Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

ToxicPanda Android malware uses VPN permissions to block Google Play

Bleeping Computer - 7 hodin 30 min zpět
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Kategorie: Hacking & Security

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News - 22 Srpen, 2026 - 16:32
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers infect Android car head units with proxy botnet malware

Bleeping Computer - 22 Srpen, 2026 - 16:14
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
Kategorie: Hacking & Security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Bleeping Computer - 22 Srpen, 2026 - 15:00
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]
Kategorie: Hacking & Security

eBPF Security Is Moving Beyond the Kernel Verifier

LinuxSecurity.com - 22 Srpen, 2026 - 02:05
eBPF security is often summarized in one sentence: Linux loads an eBPF program only after the kernel verifier accepts it under the safety checks the verifier performs. That description is useful, but it covers only one part of a larger system.
Kategorie: Hacking & Security

Kata Containers Flaw Weakens Container Security With Host-Chosen Mounts

LinuxSecurity.com - 22 Srpen, 2026 - 01:40
A flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to make the protected guest use attacker-chosen files or content at approved mount locations.
Kategorie: Hacking & Security

KVM’s TDX Control-Plane Blind Spot: When “Enabled” Does Not Mean Enforced

LinuxSecurity.com - 22 Srpen, 2026 - 00:50
Recent KVM work exposed a gap between what Linux says a TDX protection supports and what the TDX-specific code actually enforces.
Kategorie: Hacking & Security

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

The Hacker News - 21 Srpen, 2026 - 20:53
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New SynkLoader malware pushed in Microsoft Teams phishing campaign

Bleeping Computer - 21 Srpen, 2026 - 20:01
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Kategorie: Hacking & Security

Linux ShieldZFS Adds Freshness Proofs for Confidential Computing

LinuxSecurity.com - 21 Srpen, 2026 - 19:32
Confidential computing can protect sensitive workloads even when the cloud host cannot be fully trusted. Confidential virtual machines can shield memory and CPU state from the hypervisor. Disk encryption can also stop the host from reading stored data. But how does the virtual machine know the disk state it received is the newest?
Kategorie: Hacking & Security

Hundreds of leaked AWS keys give full control over corporate accounts

Bleeping Computer - 21 Srpen, 2026 - 17:55
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Kategorie: Hacking & Security

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News - 21 Srpen, 2026 - 17:52
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

The Hacker News - 21 Srpen, 2026 - 17:41
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ChatGPT wants Full Disk Access to your Mac and Messages

Computerworld.com [Hacking News] - 21 Srpen, 2026 - 17:39

<br>&lt;!--<br>/* Style Definitions */<br> p.MsoNormal, li.MsoNormal, div.MsoNormal<br> {mso-style-unhide:no;<br> mso-style-qformat:yes;<br> mso-style-parent:"";<br> margin:0cm;<br> mso-pagination:widow-orphan;<br> font-size:12.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-fareast-font-family:Aptos;<br> mso-bidi-font-family:"Times New Roman";<br> mso-fareast-language:EN-US;}<br>a:link, span.MsoHyperlink<br> {mso-style-priority:99;<br> color:#467886;<br> mso-themecolor:hyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>a:visited, span.MsoHyperlinkFollowed<br> {mso-style-noshow:yes;<br> mso-style-priority:99;<br> color:#96607D;<br> mso-themecolor:followedhyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>.MsoChpDefault<br> {mso-style-type:export-only;<br> mso-default-props:yes;<br> font-size:10.0pt;<br> mso-ansi-font-size:10.0pt;<br> mso-bidi-font-size:10.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-ascii-font-family:Aptos;<br> mso-fareast-font-family:Aptos;<br> mso-hansi-font-family:Aptos;<br> mso-font-kerning:0pt;<br> mso-ligatures:none;}<br>@page WordSection1<br> {size:595.3pt 841.9pt;<br> margin:72.0pt 72.0pt 72.0pt 72.0pt;<br> mso-header-margin:35.4pt;<br> mso-footer-margin:35.4pt;<br> mso-paper-source:0;}<br>div.WordSection1<br> {page:WordSection1;}<br> /* List Definitions */<br> @list l0<br> {mso-list-id:1984120649;<br> mso-list-type:hybrid;<br> mso-list-template-ids:226894856 134807553 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}<br>@list l0:level1<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level2<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level3<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level4<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level5<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level6<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level7<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level8<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level9<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br><br>--><br>Apple wasn’t joking when it <a style="color: rgb(150, 96, 125);" href="https://www.apple.com/newsroom/2025/09/the-digital-markets-acts-impacts-on-eu-users/">warned</a> us that competitors want access to our most private data. Now <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">OpenAI’s ChatGPT</a>has introduced a new plugin that can control Apple’s Messages app on Macs. This follows its introduction earlier of a new Computer History feature that <a style="color: rgb(150, 96, 125);" href="https://x.com/OpenAI/status/2087996496088297746?s=20">monitors what you do on your Mac</a>, and while I don’t think Apple will challenge the new feature – yet – on Mac, I do see trouble ahead on other platforms.So, what’s ChatGPT’s new thing? Its latest tool means you can use the Chat GPT app to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from the Messages app. <b>What is happening?</b>“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS. In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats,” <a style="color: rgb(150, 96, 125);" href="https://learn.chatgpt.com/docs/plugins?surface=app">says OpenAI</a>.What this means is that if you’ve ever wanted an AI system to go through all your messages to give you insights, you’re in luck – though you’ll probably want to check in with corporate legal before doing so. The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.<b>How might you use this tool?</b>ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them and more. You might get ChatGPT to recommend a set of secure browser and messaging services you can use to communicate without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples available <a style="color: rgb(150, 96, 125);" href="https://x.com/ChatGPT/status/2090499359641329950?s=20">here</a>.The company has suggested some prompts, including:<li class="MsoNormal">Suggest follow ups from yesterday in messages.Check my calendar and reply to (contact name) with a few times I'm free for dinner next week.Find birthdays in Messages and add them to my calendar.</li><b>How does it work?</b>The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed by the system, along <a style="color: rgb(150, 96, 125);" href="https://tech.yahoo.com/general/articles/chatgpt-macos-just-got-caught-134547811.html">with recent history</a> on how ChtGPT protects such data on Macs. OpenAI told <a style="color: rgb(150, 96, 125);" href="https://www.bloomberg.com/news/articles/2026-08-20/chatgpt-can-now-control-imessage-potentially-raising-apple-privacy-concerns">Bloomberg</a> the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages, but that may not mean too much given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools. The plugin also makes use of AppleScript and Accessibility settings.<b>Something to think about</b>The degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some <a style="color: rgb(150, 96, 125);" href="https://x.com/markgurman/status/2090580272433832177?s=20">apologists</a> tend to dismiss concerns around privacy, while others warn that AI automation is becoming an <a style="color: rgb(150, 96, 125);" href="https://x.com/GaryMarcus/status/2090583038338236533?s=20">always-on surveillance system</a> that itself becomes a target for exploitation and attack. It’s possible both parties have a point, but what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy.It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which may yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data, particularly in Europe where <a style="color: rgb(150, 96, 125);" href="https://digital-markets-act.ec.europa.eu/developer-portal/interoperability_en">the Digital Markets Act</a> requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools. It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers, as if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them, perhaps using ChatGPT to <a style="color: rgb(150, 96, 125);" href="https://x.com/ControlAI/status/2090565786205118516?s=20">help them build the code with which to do it</a>. <b>What next? </b>I don’t think Apple will challenge OpenAI’s approach right now as the company doesn’t appear to have actively subverted Mac security protection, but I do predict a show down on iOS, particularly if Apple is unable to build support for the ‘<a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/apples-siri-ai-stand-off-with-europe-just-escalated/">trusted intermediary’</a> approach it <a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/eu-regulators-just-killed-europes-ios-developer-industry/">originally proposed</a> to the EU, if only because of the much wider extent of information collected on mobile. It also puts yet another slant on the <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">ongoing litigation between both companies</a>.<em><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: rgb(12, 12, 12); letter-spacing: -0.15pt;">Join me on <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://bsky.app/profile/jonnyevanssays.bsky.social"><span style="color: rgb(12, 12, 12);">BlueSky</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="http://www.linkedin.com/in/jonnyevans"><span style="color: rgb(12, 12, 12);">LinkedIn</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://social.vivaldi.net/@jonnyevans"><span style="color: rgb(12, 12, 12);">Mastodon</span></a> and <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://thecorenews.substack.com/?r=5l3lg&amp;utm_campaign=profile&amp;utm_medium=profile-page"><span style="color: rgb(12, 12, 12);">subscribe to my newsletter</span></a> for news and analysis.</span></em>Apple wasn’t joking when it warned us that competitors want access to our most private data. Now, OpenAI’s ChatGPT has introduced a new plugin that can control Apple’s Messages app on Macs. This follows the earlier introduction of a new Computer History feature that monitors what you do on your Mac. And while I don’t think Apple will challenge the new feature — yet — on the Mac, I do see trouble ahead on other platforms.

So, what’s ChatGPT’s new thing? Its latest tool means you can use the tool to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from Messages. 

What is happening?

“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS,” says OpenAI. “In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats.”

So, if you’ve ever wanted an AI system to go through all your messages to pluck out insights, you’re in luck (though you’ll probably want to check in with corporate legal before doing so). The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.

How might you use this tool?

ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them, and more. You might get ChatGPT to recommend a set of secure browser and messaging services you could use without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples here.

The company has suggested some prompts, including:

  • Suggest follow ups from yesterday in messages.
  • Check my calendar and reply to (contact name) with a few times I’m free for dinner next week.
  • Find birthdays in Messages and add them to my calendar.
How does it work?

The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed, along with recent history on how ChatGPT protects such data on Macs. 

OpenAI told Bloomberg the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages. But that may not mean much, given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”

Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools.

Something to think about

The degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some apologists tend to dismiss concerns around privacy, while others warn that AI automation is becoming an always-on surveillance system that itself becomes a target for exploitation and attack. Both sides may have a point. But what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy. It’s all well and good to require consent to make the AI magic happen, but it would be far better, and more legitimate, for such consent to be informed.

It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which might yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data. That’s particularly true in Europe, where the Digital Markets Act requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools.

It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree on some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers; if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them — perhaps using ChatGPT to help them build the code with which to do it

What’s next? 

I don’t think Apple will challenge OpenAI’s approach for now, as the company doesn’t appear to have actively subverted Mac security protection. But I do predict a showdown on iOS, particularly if Apple is unable to build support for the “trusted intermediary” approach it originally proposed to the EU, if only because of the wider extent of information collected on mobile. It also puts yet another slant on the ongoing litigation between both companies.

Join me on BlueSkyLinkedInMastodon and subscribe to my newsletter for news and analysis.

Kategorie: Hacking & Security

Microsoft blames Windows gaming issues on RGB lighting devices

Bleeping Computer - 21 Srpen, 2026 - 16:54
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
Kategorie: Hacking & Security

Is Online Privacy Possible? How Digital Identities Can Help

Bleeping Computer - 21 Srpen, 2026 - 16:00
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]
Kategorie: Hacking & Security

Microsoft rolls out Classic Outlook theme for New Outlook users

Bleeping Computer - 21 Srpen, 2026 - 15:39
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
Kategorie: Hacking & Security

Waymo doubles spending on lobbying in robotaxi battle with Uber

Ars Technica - 21 Srpen, 2026 - 15:11

Waymo has sharply increased its lobbying spending as it seeks to persuade US regulators to clear a path for fully autonomous taxi services, intensifying its battle with rival Uber over the future of robotaxis.

The Alphabet-owned company spent more than $1 million between April and June on lobbying the federal government, more than double its outlay a year earlier, according to filings. That put Waymo’s spending close to Uber’s and well ahead of rivals including Amazon’s Zoox and Tesla.

The rise in lobbying comes as Waymo and Uber push competing visions for the future of ride-hailing. Waymo wants a faster route to fully driverless commercial services, while Uber is advocating a staggered rollout in which robotaxis operate alongside human drivers.

Read full article

Comments

CISA orders feds to patch actively exploited TrueConf Server flaws

Bleeping Computer - 21 Srpen, 2026 - 14:25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
Kategorie: Hacking & Security

New ‘Slack Code’ turns AI coding into a team activity

Computerworld.com [Hacking News] - 21 Srpen, 2026 - 13:22

With the launch of “Slack Code” channels, Slack this week introduced a new way for developers and non-tech staff to work collaboratively with coding agents.

While Slack already integrates with several coding agents, developers have to interact with them independently to get work done. The aim of Slack Code is to make agents available to multiple coworkers in shared, project-based “code channels.” 

“We built code channels to be this multi-player AI experience and bring more development into Slack,” said Sateja Parulekar, vice president of product marketing at Slack. “It’s not just engineers and product managers who are working with the coding agents; it’s the marketers, the product designers who are now able to interact with a coding agent in a safe, governed environment.”

Slack code channels are intended for one-off coding sessions and projects — building a new application feature, updating a web page, or fixing a bug, for example. 

When the coding agent is tagged in a Slack channel or DM with a request, it automatically creates a new code channel, adds links to required documents, and invites relevant participants. 

The code channel functions just like a normal Slack channel, with participants able to send messages and files as usual, while also letting them interact with a coding agent and track outputs via the channel’s “session artifacts.” These artifacts include “code diffs” that highlight changes to code made by the agent, as well as Slack “canvas” documents and live HTML that displays prototypes and previews created by the agent. 

All participants can use natural language to direct the agent, making suggestions and signing-off on outputs, for instance. Any updates are then highlighted in the original Slack channel. And when a task or project is complete, the code channel is automatically archived.

Slack Code channels can also be customized — Slack admins can create guardrails to prevent non-technical workers from shipping code without engineering review, for example.

Code channels adhere to Slack’s existing security and permissions model, the company said, with agents able to access conversations and data based on controls set for a Slack workspace.

At launch, four agents integrate with Slack Code — Claude Code, Devin, GitHub Copilot, and Vercel — though Slack intends to expand the list of options over time. Slack Code is available at no extra cost on all Slack subscriptions.   

“Slack Code closes the gap between where work gets done and where code gets written with dedicated spaces built for output along project-based channels right in Slack,” said Wayne Kurtzman, research vice president at IDC. “This furthers the Salesforce goal of making work more seamless and multi-player within the Slack environment, regardless of the other applications the business is using. 

“While Slack Code may seem early to market for some companies, others are leveraging the first-mover advantage.”

While software development and coordination work “has happened in Slack forever,” according to Will McKeon-White, senior analyst at Forrester, the new features make it “easier to just stay in Slack only and [open] up who is involved with the actual code creation.”

For IT staffers who enable Slack Code, the immediate consideration involves  permissions, he said — “a persistent challenge for anything multiplayer.” McKeon-White cites various approaches: “…Some inherit user permissions based on task, some have persistent permissions with different ‘invoking’ permissions for users, some inherit the permissions of the room. Each has flaws.” 

The longer-term challenge, he said, is around multi-agent collaboration. 

“Multi-agent collab today in successful environments isn’t very dynamic,” said McKeon-White. “Having true dynamic agents cooperating can create extremely interesting emergent behavior,” he said, pointing to recent Anthropic research on the topic.

While Slack Code is aimed at software development-related tasks, Slack also envisages a similar cross-functional, collaborative approach to AI agent interactions applied to a wider variety of purposes: marketing campaigns, for instance, or legal document reviews. 

“That might not involve code per se, but it does involve a very detailed review of a document and tracking changes and a preview of what’s going to be sent out to the customer,” said Parulekar. “In the future, we see this extending to a lot of different teams and use cases for technical and non-technical users.”

Other features announced Thursday include “agent DMs” that allow for individual interactions with an agent and a new “agents tab” where users can view existing agent conversations.   

Parulekar said Slack Code feeds into a wider Slack strategy centered on a “multi-player experience” for human workers and AI agents. This includes the recent announcement of Claude Tag, which makes Anthropic’s agent available to teams.

“Whether it’s the user experience that we’re evolving — like the agent tab, or coding channels where you can plan, code, test, and ship inside of Slack — it’s all part of that bigger vision of making Slack a great home for agents and furthering that vision of multiplayer AI,” she said.

Kategorie: Hacking & Security
Syndikovat obsah