From VentureBeat · 8 stories
Azure OpenAI Assistants Can Exfiltrate Data Due to Retrieval Access Control Gaps
An Azure OpenAI email assistant was found to return SharePoint content to users who lacked the necessary permissions, indicating a data exfiltration vulnerability in retrieval-augmented generation (RAG) deployments. This issue arises because agents often answer with the indexer's broad permissions rather than the requester's, a problem that affects custom RAG pipelines and some first-party Azure OpenAI configurations.
Prompt Injection Ranks High in OWASP List but Low in Incident Records Due to Detection Gaps
A new analysis by OWASP Top 10 for LLM Applications leaders found a significant discrepancy between expert-ranked prompt injection risk and its appearance in real-world incident records. This gap exists because prompt injection attacks operate in a way that traditional vulnerability scanners cannot detect, leading to underreporting in incident databases. The findings highlight a blind spot in current security monitoring for LLM applications.
AI Models Exhibit High Confidence When Incorrect, Evading Qualitative Review
AI models often present incorrect information with high confidence, which qualitative evaluation methods fail to detect because they primarily assess fluency and plausibility rather than factual accuracy. This issue is critical for LLM-assisted tools used in business decisions, where accuracy has significant consequences.
AI and human expertise must evolve together in IT and security fields
Organizations are increasingly using AI to automate tasks traditionally performed by junior analysts, which risks diminishing the apprenticeship opportunities crucial for developing skilled operators. Without intentional restructuring, companies may lose the deep analytical expertise needed to manage complex systems effectively in the future.
OpenClaw Maintainers Discuss Managing Rapid Growth and Security Challenges
The maintainers of OpenClaw, an AI assistant project, discussed their experiences managing a surge of pull requests, rethinking contributor trust, and addressing software supply chain risks. This provides insights into the operational challenges of rapidly growing open-source AI projects.
VentureBeat Appoints Rob Strechay as First Lead Analyst for Enterprise AI Research
VentureBeat has hired Rob Strechay as its first Lead Analyst and a founding analyst of VentureBeat Research, aiming to expand its coverage of enterprise AI for technical decision-makers. This move signifies VentureBeat's push for deeper specialization in enterprise AI analysis, providing objective data for organizations moving from generative AI experimentation to production deployment.
Heidi Scribe Automates Healthcare Administration Globally with Production-Ready AI
Heidi, an AI Care Partner, has successfully deployed its AI product, Heidi Scribe, to automate administrative tasks for clinicians in over 190 countries, handling 2.7 million patient interactions weekly. This global expansion was achieved by building an architecture that prioritizes data residency, auditability, and safe change management to meet strict healthcare compliance regulations.
Runway ML turned an AI video generation bug into a feature for its Characters model
Runway ML addressed a bug in its AI video model, where AI-generated avatars drifted off-center, by implementing a front-end feature that worked around the problem rather than fixing the underlying issue. This approach was highlighted by Ryan Phillips, head of enterprise product at Runway ML, as a lesson in AI development and evaluation for companies building generative tools.