Agregátor RSS

Granola lawsuit raises concerns over AI note-taking app privacy

Computerworld.com [Hacking News] - 6 Srpen, 2026 - 17:21

AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.

It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.

AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.

However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.

The proposed class action complaint against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  

While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.

The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.

The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”

Granola did not respond to a request for comment.

According to the company’s website, Granola offers two optional “transparency features” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also promises that data used to train its AI models is anonymized and “never sent to third parties.”

The Granola case bears similarities to a separate lawsuit involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.

Reporting on the latest developments in the Otter.ai suit, MLex wrote this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.

The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.

AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said Enza Iannopollo, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.

“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.

Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”

“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.

Kategorie: Hacking & Security

Chrome kašle na design Windows 11. To stejné ale dělá Microsoft s Edgem

Živě.cz - 6 Srpen, 2026 - 16:45
Google z Chromu 151 odstranil experimentální předvolbu. • Aktivovala materiál Mica v záhlaví okna. • Microsoft na designový styl Windows 11 loni rezignoval také.
Kategorie: IT News

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

Bleeping Computer - 6 Srpen, 2026 - 16:02
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]
Kategorie: Hacking & Security

NASA chce prozkoumat jeskyně pod povrchem Měsíce pomocí dronu napájeného laserem přes optické vlákno

Živě.cz - 6 Srpen, 2026 - 15:45
Projekt LUX vyvíjí dron k průzkumu temných měsíčních lávových tunelů • Dron bude napájen laserem přes tenké odvíjené optické vlákno • NASA vyčlenila finance na devítiměsíční studii proveditelnosti konceptu
Kategorie: IT News

Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

LinuxSecurity.com - 6 Srpen, 2026 - 15:07
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
Kategorie: Hacking & Security

Alza má další variaci na Logitech MX Master. Nová myš už nabídne i kolečko se setrvačníkem

Živě.cz - 6 Srpen, 2026 - 14:45
Alza uvedla svou zatím nejlepší kancelářskou myš. • Eternico M505 je téměř klonem Logitech MX Master. • Láká na tichá tlačítka, hliníková kolečka a design.
Kategorie: IT News

Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities

LinuxSecurity.com - 6 Srpen, 2026 - 14:21
Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the security work did not end with those fixes.
Kategorie: Hacking & Security

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

The Hacker News - 6 Srpen, 2026 - 14:16
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI’s ‘Rotten to the core’ defense is its weakest play yet

Computerworld.com [Hacking News] - 6 Srpen, 2026 - 14:07

Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.

The filing

In case you missed the news, OpenAI filed a motion to the court to dismiss Apple’s recent lawsuit against it. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”

The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”

The narratives can change

As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a “cookie jar” defense, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.

OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.

Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.

What the truth might be

The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the services of former Chief Design Officer Jony Ive, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.

Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. Apple is asking for discovery precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.

What happens next?

I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.

OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its manufacturing partners and sought access to secret manufacturing processes Apple developed with them.

Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. 

Fight or settle

What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.

Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent.

I expect they’ll find it.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

IT department put sticky notes on the laptops to help employees log in

The Register - Anti-Virus - 6 Srpen, 2026 - 14:00
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations' security screw-ups, in hopes the rest of us can learn a valuable lesson. This week’s story involves an IT department that ought to know better putting user credentials in the precisely wrong place. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our terrifying tech tale comes courtesy of Marc Bishop, director of business growth at Wytlabs, a marketing and SEO company. In the course of his career, Bishop came across one firm where the people guarding the henhouse left the keys out where almost anyone could get them. Bishop’s client company was responsible on the surface. They had a strong password policy and even made users take security training. Then they moved offices, and that's when basic security hygiene went out the window. The company decided to take some old laptops and give them out to new users. To make life easy for the recipients, they put sticky notes – everyone’s favorite credential-sharing tool – on the laptops with the name of each employee and their initial login credentials on it. Let’s just stop for a moment to remark on how bad it is to put usernames and passwords on a piece of paper where the wrong person could see them. Even the IT department should not know your password, should someone in IT themselves turn rogue. So, even if the laptop stayed on a shelf in a closet that only the support staff had access to, having that sticky note would be bad. However, our situation is even worse because the laptops in question were stored in a conference room while the facilities team finished readying the office for the move. During that time, anyone who had access to the conference room could go in and get multiple user account credentials. And that's exactly what happened: A contractor entered the conference room and took pictures of the sticky notes. This non-employee later logged in remotely and accessed all kinds of proprietary data, including planning documents that were sitting on shared drives. What’s particularly shocking about this story is that the IT department was the cause of the information leak. People who work in tech and are charged with maintaining security should never put a password, even a temporary password, out in the open. Password security is paramount. If someone is starting with a new account, send the credentials through an encrypted channel - and preferably ensure only the intended recipient can view the temporary password. ®
Kategorie: Viry a Červi

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

The Hacker News - 6 Srpen, 2026 - 13:49
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

The Hacker News - 6 Srpen, 2026 - 13:33
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

The Hacker News - 6 Srpen, 2026 - 13:30
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a [email protected]
Kategorie: Hacking & Security

80 % čistoty, 2 % námahy. Stojan na kolo Gearrista automaticky vyčistí řetěz po každé jízdě

Živě.cz - 6 Srpen, 2026 - 12:45
Dánská značka Gearrista řeší problém, který má každý cyklista, který chce udržovat své kolo ve špičkovém stavu – čištění řetězu. Gearrista System je stojan, do kterého postavíte kolo po každé jízdě, a tlačítkem spustíte desetiminutový program na čištění řetězu a kazety. Žádná voda, žádná chemie, ...
Kategorie: IT News

Novou baterii pro elektromobily nabijete na 97 % za pouhých osm minut. Ale jen s megawattovým zdrojem

Živě.cz - 6 Srpen, 2026 - 11:45
Automobilka Hongqi otestovala baterii s rychlým dobíjením za 8 minut • Nová čínská baterie výrazně snižuje vnitřní odpor i celkové přehřívání • Prototyp vyžaduje zatím nedostupné megawattové nabíjecí stanice
Kategorie: IT News

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

The Hacker News - 6 Srpen, 2026 - 11:19
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

The Hacker News - 6 Srpen, 2026 - 10:57
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Polohovací stůl tam, kde je málo místa. Tenhle má na šířku jen 88 cm a stojí jen 2100 Kč

Živě.cz - 6 Srpen, 2026 - 10:45
Elektricky polohovatelný stůl Di volio Barga stojí jen 2100 Kč. • Má i pracovní desku, fyzická tlačítka, displej a držák na sluchátka. • Díky šířce jen 88 cm se hodí i do menších prostor.
Kategorie: IT News
Syndikovat obsah