Microsoft detailed a new agentic AI vulnerability discovery system, code-named MDASH, that found 16 previously unknown flaws in Windows networking and authentication components, including four critical remote code execution bugs patched in the May Patch Tuesday release, SiliconANGLE reported. The system orchestrates more than 100 specialized AI agents across frontier and distilled models, spanning the Windows TCP/IP stack, the IKEEXT IPsec service, HTTP.sys, Netlogon, DNS resolution and the Telnet client. MDASH identified all 21 planted vulnerabilities with zero false positives on Microsoft's StorageDrive test driver and recorded 96% recall on five years of Microsoft Security Response Center cases. On the public CyberGym benchmark covering 1,507 real-world vulnerability reproduction tasks, MDASH scored 88.45%, the top result on the leaderboard.
Read at SiliconANGLE ↗
Google AI chatbots are surfacing real users' phone numbers and other personal contact information, including a case where an Israeli software developer was contacted on WhatsApp after Gemini provided his number in response to a customer service question, MIT Technology Review reported. Privacy-tools firm DeleteMe told the outlet that customer queries about generative AI have increased 400% in the past seven months to a few thousand, with 55% referencing ChatGPT, 20% Gemini and 15% Claude. Experts cited in the piece say the lapses are most likely caused by personally identifiable information appearing in training data, though the precise mechanism producing real phone numbers in AI outputs remains unclear. One PhD candidate at the University of Washington got Gemini to produce her colleague's personal cell phone number while testing the model.
Read at MIT Technology Review ↗
Palo Alto Networks warned that AI driven cyberattacks will become the new norm within months as more sophisticated AI models pressure cybersecurity teams to defend against faster and more autonomous attacks, CNBC reported. Industry experts told EnterpriseAI that Anthropic's Mythos model could accelerate complex cyberattacks against bank legacy systems, with Guardrail Technologies CEO TJ Marlin saying the model can "look across a very complex architecture" to expose previously undiscovered vulnerabilities. The warnings sit alongside Anthropic's Project Glasswing defensive partnership covering Amazon Web Services, Apple, Google, Microsoft and Nvidia.
Read at CNBC ↗ • Read at EnterpriseAI ↗