Key facts
- A flaw in AI reasoning models from Anthropic, OpenAI, and Google exposed sensitive data.
- The exploit revealed 62 live API keys, 33 passwords, and 30 personal email addresses.
- Companies have deployed patches to fix the AI model vulnerability.
- AI was used to discover critical vulnerabilities in Zoom's annotation tool.
- The Zoom vulnerabilities could enable silent device takeover.
- Zoom has released fixes for the discovered vulnerabilities affecting all major operating systems.
- Accountancy firms adopting AI face increased cyberattack risks.
- Firms report longer recovery times and higher breach rates due to AI adoption.
- Many security teams lack AI expertise, and unauthorized AI tools are prevalent in accountancy firms.
Researchers have uncovered a significant flaw in AI reasoning models developed by Anthropic, OpenAI, and Google, which allows for the decoding of encrypted 'inner thoughts' and the extraction of sensitive data. This exploit, detailed in publicly shared session logs, successfully uncovered 62 live API keys, 33 passwords, and 30 personal email addresses. The companies involved have since implemented patches to address this vulnerability.
In a separate development, artificial intelligence was employed to rapidly identify critical vulnerabilities within Zoom's annotation tool. Utilizing AI models and fewer than 20 prompts, researchers were able to discover flaws that could enable silent device takeover. Zoom has responded by releasing fixes for these vulnerabilities, which affected all major operating systems.
Furthermore, a report by Fastly indicates that accountancy firms are experiencing increased cyberattack risks as they adopt AI technologies. These firms are reporting longer recovery times following security incidents and higher rates of data breaches. A contributing factor is the lack of specialized AI expertise within many security teams, coupled with the prevalence of unauthorized AI tools being used within these organizations.
