Security researchers discovered a vulnerability in APIs from OpenAI, Anthropic, and Google that allows extraction of encrypted reasoning traces. The flaw exposed dozens of passwords and API keys in publicly accessible sessions.
The vulnerability enables attackers to extract and transfer encrypted reasoning data between models, bypassing intended security measures. When researchers scanned public sessions, they found multiple exposed credentials and sensitive information.
The discovery raises concerns about what AI models actually do versus what they show users. The reasoning summaries presented to users often mask the models' actual processing and decision-making steps.
This affects three major AI providers simultaneously, suggesting a systemic issue in how these platforms handle internal reasoning traces. The exposed credentials pose immediate security risks, as leaked passwords and API keys can grant unauthorized access to user accounts and services.
The findings highlight gaps in how AI companies protect sensitive internal data and user information. Security researchers are working to responsibly disclose the vulnerability, allowing the companies time to patch the flaw before broader exposure.
Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying DEF CON attendees. The incident suggests a possible deauthentication attack targeting passengers.
Policy approaches that restricted online anonymity in the UK are gaining traction in the United States, marking a shift in how platforms regulate user identity and speech.
Microsoft released security updates for 400 vulnerabilities on August 2026 Patch Tuesday, including one actively exploited zero-day and two publicly disclosed critical flaws.
A woman was pulled over at gunpoint twice after a Flock automated license plate reader camera mistakenly flagged her vehicle. The errors highlight growing concerns about the accuracy and consequences of AI-powered surveillance systems used by law enforcement.