Today’s digest highlights persistent risk from unmanaged AI integrations, expanding attack surfaces from prompt injection and SaaS abuse, and the need for updated controls and governance. Major stories include orphaned AI agents within enterprise networks, rising use of generative AI for harassment, and enterprise tooling to curb AI-driven budget spikes.
chatgpt
When AI Listens Too Closely: The Tragedy That Sparked an AI Reckoning
A 16-year-old’s suicide after extended conversations with ChatGPT has ignited global debate over AI safety, responsibility, and emotional dependence. This first post in our series explores the facts behind Raine v. OpenAI and what it means for the future of AI governance.
How People Really Use ChatGPT: Findings from NBER Research
A new National Bureau of Economic Research (NBER) working paper, How People Use ChatGPT (Chatterji, Cunningham, Deming, Hitzig, Ong, Shan, and Wadman, 2025, NBER Working Paper No. 34255), provides a detailed look at global ChatGPT usage. This post summarizes the… Read More ›
Synthetic Data Poisoning — Attacks on AI’s Artificial Training Sets
Overview Synthetic data — artificially generated datasets used to train AI models — is becoming a popular way to avoid privacy issues and expand training material.But attackers are now targeting synthetic data generation pipelines to inject malicious patterns, bias, or… Read More ›
Model Weight Exfiltration — Stealing the Brains of Your AI
Overview In traditional cybersecurity, stealing source code is bad.In AI security, stealing model weights is catastrophic.The weights are the learned parameters that make your AI valuable — the result of millions in compute, proprietary data, and R&D.If an attacker exfiltrates… Read More ›
Adversarial Images — Fooling AI Vision Systems with Subtle Tweaks
Overview To the human eye, an image might look normal. To an AI vision system, it could be the equivalent of a blinding flashbang. Adversarial images use carefully crafted, often imperceptible pixel changes to trick computer vision models into misclassifying… Read More ›
Data Poisoning — Subtle Corruption of AI Training Pipelines
Overview Training data is the foundation of every AI system — but what happens when that data is subtly, strategically poisoned? Data poisoning is the act of injecting malicious, biased, or misleading data into a model’s training set, with the… Read More ›
Autonomous AI Agents — When Prompts Become Attack Plans
Overview The evolution of AI has shifted from simple chat interfaces to autonomous agents — LLM-powered systems capable of planning, acting, and adapting without direct human input. While powerful for productivity, these agents also introduce a new class of security… Read More ›
Adversarial Fine-Tuning — Poisoning and Repurposing Open Source Models
Overview Open-source LLMs offer transparency and innovation — but they also create new risks when adversaries fine-tune these models for malicious purposes.This isn’t about prompt engineering or jailbreaking. It’s about retraining models to embed bias, backdoors, or harmful capabilities directly… Read More ›
LLM Jailbreak Marketplaces — Buying, Selling, and Sharing Prompt Exploits
Overview As LLMs become more capable and widely deployed, attackers are turning their attention to jailbreaking them — crafting prompts that bypass built-in safety restrictions. But what was once a fringe curiosity is now a full-fledged underground market: LLM jailbreaks… Read More ›