Every week brings a stack of security headlines, and most of them blur together. This week had a theme worth pulling out, though: artificial intelligence tools are quickly becoming both a target for attackers and, in some cases, the attack itself.
Researchers recently used an AI model to chain together two flaws and gain access to internal accounts at OpenAI, the company behind ChatGPT. Around the same time, security researchers demonstrated a technique called BragJack, which uses a malicious browser extension to hijack AI assistants built into browsers like Chrome and Edge — the kind of "AI agent" tools that can read your email, fill out forms, or browse the web on your behalf. Neither of these stories means AI tools are unsafe to use. But they're a good reminder that any tool with broad access to your accounts and data — AI included — needs the same scrutiny you'd give a new employee with admin privileges. Who can install these tools in your business? What can they see and do once installed? If you don't know the answer, that's a conversation worth having with whoever manages your IT.
Meanwhile, the more familiar side of security kept humming along. Microsoft released patches for nearly 1,000 security holes this week — its largest single update ever — which is a useful reminder that "patch Tuesday" (the regular schedule most software companies use to release security fixes) isn't optional busywork. It's how known weaknesses get closed before someone finds them first. Separately, a dark web service began selling scans of more than 153 million U.S. and Canadian driver's licenses, and a breach at the image-sharing service Gyazo exposed 23 million user records. Neither story involves your business directly, but they're part of a steady drumbeat: personal information, once stolen, doesn't stay in one place. It gets bought, sold, and reused in identity theft and phishing schemes for years afterward. If your business collects driver's licenses, ID scans, or other sensitive personal data from customers or employees, it's worth periodically asking how long you actually need to keep it and where it's stored.
There was also some good news on the law enforcement front — arrests tied to a long-running cybercrime and extortion group, plus a public spat between two ransomware gangs that ended with one hacking the other's leak site. It's a small reminder that the criminal ecosystem behind these attacks isn't invincible or unified, even if it can feel that way from the outside.
None of this requires a dramatic response from a small or mid-sized business. But it's a good week to ask two simple questions: do we know what AI tools our team is using and what access they have, and do we have a routine for applying security updates without letting them pile up? If you're not sure how to answer either one, that's what we're here for.