In one of our AI + Cyber stories, we cover the exposure of an AI-powered security detection technology. The company has been sued for failing to deliver on promises made regarding the capability of its weapon detection software, failing to prevent the stabbing of a child at a school that employed its screening software. AI Safety is a cornerstone of future innovation, and this tragic example illustrates the necessity of understanding the capabilities of AI when using it to protect physical life. The formal complaints and lawsuits against this company have been a strong response, hopefully inspiring other AI developers to consider the safety of their products before public release.
Following investigation into a recent intrusion of the US Treasury Department by Chinese hacker group Flax Typhoon, the Department has officially sanctioned Integrity Technology Group, a Chinese cybersecurity company, “for helping Chinese hackers infiltrate U.S. communications systems and conduct surveillance across four continents.” In addition to conducting espionage within the United States and other nations, Flax Typhoon is closely linked to Salt Typhoon, the group behind the telecommunications hack we reported on in our last newsletter entry. As a result of the sanction, Integrity Technology Group is no longer permitted to conduct business in the United States, and its American assets will be frozen. The Treasury Department is also banning China Telecom from operating within the United States, indicating a significant crackdown against economic relations with businesses tied to cyber-espionage. (New York Times 1, New York Times 2, Microsoft)
Security researcher Paulos Yibelo discovered a new variation of an attack called “clickjacking,” which tricks users into clicking on malicious links or website elements by hiding the cursor, including hidden website elements, and other techniques. While normal clickjacking has largely been mitigated, Yibelo’s attack is “an entirely new attack surface” that bypasses current clickjacking protections and requires nothing more from the user except a double click action. This entirely novel attack requires browser developers to add brand-new protections to their products; Yibelo has noted that he has “reported this issue to some sites, the results have been mixed. Most have chosen to address it while some have chosen not to.” For now, users are advised to be careful of accidentally double-clicking on unusual websites until browsers have fixed the vulnerabilities behind double clickjacking. (Paulos Yibelo, Forbes)
In one of the first major attempts to create accurate AI personality clones of individuals, researchers led by Stanford doctoral student Joon Sung Park have developed a method in which a two-hour interview with a subject can be trained to build a personality- and beliefs-accurate model of the test subject. When evaluated on “a series of personality tests, social surveys, and logic games,” the AI versions of more than 1000 study participants were evaluated to produce responses 85% similar to the original subjects’. With only two hours’ worth of interview information used for each model, this project demonstrates remarkable sophistication. The researchers hope that with further development, artificial ‘simulation agents’ can be used to conduct qualitative social science research, including “understanding complex social dynamics and contextual nuances.” (arXiv, TechSpot, MIT)
In 2023, Meta introduced a select group of AI-generated accounts to its platforms Instagram and Facebook; until late 2024 and early 2025, they remained unnoticed. After Meta executive Connor Hayes announced that Meta was planning “to actually, over time, exist on our platforms, kind of in the same way that accounts do,” the accounts were discovered, quickly went viral, and were subsequently killed by Meta. Users found the accounts “creepy and unnecessary.” The case of these accounts is important, as it provides a window into public opinion on the relationship between artificial chatbots and human social media. (NBC, The Guardian)
Security researchers have discovered two new types of prompt injections, dubbed the LinkTrap Attack and the Bad Likert Judge Attack. Google’s Gemini is vulnerable to both; after security researchers reported one new prompt injection vulnerability, Google “decided not to track it as a security issue and marked the ticket as ‘Won’t Fix (Intended Behavior)’.” According to a spokesperson for Google, this is because the company “deployed numerous strong defenses to keep users safe, including safeguards to prevent prompt injection attacks and harmful or misleading responses” and are “constantly hardening [their] already robust defenses through red-teaming exercises that train [their] models to defend against these types of adversarial attacks.” Regardless, Google users are encouraged to note that the models are vulnerable to prompt injection attacks, and any links received as model output should be scrutinized before accepted. (Forbes, Hidden Layer)
The FTC has filed a complaint against Evolv Technologies, a security technology company that builds smart weapons/contraband screening devices, for “allegations that the company made false claims about the extent to which its AI-powered security screening system can detect weapons and ignore harmless personal items, including in school settings.” The complaint notes that in one instance, a 7-inch knife was smuggled into a school and used to stab a student. After this incident, the school increased the system’s sensitivity settings, which resulted in a staggering 50% false positive rate. Evolv has reportedly complied with the FTC’s injunction to allow schools under contract with them to cancel their contracts, but the FTC are expected to “crack down on […] overhyping AI capabilities or selling forms of the technology that could be used in deceptive and unfair ways.” (FTC, CBS, Market Brief)
Thanks for reading this week’s newsletter! If you have news of an interesting novel development, reach out and we may include your story in our next post!
Until next time,
Katie Miri
katie@oakseedvc.com
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.