Connect with us

Tech

Amazon is already offering new OpenAI products on AWS

Published

on

Almost as soon as OpenAI announced that its major investor and cloud partner, Microsoft, no longer has exclusive rights to any of its products, Amazon started gloating.

After the revised OpenAI/Microsoft agreement was announced on Monday, Amazon CEO Andy Jassy noted in a tweet that it was a “very interesting announcement.” That agreement solved OpenAI’s problem of allowing AWS to offer its products, an issue that crystalized after it signed an up-to-$50-billion deal with Amazon.

Amazon announced on Tuesday that AWS’s Bedrock service now has OpenAI’s latest models, its code-writing service Codex, and a new product for creating OpenAI-powered AI agents. Bedrock is Amazon’s AI app building and model-choosing service.

Amazon is calling the new agent service Bedrock Managed Agents. It is specifically designed to use OpenAI’s reasoning models, offering features like agent steering and security.

Amazon promises in its blog post that “this is the beginning of a deeper collaboration between AWS and OpenAI.” And it will certainly be interesting to watch.

The Microsoft/OpenAI relationship has reportedly been deteriorating for some time, with each of them finding comfort in the arms of their partner’s biggest rival. OpenAI has turned to AWS and Oracle. Microsoft to Anthropic; the Redmond-based software giant is also working on a new agent offering powered by Claude.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

>

Continue Reading

Tech

Ring’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features

Published

on

Ring has a new answer to a difficult security-camera trade-off: keeping cloud-powered intelligence without retaining long-term access to the keys that unlock customers’ videos.

The Amazon-owned company announced TAKE, or Throw Away the Key Encryption, on Aug. 26. A phased rollout begins in September 2026, with Ring planning to make the system its default encryption worldwide while retaining cloud-dependent features such as intelligent alerts, video descriptions, and search. End-to-end encryption will remain optional.

How Ring TAKE limits access to video

Under Ring’s TAKE system, recordings use unique, rotating encryption keys. Ring temporarily holds a copy inside a secure cloud enclave so enabled services can process footage, then deletes that copy.

Ring already encrypts video in transit and at rest. Its privacy documentation says TAKE limits retention of video encryption keys to 24 hours. After deletion, the customer and authorized Shared Users retain the keys on enrolled devices.

Optional end-to-end encryption goes further by preventing Ring from accessing encrypted content. It also disables Shared User video access and numerous cloud-dependent features, including Video Search and Video Descriptions.

The tension between encryption and cloud processing extends beyond home cameras. Organizations face similar questions around encrypted cloud data and lawful access, while flaws in cloud-connected security cameras have highlighted the risks attached to remotely managed video.

TAKE also affects what Ring says it can provide to authorities. The company responds to legally valid government demands, including search warrants, subpoenas, and court orders. Ring’s privacy policy says that when TAKE or E2EE protects footage, the company can provide non-video information but not the protected recordings. Users can still choose to share footage themselves.

Ring Verify and Ring Pro add another layer

TAKE arrives as Ring expands the intelligence attached to its cameras. The company’s 2026 subscription changes renamed AI Pro as Ring Pro. Intelligent features include Video Descriptions, Familiar Faces, Unusual Event Alert, Active Warnings, Single Event Alert, and Video Search.

Availability varies by device, subscription, language, and location. Amazon said Aug. 26 that Video Descriptions expanded to more regions, while some intelligent features remain restricted in certain jurisdictions.

Ring Verify addresses the integrity of exported footage rather than who can decrypt it. Ring’s verification documentation says downloaded or shared cloud videos carry a digital security seal. A verified result means the file has not changed since download.

A failed check does not prove a clip is fake. Cropping, trimming, brightness changes, filters, or compression can break verification. Videos recorded with E2EE are also incompatible with Ring Verify and return “not verified.”

Organizations using Ring footage for investigations or evidence should account for both controls when setting encryption, export, and retention policies.

Read more: Ring’s evolving privacy posture also includes its decision to drop a planned Flock Safety integration after concerns over surveillance and access to camera footage.

>

Continue Reading

Tech

Snapchat’s 13+ Rating Under Fire: Pennsylvania Alleges Addictive Design, Adult Content

Published

on

Snapchat says it is suitable for teens as young as 13, but Pennsylvania now alleges the app’s content and design tell a very different story.

The state’s attorney general has sued the social media company, alleging Snapchat uses disappearing content, Snapstreaks, notifications, and other engagement features that encourage compulsive use among children. Pennsylvania says these mechanics can create a cycle in which young users return repeatedly because they fear missing content, losing a streak or falling behind socially.

The lawsuit also challenges Snapchat’s 13+ age rating, alleging that the company does not accurately reflect how often younger users encounter mature material.

Together, the claims put both sides of Snapchat’s teen experience under scrutiny.

Why Pennsylvania says Snapchat’s teen safeguards fall short

App store ratings and labels are intended to be a quick way potential app users, and in this case, parents, can check how suitable an app aligns with their needs and preferences. That means such labels should always be accurate.

However, the Pennsylvania judiciary has found that Snapchat’s age ratings and the app’s actual behavior are miles apart.

According to the court filing, an investigator working with the Pennsylvania attorney general’s office created a Snapchat account for a fictional 13-year-old and tested the content a minor could encounter on the platform. According to the complaint, the investigator encountered frequent and intense profanity, drug and alcohol references, sexual content and other mature material despite Snap maintaining a “T for Teen” rating in Google Play and Microsoft’s store and a 13+ rating in Apple’s App Store, The Next Web reports.

But Pennsylvania’s case does not stop at what Snapchat shows children. The case also aims to show how the platform keeps them coming back.

The complaint alleges that disappearing content, infinite scrolling, push notifications, autoplay, Snapstreaks and Snapscores create repeated-use loops that can encourage compulsive behavior among young users.

Snapchat has a defense; the courts have the decision

A Snapchat spokesperson told Fox Business in a statement that Snapchat was designed differently from the beginning, opening to a camera rather than a content feed and focusing on self-expression and connections between friends.

The statement also noted that Snap shares the attorney general’s goal of protecting young people online but is disappointed that Pennsylvania chose to pursue litigation rather than work with the company.

The dispute will now move forward in the Philadelphia Court of Common Pleas. Pennsylvania is asking the court to declare the alleged practices unlawful, impose temporary and permanent injunctions, and levy civil penalties for willful violations, along with legal costs and other relief.

The court will ultimately determine whether Snap’s practices violated that law and whether the state is entitled to the remedies it is seeking.

Earlier this month, a US appeals court allowed more than 3,000 lawsuits against Meta, Google, TikTok and Snap over alleged addictive platform design to proceed. Separately, a recent Meta settlement with dozens of states could force sweeping changes to how the company handles young users.

Australia has gone even further, imposing a ban that prevents children under 16 from holding accounts on social-media platforms.

The policy, which took effect in December 2025, has since helped trigger a wave of regulations and proposals aimed at limiting children’s access to social media across age groups. Governments are increasingly targeting features such as endless feeds, feedback systems and disappearing content that can encourage prolonged or repeated use.

What this means for Snapchat users and parents

For parents and younger Snapchat users, the Pennsylvania case is worth watching because its impact could extend beyond warning labels and app-store ratings. If the state succeeds, Snap could face pressure to change how it presents Snapchat to younger users, how it handles mature content, or how some of its most popular engagement features work for teen accounts.

That could put features such as Snapstreaks, disappearing content, autoplay, and frequent notifications under greater scrutiny. These are familiar parts of the social media experience, but regulators are increasingly questioning whether platforms should be allowed to use the same engagement mechanics for children as they do for adults.

The case could also contribute to a broader shift in how social-media companies verify ages and design accounts for younger users. Parents and teens may eventually encounter stronger age checks, expanded parental controls, different default settings, or restrictions on features intended to encourage repeated use.

For now, Snapchat’s existing features remain in place, and Pennsylvania’s allegations must still be tested in court. But the outcome could help determine how much responsibility social-media companies have for designing a fundamentally different experience when the person behind the screen is a child.

Also read: Meta was ordered to pay $567 million and overhaul teen protections as courts put more pressure on social media companies over how their platforms affect young users.

>

Continue Reading

Tech

Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests

Published

on

An AI agent found a shortcut through a vulnerable gym booking API — and used it. A new controlled test suggests the behavior was reproducible.

Security firm Aikido reported Aug. 25 that Claude Opus 4.6, running through the OpenClaw agent framework, bypassed a simulated gym’s booking-window restriction in nine of 10 test runs. In two runs, the agent also canceled another synthetic user’s reservation through a missing authorization check.

The experiment recreated an incident involving Australian software developer Andrew Bird that drew wider attention in August. As AI assistants gain access to sensitive systems, weak permissions and backend controls can give unintended actions consequences far beyond the interface an employee normally sees. Organizations deploying agents therefore need security controls at the API and identity layers, not just restrictions in the agent’s instructions.

How Aikido recreated the gym booking hack

Aikido built a synthetic gym booking application around two vulnerabilities described in reports of Bird’s experience. Researchers connected an April 2026 build of OpenClaw, version 2026.4.1, running Claude Opus 4.6 and completed 10 conversations totaling 1,130 messages and tool calls.

The test was modeled on an incident ABC News reported Aug. 10. Bird first asked his OpenClaw assistant to book a gym class. After the agent found a way to book farther ahead than the interface allowed, Bird — then fourth on a waitlist — asked whether it could move him higher. The agent canceled the top waitlisted member’s reservation without being told to do so, moving Bird from fourth to third.

In Aikido’s simulation, the one-week booking limit existed only in the website interface, while direct API requests were not subject to it. Claude used the weakness in nine runs, including five after the first user message.

The more serious flaw involved reservation ownership. The simulated cancelReservation function did not verify that the logged-in user owned the reservation being canceled. Claude exploited it in two runs, although Aikido said researchers never explicitly instructed the model to exploit a vulnerability.

Other evaluations have raised related concerns. In August, UK researchers reported unsanctioned actions by Anthropic and OpenAI agents during deliberately permissive cybersecurity tests, although those models operated under different conditions.

Weak API controls give agents room to act

The missing ownership check matches what OWASP calls Broken Object Level Authorization, or BOLA, the No. 1 risk in its 2023 API Security Top 10. OWASP recommends authorization checks on every endpoint that receives an object ID and acts on that object.

Server-side controls should cover operations that read, modify or delete data rather than relying on restrictions in a website interface. Organizations deploying agents should also use narrowly scoped credentials and approval gates for consequential actions, controls that become increasingly important as agents operate across connected workplace apps.

Anthropic documented a related behavioral risk before releasing Opus 4.6 on Feb. 5. Its Opus 4.6 system card said the model could at times become “overly agentic” in coding and computer-use settings, taking risky actions without first seeking permission.

Aikido tested one OpenClaw build against one synthetic application, and the setup did not enable Claude’s thinking tokens. The researchers said additional reasoning would likely increase refusals, so the results should not be generalized to Claude or AI agents broadly. The underlying API weaknesses remain conventional security problems regardless of whether the caller is a person, script or agent.

Read more: A recent AI safety test that accidentally reached real company systems shows why autonomous agents need enforced access boundaries rather than scope defined only by prompts or labels.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.