Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Hackers Shift From Disrupting to Destroying Critical Infrastructure

  Cyberattacks on operational technology (OT) systems have shifted from data theft and ransom demands toward outright physical destruction, ...

All the recent news you need to know

Salesforce’s Headless 360 Pushes Enterprise Software Beyond the Browser

 




Salesforce is preparing for a future in which employees may no longer need to open Salesforce to use it.

At TDX 2026, CEO Marc Benioff described the shift with the line, “Our API is the UI,” as the company introduced Headless 360. The platform makes Salesforce capabilities, including Customer 360, Agentforce and Slack, accessible through APIs, Model Context Protocol (MCP) tools and command-line interfaces (CLI), allowing applications and AI agents to interact with Salesforce without relying on its traditional browser interface. Salesforce says its Headless 360 MCP server can support operations including querying and updating records, managing permissions, working with Apex and interacting with platform events.

The change challenges a model Salesforce spent decades building: software operated primarily by humans through screens and sold largely through user-based licensing.

If an AI agent performs the work, the traditional per-seat model becomes harder to justify. An agent does not need a dashboard or training programme in the same way an employee does. It needs authenticated access to data, tools and workflows.

Salesforce is already experimenting with consumption-based pricing. Its Agentforce model includes Flex Credits, which customers can use for agent actions, alongside conversation-based and user-based pricing. Salesforce lists 100,000 Flex Credits at $500, while certain Agentforce services can also be priced according to successful outcomes.

That transition could also affect the Salesforce consulting ecosystem. Implementation work historically centred on configuring screens, workflows and processes for employees. As agents take over more workflows, organizations may instead spend more on data quality, permissions, API architecture, agent governance and testing.

Salesforce has a reason to disrupt itself before competitors do.

AI-native platforms can be designed around APIs and autonomous agents without inheriting the assumptions of traditional enterprise software. By opening Salesforce to agents, the company is betting that its strongest asset is not the interface but the business data, permissions and workflows underneath it.

That makes governance a central part of the strategy.

Salesforce's Einstein Trust Layer is designed to keep Agentforce grounded in enterprise data while respecting existing access controls. Salesforce describes capabilities including dynamic grounding, secure data retrieval, auditability and zero-data-retention arrangements with external model providers.

But making Salesforce accessible through MCP and external AI systems creates another risk: the company no longer fully controls the interface through which users interact with its platform.

A sales manager could eventually ask an external AI agent to analyse pipeline data, update opportunities, trigger Salesforce workflows and coordinate information across Slack, Salesforce and other enterprise systems. The AI layer becomes the operating interface while Salesforce functions as the underlying system of record.

MCP also introduces new security considerations. Research has identified threats including tool poisoning and prompt injection, where malicious instructions embedded in tools or outputs can influence an agent's behaviour. The U.S. National Security Agency has similarly warned about cascading prompt-injection risks in MCP environments, where one agent's output can become another system's input.

The pricing problem remains unresolved as well. Agent actions vary enormously in complexity. Updating a contact record is not equivalent to autonomously completing a sales renewal, making a simple “pay per action” model difficult to align with business value.

Salesforce's Headless 360 strategy therefore represents more than a move away from browsers. It is a test of what enterprise software is worth when humans are no longer its primary operators.

Interfaces can be replaced. What is harder to replace is trusted business data, permission architecture, proprietary workflows and the infrastructure required to let autonomous systems act safely.

Salesforce is betting that those foundations will remain valuable.

The risk is that by making them accessible to external agents, it could also help those agents become the new interface between enterprises and Salesforce itself.

Flock Cameras Spark Debate Over Surveillance and Civil Liberties


With Flock Safety operating one of the largest networks of automatic license plate readers (ALPRs), automatic license plate readers (ALPRs) are becoming more common across the United States as part of surveillance infrastructure. As a result of their rapid expansion, privacy advocates have expressed concern that such systems may create detailed records of vehicle movements in communities across the nation. 

How Flock Cameras Work

While traffic enforcement cameras usually focus on specific violations, Flock cameras photograph passing vehicles and translate the images into searchable records. License plates, locations, times, make, model, color and body type can all be included in records, along with distinguishing features such as bumper stickers or visible damage that can assist investigators in finding a particular vehicle or based on broader descriptions.

Watchlists are also available for cars associated with stolen vehicles, missing people, or criminal investigations, triggering alerts in the event that a potential match is detected. It is possible for participating law enforcement agencies to search the data of other agencies, depending on how their networks are configured. 

Why Police Departments Use Flock Cameras

A flock camera is a compact device that captures passing vehicles and records information such as license plate numbers, vehicle make and model, color, and location. Throughout the course of the investigation, data will be stored in a searchable system that will allow participating law enforcement agencies and other authorized organizations to access the system, potentially enabling the tracking of individual vehicle movements. 

The company claims that its technology does not utilize facial recognition and that customers can manage access to collected data through controls. However, given the extent to which its network is deployed, concerns have been raised about the manner in which vehicle data is shared, retained, and utilized. Approximately 120,000 cameras are now deployed across 49 states in the company's system, which is deployed by police departments, businesses, schools and homeowner associations in more than 6,000 communities. 

With the capabilities of the technology, more than just a license plate can be captured, as the records may include distinctive vehicle characteristics such as bumper stickers, dents, and other visible features. With the proliferation of surveillance cameras along public roads as well as private properties, questions regarding data access, civil liberties, and data privacy are becoming increasingly difficult to separate from the broader discussion surrounding public safety technology. 

Why Flock Cameras Are Controversial

It is not just about a single camera recording the movement of a vehicle that is of concern, but the network surrounding it at large. By using a large number of cameras, investigators may be able to reconstruct patterns of movement involving individuals who are not suspected of committing crimes by repeating recordings of the same vehicle at various times and locations. 

The use of vehicle-location data has also been criticized by privacy advocates, who have noted that it may reveal visits to sensitive areas, such as health facilities, protest sites, and churches. Searches based on historic ALPR records are still subject to legal uncertainty, including when warrants are required. Flock rejects the characterization that its system constitutes mass surveillance, however. 

Data Sharing Raises Additional Concerns

In addition to bringing Flock into the debate about immigration enforcement, data sharing has brought Flock into the public eye. According to a 2025 review of search logs, there were more than 4,000 Flock searches conducted by local and state police at the request of federal authorities, including searches that may have been related to immigration enforcement. 

An investigation conducted in 2026 revealed that outside police departments searched school cameras. It has been contested that the federal government has direct access to Flock's cameras, claiming it does not have a contract with U.S. Immigration and Customs Enforcement and does not have the right to access its data or cameras directly. 

Unauthorized Access and Personal Misuse 

In addition to allegations of misuse, there have been 28 documented cases in which officers are alleged to have abused license plate reader systems to monitor spouses, former spouses, colleagues, or romantic interests. 

Another instance occurred in July 2026 when North Carolina authorities arrested a Charlotte-Mecklenburg police officer who was accused of conducting an unauthorized license plate search for a non-law enforcement purpose using Flock and the state criminal justice database. 

Flock Cameras Can Also Produce False Alerts

If surveillance data is inaccurate, it can also pose problems. During June 2026, a driver in Minnesota was stopped by Flock alerts triggered by license plates that were similar to license plates reported stolen in another state. According to Flock, license plate translations are sometimes incomplete or inaccurate, which can result in negative consequences when automated alerts are used to influence police conduct. 

Communities Push Back Against Flock Surveillance

Over 80 municipalities have reported terminating or refusing to renew their Flock agreements, while Washington has imposed restrictions on how license plate data can be collected, searched, and shared as a result of the debate. 

Opposition to the technology has gone beyond policy debates. There have been at least 33 incidents in which Flock cameras have been damaged or destroyed, including cases where cameras have been painted, blocked, cut down, or burned in 23 states.

Why Andy Rubin’s Essential Phone Failed Despite Fixing Android’s Biggest Problems

 

Andy Rubin spent ten years creating Android before launching Essential Products, which was based on the idea that Android phones had too many compromises, such as bloatware, software skins, slow updates, and accessories that became obsolete when new hardware was released. Essential launched the PH-1 in August 2017, which had near-stock Android, premium materials, fast updates, and a display that extended to the edges. 

Rubin had co-founded Android Inc. with Rich Miner, Nick Sears, and Chris White in 2003, and Google bought the company in 2005 for $50 million. Rubin continued to lead Android’s development for the next eight years. The PH-1 was meant to overcome some of the shortcomings of the open-source platform. It had Android 7.1.1 and was expected to receive two major Android upgrades and three years of monthly security updates. 

Essential delivered on Android 9 and Android 10, the same day as Google’s Pixel phones. The hardware was also supposed to overcome Android’s challenges. The phone had a titanium frame and a ceramic back, and it was among the first smartphones to have a notch. It had magnetic pins on the back, which were supposed to allow accessories to snap onto the phone instead of using a USB-C port. Essential announced a 360 camera and an audio adapter, but the ecosystem was never realized.

The launch of the PH-1 did not go well for Essential. The company announced that the phone would be available for purchase within 30 days, but the first units were not shipped until August 25 th , nearly two months after launch. The camera was also heavily criticized, and the $699 price was permanently reduced to $499 only two months after its launch. The only US carrier that sold the Essential PH-1 was Sprint. Essential’s sales were also underwhelming despite the star power of Andy Rubin.

A $300 million funding round in 2017 valued Essential at around $1.2 billion, but Bloomberg revealed that Essential had only sold 150,000 phones by May 2018. In October 2018, The New York Times revealed that Google had investigated a sexual harassment complaint against Rubin and found the allegations credible. Google approved a $90 million exit package for Rubin, but he denied the allegations. 

The report received a negative reaction from many Google employees, and Rubin’s reputation became a liability for Essential. Essential also announced Project Gem, a tall and thin smartphone that was designed to be used with one hand. The phone never reached the market, and Essential filed for bankruptcy on February 12 th , 2020, after realizing that there was no viable way to bring the phone to the market. The PH-1 was a lesson that high-end materials, limited software, and fast updates were not enough for a struggling smartphone brand to survive. 

The phone’s troubled launch, limited accessories, poor camera, and lack of network support hindered its chances, and Essential was unable to turn it around. The company realized that its ideas were not scalable enough to sustain a smartphone manufacturer, and it filed for bankruptcy later in 2020.

AI Sandbox Escape in Microsoft Copilot Raises New Concerns Over AI Agent Security

 

Security researchers are increasingly examining whether artificial intelligence can do more than accelerate existing cyberattacks and potentially develop entirely new methods of exploitation. A recently uncovered AI sandbox escape in Microsoft Copilot offers one of the clearest indications that AI environments could be exploited to reach systems and data beyond their intended boundaries.

Joe Hladik, head of Zero Labs, the threat research division of Rubrik Inc., has spent years studying backup data, an area he believes remains relatively overlooked by the cybersecurity industry. This year, his team expanded its research to examine how organizations and employees are using AI assistants, beginning with Microsoft Copilot, which is used by around 20 million people and approximately 90% of Fortune 500 companies.

“No one’s looking at backup data,” Hladik said. “We found it to be a viable place to find actual intelligence to act upon.”

Hladik discussed the research with Krista Case during Black Hat USA in an interview broadcast by theCUBE, SiliconANGLE Media’s livestreaming studio. The conversation focused on Rubrik Zero Labs’ discovery involving Microsoft Copilot and the broader security implications for AI-powered agents.

How the Microsoft Copilot sandbox escape worked

Rubrik Zero Labs discovered the vulnerability in February and subsequently followed responsible disclosure procedures by notifying Microsoft. According to Hladik, Microsoft addressed the specific vulnerability by the middle of March.

Although the particular flaw has been patched, Hladik said the research demonstrated a broader technique that could potentially be relevant to other AI copilots. The method involved escaping Copilot’s isolated environment and reaching Azure’s backend infrastructure.

Researcher Ori Lahav is presenting the detailed findings at Black Hat USA.

“[That] would allow you to get command and control of probably hundreds, thousands, or much more, depending on the volume of what exists within that tenant of users’ files, SharePoint files, OneDrive, whatever,” Hladik said. “It’s a major, major find.”

The discovery also highlights the potential scale of an AI-related security incident. If an attacker were able to move beyond an AI assistant’s sandbox, access to organizational resources could potentially extend across files and other information stored within an enterprise environment.

Organizations still lack visibility into AI agents

The Copilot discovery comes as businesses rapidly deploy AI agents without necessarily having complete visibility into where those systems operate or what they can access.

Research from Rubrik Zero Labs found that only 23% of security leaders have complete visibility into the AI agents operating within their organizations. Rubrik is attempting to address this challenge through new AI agent governance capabilities introduced this week.

Hladik compared AI agents with technologies security teams have encountered before, arguing that their underlying architecture is not entirely unfamiliar.

“Agents are just bots with models,” Hladik said. “They’re a bot that asks a model, and then the model will tell them what to do, and then they act. It’s new, it’s cool, but at the same time, I’ve seen this before.”

The findings underscore a growing challenge for organizations deploying AI: securing not only the models themselves but also thwe environments, permissions, data and connected services that AI agents can interact with. As businesses increasingly integrate AI assistants into everyday workflows, vulnerabilities that allow these systems to escape their intended boundaries could create significant new attack surfaces.


Roblox Privacy System Tracks Data Across Hundreds of Systems as Platform Faces Child Safety Concerns

 

Roblox announces new federated central data coordination, but the system also acts as a reminder of the amount of data the company stores about its users and their activity on the platform As the platform boasts more than 132 million daily users, half of which are under the age of 18, Roblox has a large-scale privacy and safety issue. 

At the Black Hat security conference, Roblox engineering manager Hao Zhang and principal privacy software engineer Yiwen Luo spoke about the company’s approach to operational privacy and data deletion. One user request to delete data could trigger over 600 subtasks that need to be tackled by different teams and systems. According to Zhang, the entire system is complex and requires close collaboration between hundreds of systems; one of the biggest challenges was figuring out where exactly the data about the user is stored. 

Luo added that per the privacy policy, Roblox collects and stores most information about the user for as long as the account is active on the platform. The topics range from chat content, audio and video data, device information, and demography, to email and phone number, government ID and selfie for voice chat and other restricted content, payment information, and username, date of birth, and password. Roblox has experienced a 3.5X growth in year-over-year privacy-related user data requests. 

The new federated management system aims to handle such requests in a more efficient system-wide manner across the company’s systems and data platforms, as well as the third-party ones storing user data. Roblox is using artificial intelligence and other technologies to improve moderation, safety, and privacy on its platform. The company’s system, called Sentinel, is designed to detect harmful content and messages using machine learning algorithms. 

Roblox also relies on a combination of human moderation and automated tools to review and filter game catalogs, chat content, and other materials. It implements preventive algorithms and age-estimation solutions as a part of its safety measures. However, the growing use of tracking systems, tools, and the controversy around the age-verification laws in over half of the U.S. states have sparked debates regarding data privacy and potential risks to users’ safety and data privacy. 

The expansion of Roblox’s operations has also led to increased scrutiny from regulators. After the games containing violent and extremist content were leaked, and the lawsuits regarding the company’s alleged role in facilitating predation and grooming were filed, Roblox’s moderation capabilities and safety tools have come under the magnifying glass. The Roblox Sentinel documentation reveals that roughly 1,200 potential child-endangerment reports had been reviewed.

Still, there was no information about how many of those had been confirmed as actual cases. While the new federated security system allows Roblox to have more visibility and control over where the data about its users is stored and how does the company handles data deletion requests, its transparency around the matter is limited by the amount of data the company stores about its users and the extent to which it monitors its platforms.

Meta’s Muse Code: Affordable AI Coding with a Privacy Catch

 

Meta, the corporate umbrella behind Facebook, Instagram, and WhatsApp, has officially launched Muse Code, a new artificial intelligence system designed to assist developers in writing software. Announced by CEO Mark Zuckerberg via an X post, Muse Code functions as a “terminal coding agent” capable of handling complete software engineering tasks—from planning changes and writing code to validating results. This move reinforces Meta’s continued investment in AI, even as its public image remains tied to its 2021 metaverse pivot. 

What sets Muse Code apart is its ability to maintain context across a developer’s session. According to Zuckerberg, the tool runs specialized background agents that stay active throughout, learning a coder’s habits and preferred patterns. This means if a developer has previously generated a specific code fragment using Muse, the system remembers it for future reuse. Additionally, Muse dynamically allocates tasks: for complex requests, it “fans out” work to separate sub-agents operating in parallel within isolated worktrees, ensuring the original codebase remains untouched during experimentation. 

Despite its technical sophistication and cost advantage, Muse Code comes with a notable caveat: privacy. As with many AI-driven platforms, the tool’s ability to learn from user behavior and retain session data raises questions about how developer information is stored, used, and potentially shared. While Meta has not disclosed full details on data handling policies for Muse Code, the trade-off between affordability and privacy remains a critical consideration for enterprises and individual developers alike. 

Muse Code arrives amid Meta’s aggressive push into AI infrastructure and tooling. Zuckerberg has previously stated ambitions for AI to write most of Meta’s code within 12 to 18 months, and the company has reported a 30% rise in engineer productivity since early 2025, largely attributed to AI coding assistants. This launch also coincides with similar moves by competitors—Google recently unveiled Gemini 3.7 Flash, a low-cost AI model for coding workflows—highlighting a growing industry race to democratize AI-assisted development.

For developers, Muse Code represents both opportunity and caution. Its ability to reduce repetitive tasks, preserve work mid-crash, and scale complex projects could significantly boost productivity. However, the privacy implications underscore the need for transparent data policies and robust security measures. As AI coding tools become more prevalent, the balance between efficiency, cost, and data sovereignty will likely shape the next chapter of software development.

Featured