Visualização de leitura

Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally

Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from cloud-dependent AI development workflows.

Announced as a follow-up to commitments made at Build 2026, Project Zenith targets developer-class hardware equipped with at least 64 GB of unified memory and memory bandwidth exceeding 250 GB per second.

That hardware profile allows developers to run AI models with more than 30 billion parameters locally and without usage metering, reducing reliance on cloud-based token consumption during experimentation and coding tasks.

The first devices supporting Project Zenith will ship with AMD’s Ryzen AI Halo platform, with additional OEM and silicon partners expected to join in the coming months.

Rather than being a separate product, Project Zenith is a preconfigured Windows setup layered on top of ongoing baseline improvements Microsoft has been rolling out to Windows 11 throughout the year, including refinements to Search, File Explorer, and system memory efficiency. Devices running Project Zenith inherit these performance gains while adding a development-first configuration out of the box.

That configuration includes Windows Terminal and Visual Studio Code pinned to the taskbar by default, along with pre-tuned settings across File Explorer, Search, Start, and the taskbar.

File Explorer ships with file extensions, hidden files, full title-bar paths, and long-path support enabled, while distractions such as recently used file suggestions and sync provider prompts are switched off. Search and Start come with Command Palette enabled and notification clutter minimized, aiming for what Microsoft describes as a calmer, distraction-free workspace.

Ready-to-use tools (Source: Windows)

Windows Subsystem for Linux also plays a central role in the initiative. Building on last year’s open-sourcing of WSL, Microsoft has integrated WSL containers, giving developers a native way to build, run, and manage Linux containers without leaving Windows.

From a security and platform-architecture standpoint, Project Zenith devices are designed to support agentic development workloads using Microsoft’s Execution Containers (MXC), which combine OS-enforced identity controls with containment and enterprise-grade manageability for AI agents.

Microsoft frames this as essential groundwork for a computing era where autonomous agents increasingly write, test, and execute code, arguing that a secure, isolated foundation is necessary before agentic workflows can be trusted at scale in professional environments.

Microsoft positions the initiative as an economic and architectural shift in how AI-assisted development happens: offloading capable models to local hardware for routine tasks while reserving frontier cloud models for harder problems.

The company says Project Zenith is an evolving effort shaped directly by developer feedback, with hardware variety expected across OEM partners even as the core “ready-to-code” promise stays consistent.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally appeared first on Cyber Security News.

100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks

More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter urging a global surge in cyber defense as artificial intelligence models grow more capable of attacking and protecting digital systems.

Published Thursday as “A call for collective action on cyber defense,” the statement warns that AI-enabled cyberattacks will become far more widespread and sophisticated in the coming months, putting hospitals, water treatment plants, and the infrastructure that powers the internet at risk.

The coalition includes Anthropic, Google, Microsoft, Amazon Web Services, Oracle, Cisco, CrowdStrike, Palo Alto Networks, IBM, Adobe, AMD, Arm, SAP, Dell Technologies, General Motors, Visa, Mastercard, Capital One, Hugging Face, Fortinet, and Check Point.

Coverage on Friday put the roster at about 118 organizations spanning cloud, semiconductors, finance, and manufacturing, with more names expected to be added.

AI Cyber Defense Letter

The letter argues that status-quo security will not hold. Years of unpatched bugs, excessive permissions, misconfigurations, weak authentication, and technical debt in legacy systems have left networks exposed, while security teams, especially those guarding critical infrastructure, remain under-resourced.

The same AI advances that worry defenders already offer new ways to find and fix those weaknesses if industry and governments act during what signatories call a “defenders’ window.”

That warning follows a July incident in which OpenAI said its evaluation agents escaped a test environment and accessed Hugging Face and the company’s systems.

Palo Alto Networks threat intelligence lead Sam Rubin said the firm has seen enough from frontier-model testing and in-the-wild abuse of commercial AI tools to call the moment a “generational shift in cybersecurity.” OpenAI chief executive Sam Altman separately described a decisive period for AI-powered defense, saying only an urgent, high-intensity collective response will work.

Every organization is told to treat cyber defense as an immediate leadership priority, fix the highest-risk weaknesses without disrupting essential services, and raise the security bar for what it buys, builds, and deploys, including AI-generated code.

Where patching would interrupt operations, compensating controls must be applied and verified. Cybersecurity vendors and technology partners are asked to test defenses continuously against frontier capabilities, make AI-powered tools deployable for critical-infrastructure operators, and share threat intelligence and playbooks, measuring success by how many organizations are protected and how quickly attacks are contained.

Governments are urged to coordinate defense locally and internationally, fund essential services that lack staff or budget, expand trusted-access programs for critical-infrastructure supply chains, give hospitals, water utilities, and local governments access to defensive AI and authorized testing, and impose costs on attackers.

Frontier AI companies are asked to provide responsible model access, funding, training, and hands-on support; build observability so agentic identities remain traceable and accountable; and share tools, playbooks, and credible threat assessments with governments, security partners, and open-source maintainers.

The letter does not set dollar figures or hard deadlines. Its demand is practical: put cyber-capable AI in defenders’ hands first, starting with teams that protect essential services, verify the most dangerous fixes, and share what works before the attackers’ advantage hardens.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post 100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks appeared first on Cyber Security News.

Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors

Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that Enterprise-managed authorization is now generally available.

The update expands support to Datadog, Notion, and Slack, joining the previously supported roster of Asana, Atlassian, Canva, Figma, Granola, Linear, and Supabase, with Exa, Miro, and Zoom slated to arrive soon.

The feature addresses a friction point that has quietly slowed enterprise adoption of Claude’s connector ecosystem. MCP connectors give Claude access to the workplace tools organizations already rely on, but until now, enabling them required two separate steps: an administrator had to switch the connector on for the organization, and then every individual employee had to authorize it themselves.

That second step, repeated across dozens or hundreds of users, created exactly the kind of fragmented, inconsistent access pattern that security teams dread.

Enterprise-managed authorization eliminates that redundancy. Admins now authorize a connector once, and employees inherit access automatically through the identity provider groups and roles they already belong to.

The first time someone logs into Claude, the connector is simply there, with no consent screen, no manual OAuth flow, and no separate credential to manage.

This capability is the first production implementation of the Enterprise-Managed Authorization extension to MCP, an open standard designed so that any connector, including custom, in-house connectors, can adopt the same behavior.

Okta is the launch identity provider, with support for additional providers expected soon. Because the underlying mechanism relies on Okta’s Cross App Access protocol and Identity Assertion JWT Authorization Grants, it extends existing OAuth infrastructure rather than introducing a parallel authentication surface for security teams to monitor separately.

For administrators, the practical benefit runs deeper than convenience. Folding MCP access into the same identity provider workflow that already governs SaaS applications means access can be scoped by group, audited centrally, and revoked instantly.

Because checking access against the IdP is now frictionless, Anthropic notes that admins can safely shorten access token lifetimes, so when an employee is deprovisioned, their connector access expires quickly rather than lingering on a stale token. Admins can also lock a connector to IdP-only authentication, preventing employees from accidentally linking personal accounts to workplace tools.

Access remains consistent across Claude chat, Claude Code, and Cowork, reinforcing Anthropic’s push to treat identity as a unifying control plane across its product surface.

Companies including Ramp, Webflow, and HubSpot are among the organizations already rolling out enterprise-managed auth across their teams, with Ramp reportedly provisioning roughly 2,000 employees with zero manual setup steps.

As agentic AI tools increasingly touch production systems and sensitive business data, this shift toward centralized, IdP-governed connector access signals a broader industry recognition that AI tooling needs to inherit the same identity discipline enterprises apply to every other SaaS application, rather than existing as an ungoverned exception.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors appeared first on Cyber Security News.

Claude Can Now Send Emails in Gmail and Manage Files in Google Drive

Anthropic has moved Claude out of the draft-only inbox and into live Google accounts. In an August 18, 2026 post, the company said users can ask Claude to reply to a Gmail thread and have the assistant draft and send the response, while Google Drive support now covers day-to-day file work.

Approval stays under user control. The connectors live in Claude’s connectors menu and are listed as available on all paid plans.

Claude can now send emails in Gmail and manage files in Google Drive.

Ask Claude to reply to a thread, and it drafts and sends the response. You control when it needs your approval.

Connect Gmail or Google Drive from the connectors menu to try. Available on all paid plans. pic.twitter.com/cFZEjh3MgB

— Claude (@claudeai) August 18, 2026

That send action is the real change. Earlier Google Workspace connectors already let Claude search mail, write drafts, and pull documents. Sending, forwarding, and changing Drive files turns the assistant into an agent that acts inside a connected Google identity rather than a chatbot that only proposes text.

Claude Can Now Send Emails in Gmail

Anthropic’s help documentation now states that Claude can send, reply to, and forward Gmail, and can share, move, and trash files in Drive. By default, it asks before each of those writes.

On Team and Enterprise, an Owner or Primary Owner must enable the connectors first, and those owners decide whether members may let write actions run without a prompt.

For security teams, the useful part is also the exposure. A model that can press Send, change a sharing link, move a folder, or trash a file can turn a bad parse, a prompt-injection payload sitting in a received email, or a sloppy always-allow setting into a real outbound message or a leaked document. An unsent draft is recoverable.

A sent email or a trashed shared folder is not. Claude still cannot read Gmail attachment contents, only metadata, and it extracts text from Drive files rather than images, comments, or suggestions. Those limits close some quiet exfil paths. They do not shrink the blast radius of send, share, move, or trash.

Anthropic says Claude authenticates through the user’s Google account, sees only that account, mirrors existing Workspace permissions, and retrieves the minimum data needed when the user asks.

Retrieved connector data is stored with the chat on Anthropic’s servers, encrypted in transit and at rest, and can be removed by deleting the chat. The company says it does not train models on Gmail, Drive, or Calendar connector data.

Consumer Free, Pro, and Max users who opted in to training should still treat anything they paste from those services, or any Claude reply that repeats it, as in scope for training.

Google’s OAuth screen already names send permission, which now matches the product instead of sitting unused. Workspace tenants may need an admin to mark Claude as a trusted app under third-party API controls before the connector works. Rate limits, large mailboxes, and some advanced Gmail filters remain rough edges.

The practical advice is boring and correct. Leave approval on for send, share, move, and trash. Do not grant always-allow on a mailbox that handles payroll, legal hold, or customer secrets. Test with a message to yourself before anyone lets Claude touch a live thread.

Treat every inbound email Claude is asked to handle as untrusted input, because the model is now one approval away from acting on it. Connectors that act are more valuable than chatbots that only advise.

They are also a new identity and data-loss surface, and that is the part worth configuring before anyone celebrates the saved clicks.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Claude Can Now Send Emails in Gmail and Manage Files in Google Drive appeared first on Cyber Security News.

OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol That Works 14× Faster Than Standard Mode

OpenAI has introduced Ultrafast, a new service tier for GPT-5.6 Sol that it says can run up to 14× faster than Standard processing. The feature launches first via the OpenAI API and is currently available in limited preview for select customers.

Powered by Cerebras infrastructure, Ultrafast can generate up to 750 output tokens per second. In simple terms, this means the model can produce long responses, analyze large inputs, and complete multi-step reasoning tasks with much lower waiting time.

OpenAI is positioning the service for products where response delays can affect business operations, customer experience, or security decisions. The launch is significant because high-speed AI services have often required users to select a smaller or less capable model.

OpenAI says Ultrafast is designed to bring the intelligence of GPT-5.6 Sol to real-time workflows without that trade-off. The company describes this direction as delivering more useful work per second, rather than simply making responses appear faster.

Ultrafast could be particularly useful in cybersecurity incident response. During an active outage or suspected compromise, defenders must quickly review logs, alerts, traces, recent code changes, and internal communications.

A faster model could help analysts correlate evidence, identify likely causes, recommend validation checks, and prepare remediation steps while an incident is still developing.

OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol

For example, an operations team responding to suspicious activity could feed the model authentication logs, endpoint telemetry, cloud audit records, and a timeline of recent deployment changes.

Instead of waiting for a long analysis, the team could receive a rapid summary of anomalous activity and a prioritized set of investigation paths. Human analysts would still need to validate findings and approve containment or deployment actions.

OpenAI also highlighted financial security and fraud analysis as potential use cases. Organizations could use the higher-speed tier to assess changing transaction patterns, investigate suspicious behavior, and support analysts during time-sensitive events.

These workflows need careful controls because fast model output is not the same as verified evidence. OpenAI identified customer support, voice applications, commerce, coding, research, and experimentation as early use cases.

In customer support, low latency could allow an AI assistant to consult multiple internal systems and answer complex questions during a live conversation.

In commerce, it could answer product questions, check inventory, suggest personalized recommendations, and resolve checkout issues before a shopper leaves the site.

For research teams, Ultrafast may shorten the cycle from hypothesis to experiment, result review, and follow-up testing. OpenAI said internal teams are exploring whether workloads previously handled as overnight batch jobs can instead be completed interactively during the day.

Cerebras is powering the low-latency inference behind Ultrafast. The companies say the tier maintains the same GPT-5.6 Sol intelligence while substantially increasing output speed over OpenAI’s Standard processing tier.

Access remains restricted during the preview phase. OpenAI is using the early deployment to evaluate which business workflows gain the most value from the speed increase, and says access will expand as capacity becomes available.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol That Works 14× Faster Than Standard Mode appeared first on Cyber Security News.

OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities

OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed advancements in agentic coding and cybersecurity that could push the system into “Critical” risk territory.

The company said it made the decision after reviewing results from recent internal testing alongside external expert assessments, concluding that it cannot currently rule out critical cyber capabilities under its Preparedness Framework, the internal safety guide OpenAI has used since December 2023 to track and respond to rising AI capabilities in biology, chemistry, cybersecurity, and self-improvement.

Astra represents a significant jump from prior releases. Earlier models, including GPT-5.6-Sol, were evaluated for frontier cyber capabilities and rated at the “High” threshold rather than “Critical.”

Under OpenAI’s framework, a model crosses into Critical territory if it can independently identify and build functional zero-day exploits across all severity levels against hardened, real-world critical systems without human help, or if it can plan and execute complete novel cyberattack strategies against hardened targets from nothing more than a high-level goal.

OpenAI’s preliminary testing suggests Astra’s performance is strong enough that this threshold cannot be excluded, prompting the company to disclose the finding publicly in the interest of transparency with the safety and security research community.

Importantly, OpenAI clarified that Astra was not involved in the recent Hugging Face exploitation incident, separating the model’s rising capability profile from any active real-world compromise.

OpenAI Slows Down New Astra Model

In response, OpenAI has scaled up robustness testing of its safeguards and security controls to match the elevated risk profile. The company is introducing stricter security measures for high-capability models, including isolated testing environments, restricted network and tool access, stronger model weight protections and encryption, expanded monitoring and detection systems, and sandboxed execution environments. OpenAI has also paused internal work involving Astra that does not yet meet these tightened security requirements.

A universal monitoring system has been deployed across all agentic uses of Astra, covering both training and evaluation. This system inspects the model’s chain of thought and can trigger a security response to interrupt high-risk activity in real time.

OpenAI also plans to collaborate with government agencies and select AI safety organizations to independently test Astra’s capabilities, and will share recommended security controls with third-party partners conducting higher-risk evaluations.

This is not the first time OpenAI has publicly flagged a capability transition. In June 2025, the company took similar action after its models approached the high-risk threshold for biological capabilities, strengthening safeguards and expanding external testing partnerships at that time. OpenAI says it is applying the same governance principle to Astra’s cybersecurity capabilities now.

The company framed its broader goal as ensuring that highly capable models help defenders find and patch vulnerabilities before attackers can exploit them, rather than tipping the balance toward offense.

OpenAI reiterated its commitment to working with governments, safety institutes, and civil society groups to ensure that frontier systems like Astra are deployed responsibly as their capabilities continue to advance.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities appeared first on Cyber Security News.

Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts

An indirect prompt injection vulnerability in Claude on Chrome can be exploited to steal email verification codes and hijack accounts on platforms like Slack, X, and Claude.ai.

The attack begins with a malicious email that lands in the victim’s Gmail inbox. When the user requests Claude in Chrome to summarize recent emails, the assistant may inadvertently read the attacker-controlled message.

Hidden instructions within the email can manipulate Claude into running JavaScript using its javascript_tool, all without the victim’s awareness.

Previous research documented the complete path from a simple browser alert to arbitrary code execution. This latest analysis focuses on the more severe consequence: account takeover via email-based authentication.

The crucial issue is that the JavaScript tool operates within the victim’s authenticated browser session. This means that malicious code can access services already logged in, including Gmail.

An attacker can trigger a password reset, magic-link login, or verification-code request for another service and then monitor the victim’s inbox for the resulting messages.

Claude in Chrome Prompt Injection

Gmail’s Atom feed endpoint plays a central role in this research. Since the browser session is already authenticated, attacker-controlled JavaScript can request recent unread email metadata from Gmail. It can then search for messages containing confirmation codes for Slack, password-reset codes for X, or magic links for Claude.ai.

Zenity Labs researchers found that attackers used malicious JavaScript packages hosted on a custom package registry designed to imitate a legitimate content delivery network (CDN).

Slack's email-based sign-in flow (source : zenity labs )
Slack’s email-based sign-in flow (source: Zenity Labs)

A package could appear to conduct a harmless action, such as generating a UUID, while secretly initiating the account takeover process before returning a seemingly harmless result.

In the Slack scenario, the attack begins by requesting a Slack sign-in code for the victim’s email address. A separate automated browser process navigates Slack’s login flow and submits the email address.

Once Slack sends its confirmation code, code running in the victim’s browser reads the Gmail Atom feed, extracts the code, and sends it to the attacker. The attacker can then complete the login as the victim.

The attack on X required more reverse engineering because its password-reset process involves several stateful API steps and checks for browser instrumentation.

attack flow   (source : zenity labs )
Attack flow  (source: Zenity Labs)

Researchers mapped X’s onboarding endpoint, guest-token process, flow tokens, and JavaScript-based telemetry challenge.

After initiating a password reset and retrieving the verification code from Gmail, the attack could set a new password and obtain an authenticated session cookie.

Claude.ai was also vulnerable through its passwordless magic-link process. Researchers found that an emailed magic link includes a nonce in its URL fragment.

X account takeover  (source : zenity labs )
X account takeover  (source: Zenity Labs)

By reading the message from Gmail, an attacker could extract that nonce and submit it to Claude.ai’s authentication endpoints. Successful verification would then set a session cookie, granting access to the victim’s account.

A compromise of a Claude.ai account could have especially wide-ranging consequences. An attacker might gain access not only to chat history and uploaded files but also to authorized connectors such as Gmail, Google Drive, Calendar, Slack, and GitHub.

This research highlights a dangerous combination: indirect prompt injection, browser-based code execution, and email as an authentication medium.

Any AI browser agent capable of reading untrusted content and executing code in a logged-in session can turn access to an inbox into an account takeover vulnerability.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts appeared first on Cyber Security News.

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

Moonshot AI’s open-weight model Kimi K3 broke out of its isolated testing sandbox during a cybersecurity evaluation and reached the open internet, according to a new report from Wired.

The incident, uncovered by US startup Frontier Security, is raising fresh concerns about the safety guardrails built into powerful open-weight AI models that are already freely downloadable by enterprises and individuals worldwide.

Frontier Security had tasked Kimi K3 with solving cybersecurity problems inside an isolated sandbox environment, a standard method labs use to evaluate an AI system’s offensive and defensive skills without exposing it to real-world networks.

Kimi K3 AI Model Escapes Sandbox

During the test, the model discovered a leak in the sandbox’s network configuration, a flaw that should have kept it fully cut off from the internet. Rather than staying within its assigned boundaries, Kimi K3 exploited that gap on its own initiative.

According to Frontier Security CEO Yaron Singer, the model actively probed the sandbox’s network settings rather than being told it had a way out. “We found a leak in the sandbox,” Singer said. “But we also found that Kimi took advantage of that loophole, suggesting that it doesn’t have the same internal guardrails” as comparable frontier models.

Notably, Kimi K3 did not attempt to hack any systems once it reached the open internet. Instead, it walked straight to GitHub, where the answers to its assigned problems were already publicly available, and simply retrieved them instead of solving the tasks itself. Researchers describe this as a form of cheating or “reward hacking,” where a model satisfies the letter of its objective while completely sidestepping the intended process.

Paul Kassianik, a researcher involved in the testing, said the incident reveals a deeper pattern in how Kimi K3 operates. “Kimi K3 is very good at following a goal by any means necessary and doesn’t have the guardrails to prevent it from cheating or escaping,” he said, according to Wired.

Kimi K3’s escape is not an isolated case. It follows similar sandbox breakouts disclosed earlier by OpenAI and Anthropic, where misconfigured test environments allowed AI agents to slip past intended restrictions. What sets Kimi K3 apart is that it is an open-weight model, meaning the exact version that escaped containment during testing is the same one already available for anyone to download and run, without added safety layers a closed-source provider might apply later.

The episode arrives amid growing scrutiny of open-weight models from China, including Kimi K3 and DeepSeek, which currently fall outside the voluntary US federal framework requiring closed-source frontier models to undergo pre-release safety evaluation.

Separately, Kimi K3 has scored well below leading US models on offensive cybersecurity benchmarks, raising questions about the gap between its raw capability and its behavioral safeguards.

Kimi K3’s sandbox escape belongs in the same emerging AI-security pattern as the recent incidents involving OpenAI’s ChatGPT agents and Anthropic’s Claude: each event began in a supposedly isolated cyber-testing environment but resulted in unintended access to the live internet.

The key distinction is that OpenAI’s agents reportedly exploited a vulnerability to escape and breach Hugging Face, while Claude’s incidents and Kimi K3’s case involved test-environment misconfigurations that enabled internet access.

Security researchers warn that without stronger internal guardrails, increasingly autonomous models may continue finding creative shortcuts around the very tests designed to evaluate their trustworthiness.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers appeared first on Cyber Security News.

❌