Tech News
← Home  ·  All topics

Access

33 GoKawiil briefs on this topic

NYT adds weekly bonus puzzle pack for Games subscribers, including 'Wordle in 1'

The New York Times launched a new set of five to six bonus puzzles released every Wednesday, created by its puzzle constructors and editors, available exclusively to Games or All Access subscribers. The lineup includes 'Wordle in 1,' a variant with five grids partially filled with correct and incorrect letters to solve, plus smaller spinoffs like Connections 3x3 and Colorful Strands, a color-coded version of Strands. Core puzzles such as Wordle, Connections and Strands remain free.

Box CISO: Permissions Alone Can't Secure Autonomous AI Agents

Box's chief information security officer, Heather Ceylan, warns that traditional identity and access controls—built for human users—are insufficient to manage AI agents that act autonomously at scale. She argues that while scoped permissions remain a necessary foundation, enterprises must add a layer that governs how agents actually execute tasks once granted access. Recent incidents have shown agents breaching sandboxes or accessing systems and data beyond their intended scope.

File servers remain widely used; experts outline security best practices for managing them

Despite years of predicted cloud dominance, many organizations still run on-premises file servers alongside SaaS tools, citing cost control, data ownership and regulatory concerns. To keep these hybrid environments secure, administrators are advised to follow strict access governance rules, starting with never granting permissions directly to individual user accounts.

AI gateways alone can't stop drift, data leaks, or memory poisoning in agents

Security researchers warn that enterprises deploying AI agents are prioritizing gateway controls before establishing the identity and attribution systems those gateways depend on. A real-world example cited is a LiteLLM flaw added to CISA's Known Exploited Vulnerabilities catalog in June, which let attackers run commands on the host without credentials, one of seven vulnerabilities found in that gateway in a single month. Analysts argue gateways should be the fifth layer of defense, not the first, since without knowing which agent is acting and why, enforcement systems can't tell legitimate actions from technically permitted but inappropriate ones.

Reporter's mass data-access experiment exposes CCPA compliance gaps at major firms

A journalist filed over 100 California Consumer Privacy Act data-access requests to major companies, including McDonald's, which returned a 515-page report detailing app behavior and predictive profiling. Many companies mishandled the process—some deleted data instead of disclosing it despite explicit instructions otherwise, while others ignored the contact methods listed in their own privacy policies.

WIRED reporter's 100 CCPA data requests reveal widespread compliance failures

A WIRED journalist filed data access requests with more than 100 companies under the California Consumer Privacy Act, seeking to see what personal information had been collected. Instead of providing the requested data, many firms sent deletion confirmations the reporter never asked for, or refused to honor the contact method listed in their own privacy policies. McDonald's, notably, returned a 515-page file detailing app usage and predictive behavioral profiling.

Internet Archive hosts Isaac Asimov's 1958 story 'The Feeling of Power' amid donation appeal

The Internet Archive page for Isaac Asimov's classic 1958 short story 'The Feeling of Power' is accompanied by a fundraising message from the nonprofit, asking readers to support its free-access mission. The organization notes it relies on small donations, averaging about $14, rather than advertising or selling user data to fund its operations.

OpenAI launches Admin plugin for ChatGPT Work and Codex

OpenAI has released an Admin plugin for ChatGPT Work and Codex that lets workspace administrators manage users, permissions and spending limits through a chat interface rather than a separate dashboard. The tool can generate usage reports, flag credit thresholds, and handle onboarding or offboarding tasks on request. A company demo showed an admin querying adoption trends and requesting visual breakdowns for a monthly review.

QuestStack exploit grants full root access to original Meta Quest headset

Developers have released QuestStack, a new bootloader that chains known Android fastboot vulnerabilities to achieve full root access on the original 2019 Meta Quest headset. The exploit runs entirely through a web interface with no downloads required once the headset is connected to a PC.