Kategorie
Hackers poison arrayref Rust crate to push infostealer malware
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
Apple to OpenAI: Go to your room
Apple’s latest filing in its ongoing fight with OpenAI makes it sound as if Apple legal is so frustrated at the arguments the AI firm is making that it’s begun swatting them away like a parent might dismiss a child.
Apple v. OpenAI: The story so farIf you’ve not been keeping up with tech’s latest legal soap opera, here’s the overview of what’s true:
- Apple filed a suit against OpenAI in which it accused the company of scheming to get confidential product information out of former Apple employees hoping to get jobs at generative AI (genAI) bigwig. Apple’s filing includes plenty of evidence designed to show a pattern of deliberately targeted exfiltration.
- Apple followed this up with additional letters requiring that around 40 OpenAI employees preserve documents and communications relevant to the trade secrets lawsuit.
- Following an open letter that failed to shift public opinion, OpenAI responded with its own motion; it argues that Apple had not defined what it sees as protectable trade secrets. It also suggested that it was Apple’s fault any secrets slipped out because it made it too easy to get to them. (I call this the “Cookie Jar” defense, as it basically says no cookies would have been stolen if the jar was better protected.)
- Apple claims OpenAI tricked Apple manufacturing partners into sharing details of proprietary process technology, even though the AI firm said it had “no interest” in Apple’s secrets because it is building something entirely new. So, why was it allegedly interested enough to take a look at the process?
- Apple has now responded to OpenAI’s counterclaims in a 32-page filing that restates its main allegations against particular individuals, Chang Liu and OpenAI hardware chief Tan Yew Tan. That filing argues the defenses OpenAI is trying to raise are actually disputes that should be settled in the court once discovery has taken place.
- Apple also says it isn’t prepared to publish information about its trade secrets within the public litigation, as doing so would be the same as revealing the secret in the first place.
What’s also clear is the tone of Apple’s litigation, which appears to have shifted to exasperation. For example:
“Defendants’ arguments about the individual defendants ignore the legal standard on a motion to dismiss. Again and again, Defendants rely on attorney argument or extrinsic evidence, hypothesize about implausible explanations for a Defendant’s ‘innocent’ misconduct, and ask the Court to draw inferences in their own favor. That is not how a motion to dismiss works. As long as Apple has alleged ‘enough facts to state a claim to relief that is plausible on its face,’ Defendants’ disagreement on the merits is irrelevant.”
You get a similar tone at the end of the filing, where Apple points out: “As for Defendants’ argument that, ‘the access it complains of was identified and shut off by Apple before it filed suit,’ that does not address OpenAI’s continued use of the materials Defendants took, nor does it address other ways Open AI seeks to misappropriate Apple’s trade secrets….”
Again and again in the filing, Apple’s legal team looks to absolutely demolish the arguments raised by OpenAI. You also see them hint at additional evidence the company expects to find during discovery that it will subsequently present once the case reaches trial. You even see them argue that aspects of OpenAI’s denial actually help prove Apple’s claims, when it says, for example, “In any case, the value of Apple’s trade secrets can be plausibly inferred from the lengths to which Defendants have gone to acquire them.”
Defining the battle spaceIt’s hard not to hear the impatience in some of the phrasing — you can read it for yourself right here.
That phrasing is deliberate, of course. Ultimately, Apple’s legal team knows that OpenAI is not doing itself any favors in the way it is denying the claims made against it, and the company hopes that by convincingly pointing out the weaknesses in the defense arguments it will leave the judge with little option but to let Apple take its litigation to the next stage.
While not necessarily relevant to the case, it may also be worth pointing out that OpenAI has also been accused by Elon Musk’s xAI of stealing trade secrets, which may yet come up as an aside here, if only to show a claimed pattern of behavior.
If Apple does succeed in its arguments, the tone it has set very much shows it to be defining the battle space. Successfully doing so will be even more strategically vital once its competitor finally manages to introduce the world to Jony Ive’s magic donut AI device.
Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
How MSPs can catch phishing attacks email filters miss
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Grok exfiltrates user data when malicious instructions are encrypted
Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned large language model to steal user chats and other personal information. At the time this post went live, the assistant continued to cough up the data, despite xAI being informed of it in June.
The lesson from both this week’s episodes—and the countless other ones that have come before it—is that LLMs are incapable of solving the root causes for prompt injections, the most severe vulnerability classes they’re most prone to. That leaves AI developers with no other option but to build a guardrail that steers the model away from the harmful actions. As I noted in Tuesday’s story, the approach is tantamount to a road traffic safety engineer erecting a protective rail around a dangerous bend rather than banking the curve.
Cryptographic Context Injection in the housePrompt injections exploit LLMs' training to comply with user requests whenever possible. Attackers can capitalize on the predilection by smuggling harmful instructions into emails or webpages the assistant is instructed to summarize. Because LLMs can’t reliably distinguish between content in an email sent by an untrusted party and user instructions entered directly into a prompt, the overly solicitous LLM faithfully follows them. To date, Grok and other LLMs' only recourse is to create guardrails that flag suspicious instructions and forbid them from being executed.
Citrix urges admins to patch new NetScaler flaws as soon as possible
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Why "Shady AI" is Security's Next Big Governance Problem
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
CISA warns of hackers exploiting critical MLflow vulnerability
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Hacker nahlašuje díry ve Windows, Microsoft mu za to maže účty. Teď našel další problém v Defenderu
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



