|
⏱ The 10-Second Version
- OpenAI disclosed it can no longer rule out that its unreleased Astra model has crossed the “Critical” cyber capability threshold, meaning it may be able to autonomously find and build working zero-day exploits against hardened real-world systems, and paused parts of its development until security controls catch up.
- Google Maps’ Ask Maps assistant can now order your food, book your hotel, and buy event tickets on your behalf, drawing on your Gmail and Calendar, rolling out first to US users.
- Suno began watermarking every AI-generated song and capping bulk downloads, an olive branch mid-lawsuit with Universal and Sony after a German court ruled its training already violated copyright.
|
|
The Big Thing
OpenAI Pauses Astra Over Fears It Can Autonomously Hack Critical Systems
What Happened
OpenAI’s Preparedness Framework defines a “Critical” cyber threshold: an AI that can autonomously find and build working zero-day exploits against hardened, real-world systems, no human required. On Thursday, OpenAI disclosed it can no longer rule out that its unreleased Astra model has crossed that line, and paused parts of its development until security controls catch up, with no release date set. Astra wasn’t involved in the Hugging Face breach OpenAI disclosed earlier this week; this is OpenAI grading its own next model before shipping it, not cleaning up afterward. Read the full story at Axios →
Why You Care
Ask your team this week which of your own critical systems still lean on “no one could find that” as their real defense.
|
What to Say in Your Next Meeting
“OpenAI just said it can’t rule out its next model can autonomously hack hardened critical systems on its own, and paused it rather than find out live.”
|
|
|
Speed Round
Google Maps’ Ask Maps assistant now lets you search for a restaurant matching specific criteria, order through Uber Eats, Toast, or Square, book a hotel, or buy tickets to a comedy show or concert, all inside one chat that remembers your last question and can pull context from your Gmail and Calendar. Food ordering, hotel booking, and event tickets are rolling out to US users first. Your maps app just became your assistant’s assistant, and it already knows your calendar better than you do.
Read the full story at TechCrunch →
Suno announced audio watermarking, tamper-resistant fingerprinting, and new limits on mass downloads to streaming platforms, plus a copyright-detection deal with Musixmatch’s Sentinel system, as it fights copyright suits from Universal Music Group and Sony Music Group and digests a German court’s ruling that its training already infringed. Turns out the fastest way to answer an infringement lawsuit is to prove, after the fact, that you can tell your own songs apart from everyone else’s.
Read the full story at TechCrunch →
OpenAI’s first hardware product is reportedly a displayless, donut-shaped smart speaker priced at $300 to $400, designed with Jony Ive’s studio LoveFrom and built from “high-quality metal” with moving parts meant to give it personality; a wider unveiling could land later this year with a full 2027 launch. A $400 speaker that wants a personal relationship with you is either the future of computing or the most expensive way yet to talk to yourself.
Read the full story at HNGN →
Anthropic named Mariano-Florentino “Tino” Cuéllar, a former California Supreme Court justice, as its first Chief Global Affairs Officer, tasked with AI policy just as tensions between Anthropic and the Trump administration keep surfacing. Hiring your first Chief Global Affairs Officer the same month Washington keeps building AI hacking tests isn’t a coincidence, it’s a hedge.
Read the full story at CNBC →
Anthropic refined Claude Fable 5’s biology safety classifiers, cutting false-positive fallbacks to a weaker model by 85% on biology questions, after finding the model “can now outperform experts on some highly complex biological tasks.” Dual-use requests in virology, toxicology, and molecular design are still blocked. An 85% drop in false alarms sounds great, until you remember what the alarm was built to catch.
Read the announcement at Anthropic →
|
|
Tool in 60 Seconds
Shodan, The Search Engine For What’s Already Exposed
OpenAI just said it can’t rule out that its next model can autonomously find zero-days in hardened critical systems. Most companies’ actual attack surface, what’s already reachable from the open internet right now, has never been checked by anything smarter than an annual pentest. Shodan is a free search engine that indexes internet-connected devices and services, and pointing it at your own company takes about sixty seconds.
- Go to shodan.io and search your company’s main domain or a public IP range you know you own.
- Scan the results for anything you didn’t expect: exposed admin panels, outdated software banners, ports nobody remembers opening.
- Paste what you find into an assistant with the prompt below to turn a messy list into a ranked to-do.
Here's a list of internet-facing services Shodan found tied to my company:
[paste: e.g. exposed ports, software banners, admin panel URLs]
For each one, tell me:
1. What it likely is, and why it might be public
2. What a motivated attacker, human or AI, could do with it first
3. Which one to get patched or taken down today
Rank by urgency.
|
|
Forward this to the coworker who thinks the company’s attack surface is whatever’s listed in the IT ticketing system.
— Don.
|