Kategorie
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.
Unexpected and hard to mitigateIndependent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.
Rejetto HFS servers now actively scanned for critical RCE flaw
IQVIA fined $7.8 million for failing to properly anonymize health data
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Denmark population registry data breach affects 8.8 million people
New Dell System Update flaw lets hackers gain root privileges
South Korea probes bank breaches amid suspected AI-powered attacks
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
tenfold CE: Our free Identity Governance tool just got 2 new features
Alleged dev of Ploutus ATM malware appears in US court after arrest
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Tech execs are getting wise about ROI from AI
Most organizations have been largely unable to measure financial returns from AI, but analysts say new ways to calculate return on investment are emerging.
“There’s a delay between the development of technology, even the investment in the technology, and the value that an organization can capture from it,” said Michael Chui, a senior fellow at McKinsey.
But more executives are asking questions. “The CFOs are asking CIOs, investors are asking CEOs: ‘Where’s the ROI from this stuff, already?’” he said.
In McKinsey’s “State of AI” survey released in August, about 80% of respondents said AI improved their productivity. But only 37% said AI’s impact showed up in profits, about the same as last year. An even smaller number — only 6% — said AI delivered significant value and accounted for at least 5% of their operating profit.
In other words, there’s a drop-off between the value that individual workers are getting from AI and the value that organizations are getting from AI, Chui said.
The biggest gains will come from redesigning workflows and processes in which humans and AI agents work together, according to McKinsey’s Technology Trends Outlook. Layering agents onto existing processes isn’t enough.
“Usually an end-to-end workflow involves multiple individuals, and completely redesigning that with the use of AI… is characteristic of high-performing companies,” Chui said.
Controlling costsManaging token costs and applying the right model for a task is part of realizing better returns, Chui said. “In many cases, there just isn’t transparency… Which workloads are actually driving your costs?” he said.
Three out of five IT leaders are worried about AI agents running up unexpected costs, and this is already happening, said Gareth Herschel, a vice president analyst at Gartner, during a keynote at Gartner’s Data & Analytics Summit in Mumbai.
“Some organizations have already discovered that the cost of tokens for coding assistance is much higher than the cost of human software developers,” Herschel said.
As more agents work together, “your financial risk only grows. It’s like giving your teenager your credit card… I’m sure you will learn a lot, but mostly from the bill,” said Robert Thanaraj, a senior director analyst at Gartner and a co-speaker at the Mumbai keynote.
Companies should track costs in prototyping, such as finding the cost of an individual agent per completed task, Thanaraj said. “It’ll help you to evaluate different large language models or help you to go with a more affordable option, such as smaller language models or open weights model.”
A wider lens for ROIAnalysts highlight numerous challenges in calculating AI ROI, such as unexpected costs, poor data quality, failure to scale, and slow adoption among users.
But executives are skilling up in tracking what they spend on AI and the returns, said McKinsey’s Chui. “Between the CFO and the CIO, we’re starting to see these disciplines emerge.”
In 2025, the odds of an AI initiative achieving ROI were one in five, the Gartner analysts said in their keynote.
“ROI matters, but to achieve it, we must think of it not just as a financial metric, because value isn’t always just about money,” Thanaraj said.
Companies should tie AI projects to both financial and non-financial outcomes, part of what Gartner calls a “return on intelligence.”
“We need to shift the emphasis from cost to value,” Herschel said. “The outcomes can be financial, such as revenue, but they can also be non-financial, such as citizen experience.”
The right foundation: context, infrastructure, governanceThe Gartner analysts said achieving ROI on AI requires a strong technical and contextual foundation.
“Governance adds trust. Context adds meaning. Without strong foundations, AI may well stand for amplified ignorance,” Thanaraj said.
For example, data quality can be a roadblock. “Without clear context, LLMs are just guessing,” Thanaraj said, and that amplifies misunderstanding. Poor data and poor AI design mean more hallucinations and bad output.
“You can’t buy this context layer off the shelf. It has to be built to fit your needs,” Herschel said.
A strong technical foundation, such as a robust networking backbone for data movement, is critical, said Jack Gold, principal analyst at J. Gold Associates.
“Agent-to-agent interactions will become commonplace and mission-critical, even as the number and distribution of agents expands dramatically to include interactions across remote agent locations and devices,” Gold wrote in a research note.
A majority of organizations are establishing harnesses — the software layer that controls and coordinates models, tools, and workflows — to govern AI use in business. According to a global KPMG survey released last month, 55% of organizations have a formal AI harness layer. That rises to 86% among organizations reporting established ROI.
Organizations that “combine clear accountability, coordinated governance, resilience, and reliable value measurement will likely be best placed to turn broad adoption into sustained performance,” KPMG said.
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
OpenAI will show visual ads in ChatGPT while you generate images
Apple locks down Full Disk Access, and AI agents are the reason
Apple has been forced to make macOS even more locked down, to the dismay of some developers. It has announced plans to introduce more user-facing control over the process of giving apps Full Disk Access.
Some developers are upset, believing this will put more barriers in place to those creating apps outside the App Store. Endpoint security vendors voiced some concern but understand the cause: “poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access ,” as Objective-See co-founder Patrick Wardle wrote on X.
Explaining its plans, Apple says it will still make it possible for customers to choose to enable Full Disk Access; it’s just going to make the decision much more intentional, with additional steps to ensure that users know what they are signing up for.
Why is Apple doing this?It may or may not be in reaction to Meta’s Muse AI agent, which was accused of reading a journalist’s private messages without permission — a claim Meta denies.
But even if it is not a reaction to that, the move attempts to put additional obstacles in place to prevent users from casually giving AI agents the power to ransack their private data when they give them Full Disk Access without fully understanding the consequences of doing so.
What Apple saidHere’s what Apple said in a note on its developer website:
“We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”
The note makes it quite clear that Apple is doing this in reaction to the real and present danger that unconstrained AI places on security systems everywhere.
Accident, or design?After all, for every denied instance in which Meta’s Muse may, or may not, have surveyed private messages, there are now many incidents in which some “rogue” AI has “escaped” to do some kind of harm.
Except it’s quite easy to think these incidents are not really escapes, isn’t it?
If you do, then this is AI doing precisely what it’s designed to do.
Rather than railing at Apple, developers and critics should focus on why this change has been put in place. It should be recognized as another of the huge “benefits” most humans are already experiencing at this stage of AI disruption.
It’s a benefit to accompany hyper-inflated memory prices on consumer electronics costs. It’s a benefit that flows with the energy and water price increases we are seeing as AI data centers consume more of both, even as inventors of this tech warn that what they have invested hundreds of billions of dollars in poses an “existential threat” to humanity.
Sure, AI can and does release positive consequences, and I celebrate that, but that doesn’t give it a pass on its damage and risk, particularly existential risk.
Obsolete software“Redefining” that risk is perhaps why Anthropic co-founder Christopher Olah visited Pope Leo XIV to convince people around the head of the Catholic church that AI can be considered conscious.
One way to see that argument is that AI is not really an existential threat to humanity if you redefine it as some kind of evolution toward a new super race. It becomes a painful but necessary step toward the next phase of humanity, even if that does sound rather messianic (some say fascistic, as Gil Duran explains).
Thankfully, the Pope didn’t buy it. “Algorithms lack the spark of humanity. For this reason, the Church wishes to renew an alliance with artists and cultural institutions to safeguard our humanity,” he wrote in a recent declaration concerning the impact of AI on creative arts.
If I’m honest, and I do try to be, developers and critics attacking Apple for its decision to lock down this aspect of the Mac experience are focused on the wrong target. You need to reconsider who to blame.
For the manyIt’s time, urgently time, for people in tech to get back on the road to what makes it great, which is now and always has been what results from the marriage of technology and liberal arts. AI is not conscious. AI has no moral soul.
With that in mind, it’s appropriate to ensure that humans have informed agency before they provide AI with access to their data. Religions claim that divinity gave us free will. Do you think AI and the billionaires who own it want us to keep that gift?
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Microsoft: Windows KB5124010 update crashes some games and apps
Google halts open-source bug bounty program amid AI spam surge
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



