosing a vendor for a project with sensitive client data, that difference is worth understanding before you sign. Wider rollout and a technical paper were announced for September.

TechCrunch / OpenAIverified

Industrymedium signal

Who is responsible when an agent gets it wrong

Agents have left the pilot stage and do real work in business software, health care, logistics, and finance. What remains is a question most organizations cannot answer: when an agent deletes a record or sends the wrong message, who is responsible? It is telling that Obsidian Security raised $85 million in August at a $1.1 billion valuation, and that more than 70% of its customers already let agents into third-party apps.

agregatori vijestiunverified