Microsoft Copilot Read 'Confidential' Emails Despite DLP Labels
A bug let Microsoft 365 Copilot summarize emails marked confidential, bypassing DLP protections. Microsoft's defense misses the point.
Tag
A bug let Microsoft 365 Copilot summarize emails marked confidential, bypassing DLP protections. Microsoft's defense misses the point.
Microsoft's 'Share with Copilot' taskbar feature is enabled by default and transmits visual snapshots of any open window to cloud servers for AI processing.
This week in AI security: Chat & Ask AI exposes 300 million messages, Microsoft patches Copilot email vulnerability, and vibe-coded apps prove trivially hackable.
Kaspersky finds DeepSeek, Llama, and ChatGPT all produce password outputs that fail standard strength tests. Prediction capability makes LLMs bad at randomness.
Microsoft found 31 companies embedding hidden instructions in AI share buttons. One click poisons your assistant's memory without your knowledge.
Discord announces mandatory facial scanning and ID uploads months after a breach exposed 70,000 government documents. Users are fleeing to Matrix and TeamSpeak.
A source-by-source audit of eight AI assistants, what they collect, how training defaults differ, and which privacy settings users can change.
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
A tier-by-tier comparison of the top open-weight LLMs you can run locally, from 8GB laptops to 24GB gaming GPUs to Apple Silicon Macs.
Step-by-step guide to running a private, local AI chatbot that rivals ChatGPT - no subscription, no data collection, no internet required.
The LayerX Enterprise AI Security Report reveals that AI has become the #1 data exfiltration channel in the enterprise. 82% of those leaking data use personal accounts. Traditional DLP can't stop copy-paste.
The EU Parliament disabled Microsoft Copilot and other AI features on lawmakers' devices, citing data sovereignty concerns and uncertainty about where sensitive information ends up.
A 3.35B parameter multilingual model outperforms larger competitors on underserved languages - and runs locally on consumer hardware. Privacy-first AI for the rest of the world.
Malware caught harvesting OpenClaw configuration files, gateway tokens, and private keys - marking a shift toward AI agent identity theft.
Tennessee made it a felony to train AI chatbots that encourage suicide. Virginia is banning AI therapist impersonators. A dozen states have bills moving through legislatures right now.
ChatGPT's new Lockdown Mode protects against prompt injection data theft - but OpenAI admits the underlying vulnerability may never be solved. Here's what that means for agentic AI.
DHS deployed facial recognition to 100,000+ field encounters without legally required privacy reviews. Internal records show the agency knew the app couldn't verify identities.
Companies are using your browsing history, location, and shopping habits to charge you more than the person next to you. California just launched an investigation. Here's how it works.
Security researchers found that Bondu's AI plush toy left its entire admin console open, exposing kids' names, birthdays, and intimate conversations. A senator wants answers.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
Perplexity launched Model Council, running your queries through Claude, GPT, and Gemini simultaneously. Multi-model consensus could reduce hallucinations, but it triples your data exposure and costs $200 a month.
A Firebase misconfiguration exposed 300 million messages from 25 million users. A wider scan found data leaks across 196 of 198 AI apps.
European regulators charged Meta with antitrust violations for blocking competing AI chatbots from WhatsApp's 3 billion users - while Meta AI gets exclusive access to the platform.
Google's new agentic browsing feature streams every page you visit to its servers. Here's what that means for your privacy.