ai agents11 articles
Claude for Chrome Still Has an Unpatched Extension Hijack Bug, Eight Versions On
A security flaw in the Claude for Chrome extension allows any rogue browser extension with access to claude.ai to forge a synthetic click that triggers Claude to read a user's Gmail, Google Docs, or Calendar, bypassing the intended trust boundary. While an approval prompt exists in default mode, users who have enabled "Act without asking" receive no warning at all, earning the vulnerability a CVSS score of 9.6 Critical. Manifold Security reported both this issue and a related flaw involving a URL parameter that bypasses permission checks in May 2025, but as of July 14th, eight versions later, neither has been patched.
Agentforce Is Flopping With Customers, Says KeyBanc. Salesforce Disagrees.
Salesforce's AI agent platform, Agentforce, is struggling to gain traction with customers, according to KeyBanc Capital Markets analysts, who found that clients' data is often not ready for meaningful AI work and that the product itself falls short of expectations. The investment bank also noted that more CIOs plan to deprioritize Salesforce in their IT budgets, while customers are largely unwilling to pay for AI capabilities through their CRM provider. Salesforce disputes this characterisation, calling Agentforce its fastest-growing product ever, but broader analyst sentiment and a 36% drop in its stock price this year suggest significant market skepticism.
SAP Freezes Hiring and Travel to Fund Its AI Pivot
SAP is redirecting resources toward AI by freezing most new hiring (except for key AI roles) and suspending non-AI-related business travel and supplier spending. The German enterprise software giant is pushing heavily into AI with initiatives like its SAP Business AI Platform and Joule Studio 2.0, aiming to remain competitive in the enterprise application market. However, this AI pivot comes as SAP has fallen short of its own earlier targets for migrating customers to the cloud, with on-premises support revenue still significantly higher than projected.
Botnets in Your Living Room, Ransomware in Your Browser, and AI That Follows the Wrong Orders: This Week in Security
This week's cybersecurity recap highlights how attackers exploited ordinary, trusted systems rather than sophisticated vulnerabilities. Key incidents included Google and the FBI disrupting the NetNut residential proxy botnet (comprising at least 2 million devices), a fake GitHub PoC repository delivering the ChocoPoC RAT via a malicious dependency, and AI-generated browser ransomware leveraging Chromium's File System Access API. Additional notable stories covered WhatsApp username impersonation concerns, a Scattered Spider suspect extradited to the US, and multiple phishing-as-a-service toolkits emerging in the wild. The overarching theme was misplaced trust — in home devices, clean-looking code, identity reset flows, and browser permissions — underscoring that attackers need little more than a familiar, overlooked entry point.
AI Agents Are Being Tricked Into Sending Crypto Payments via Poisoned Web Content
Threat actors are exploiting prompt injection attacks embedded in malicious websites and manipulated search results to deceive AI agents into making unauthorised cryptocurrency payments. Zscaler identified two campaigns using these techniques: one involving a fake Python library site that instructs AI agents to pay for an API key, and another typosquatting the DeFi platform DeBank to trick agents into treating the fraudulent site as legitimate. Testing against 26 large language models found that four were successfully manipulated into making payments, highlighting the growing security risks as AI agents become more autonomous web users.
OpenAI Declares Chat Dead, Wants ChatGPT to Run Your Entire Life
OpenAI has declared "chat is dead" and is overhauling ChatGPT into a full-scale "superapp" that goes beyond question-answering to autonomously handle tasks across users' personal and professional lives. The redesigned platform will bundle coding tools, AI agents, and integrations with partners like Canva and Booking, with a revamped web and mobile interface rolling out in the coming weeks. Chief product officer Thibault Sottiaux envisions the end goal as a personal agent capable of assisting users across all aspects of their lives.
Microsoft and Nvidia Are Building AI Agent PCs, Because Copilot Wasn't Embarrassing Enough
Microsoft and Nvidia are reportedly partnering to launch AI-focused PCs powered by Nvidia chips as the main processor, with devices from Microsoft Surface and Dell expected to be unveiled at Computex and Microsoft's Build conference. Microsoft is also developing new software based on the OpenClaw framework that enables AI agents to handle tasks locally on Windows PCs, with plans to integrate this into Microsoft 365. This marks Microsoft's second major AI PC push, aiming to go beyond the largely unsuccessful Copilot+ PC initiative by embedding AI agents more deeply into actual user workflows.
Okta Wants to Be the One That Pulls the Plug on Your Rogue AI Agents
Okta is positioning itself as a key provider of identity and security controls for AI agents, responding to enterprise demand for "kill switch" capabilities that can shut down rogue or policy-violating agents. CEO Todd McKinnon highlighted that while 92% of executives report widespread AI agent use, only 22% have proper identity controls in place, creating significant security gaps. Okta's solution involves maintaining a directory of agents, setting access policies, and severing authorization tokens when agents go rogue — a capability already attracting major partners including ServiceNow, Salesforce, and AWS.
How a Lobster Mascot and a Bunch of Obsessives Dragged the AI Agent Era Into Existence
In late 2025, Anthropic's Claude Code — particularly the Opus 4.5 release — ignited a wave of AI agent enthusiasm among technically skilled users, enabling individuals to build and oversee complex software at a scale previously requiring entire teams. Alongside it, developer Peter Steinberger created OpenClaw, an open-source personal AI agent that became the fastest-growing project in GitHub history, drawing mainstream tech attention including a prominent endorsement from Nvidia's Jensen Huang. While the tools remain imperfect, risky, and expensive, they signal a broader shift toward autonomous AI agents that could soon reshape how all computer users work — and potentially displace many jobs in the process.
Google I/O 2026: Quadrillions of Tokens, Billions in Capex, and an Agent That Plans Your Block Party
At Google I/O 2026, CEO Sundar Pichai highlighted the company's massive AI infrastructure growth, noting token processing has surged to 3.2 quadrillion per month, supported by a capital expenditure budget of approximately $180–190 billion for the year. Google announced several new AI products, including Gemini 3.5 Flash (a faster, cheaper frontier model), Gemini Omni (a multimodal model combining video, image, and physics simulation), and Gemini Spark (a 24/7 personal AI agent capable of handling background tasks). The company also expanded its AI watermarking technology SynthID and deepened AI integration across Search, Chrome, and its app ecosystem, signalling an aggressive push toward always-on, agentic AI experiences.
Google Ships Gemini 3.5 Flash, an Agentic Assistant Called Spark, and a Do-Everything Model Nobody Fully Understands Yet
Google has announced Gemini 3.5 Flash a faster and more efficient AI model designed to make complex agentic tasks viable at scale, boasting nearly 300 tokens per second while matching the benchmark performance of larger, slower frontier models. Alongside it, Gemini Spark is Google's first dedicated AI agent, running 24/7 in the cloud to autonomously handle tasks across Google's ecosystem — such as monitoring emails, generating summaries, and building slide decks — and will initially be available to AI Ultra subscribers. Google also unveiled Gemini Omni, a new multimodal model intended to eventually handle any type of input and output (text, image, video, audio) from a single unified model, though for now it is launching with video generation only, replacing Veo in Google's products.