1️⃣ Breaking News
“Invitation Is All You Need”: Gemini AI Hijacked via Poisoned Calendar Invites
Researchers from Tel Aviv University, Technion, and SafeBreach demonstrated how Google’s Gemini AI can be manipulated through calendar entries—launching actions like opening smart shutters or initiating Zoom calls using indirect prompt-injection attacks. Google has responded with integrated machine learning filters, output screening, and required confirmations for sensitive actions.(WIRED)
DARPA’s AI Cyber Challenge Yields Autonomous Bug-Fixing Tools for Critical Infrastructure
At DEF CON, DARPA concluded its two-year AI Cyber Challenge, where Team Atlanta (Georgia Tech et al.) won $4 million. Finalist teams discovered 77% of injected bugs and patched 61%, with several tools now publicly available. DARPA and ARPA‑H are investing over $21 million to support deployment in sectors like healthcare.(Axios)
Microsoft’s “Project Ire” Prototypes AI Agent That Detects and Analyzes Malware Autonomously
Microsoft introduced Project Ire, an AI-powered malware detection and reverse engineering prototype. In trials, it achieved a 90% precision but only ~25% recall, with an enhanced performance (0.83 recall, 2% false positives) on Windows driver datasets. It aims to become an integrated “Binary Analyzer” within Microsoft Defender.(Axios, TechRadar)
2️⃣ Research Highlights
CAI: Open, Bug Bounty‑Ready Cybersecurity AI
This open-source framework of AI agents dramatically accelerates bug discovery—up to 3,600× faster than humans in CTFs. It enables efficient, affordable security testing with human oversight.(arXiv)
Agentic AI and the Cyber Arms Race
This research explores how agentic AI—autonomous AI agents—is reshaping cybersecurity and global cyber warfare, enabling capabilities previously accessible only to powerful actors.(arXiv)
3️⃣ Featured Tools & Resources
Google’s “Big Sleep” – AI‑Driven Vulnerability Finder
Utilizing the Gemini AI model, Big Sleep identified 20 security flaws in open-source software, marking a powerful example of AI’s role in automated code auditing.(The Times of India, Axios)
Infosys’ Innovation Hub in Hubballi
Infosys launched a Centre for Advanced AI, Cybersecurity, and Space Tech in North Karnataka. It will focus on R&D and strengthen the regional tech ecosystem.(Wikipédia, economictimes.indiatimes.com)
4️⃣ Bonus: Emerging Threats or Industry Events
“Tea” App Data Breach Reveals Risks of AI‑Fueled Rapid Development
The app “Tea” suffered a major breach, leaking 72,000 images (including driver’s licenses) and over 1.1 million private messages. Experts warn that “vibe coding”—fast-paced AI-generated app development—often sacrifices security.(Business Insider)
AI as a “Dirty Bomb” in Information Warfare
CyberCX CSO Alastair MacGibbon warns that AI — particularly from authoritarian regimes like China’s DeepSeek — can be weaponized to distort truth and manipulate societies.(News.com.au)
—
Stay informed and vigilant as the fields of AI and cybersecurity continue to evolve rapidly.






Leave a Reply