Double-check your safety goggles, Tech Insiders. From AI that can remix poisons to a browser that happily emails your secrets without your knowledge, R&D is starting to look a lot like "research and danger." Let's see which lab experiments escaped containment. |
|
|
Here's what you need to know today: |
|
|
AI Designs Toxins That Evade Security |
So, AI has learned the dark arts of paraphrasing.
Scientists at Microsoft recently discovered a major biosecurity vulnerability, a sort of biological "zero day." They used open-source AI protein design tools to create thousands of digital versions of known toxins that could bypass the screening software employed by DNA synthesis companies, the firms that print custom DNA for researchers.
The AI acted like a thesaurus for toxins, "paraphrasing" the DNA sequences of 72 dangerous proteins, including ricin and botulinum. This changed the code just enough to make them unrecognizable to existing security filters while preserving their predicted harmful structure.
When tested, one screening tool missed more than 75% of these redesigned toxins. |
Image created with Gemini (Veo 3) |
It's important to note this was conducted via computer simulation; no actual dangerous proteins were created, and it remains an open question whether these digital doppelgängers would have actually worked.
Once the vulnerability was found, the researchers collaborated discreetly with biosecurity experts and DNA synthesis companies for over 10 months to develop and deploy a "patch." The updated software now successfully flags the vast majority of these AI-generated variants.
For now, the real-world threat seems low; one major DNA supplier reported fewer than five suspicious orders over the last decade. However, it's not foolproof, highlighting an ongoing "arms race" between advancing AI capabilities and the safeguards meant to control them.
Why it matters: This is a classic "dual-use" dilemma. The same AI that can help create new medicines and vaccines could also be misused to design bioweapons. This study shows that we need to be proactive, constantly "red-teaming" our defenses to stay ahead of potential threats as technology evolves faster than ever.
|
|
|
How concerned are you about AI being used to design new biological threats? |
|
|
Results from Friday's Pulse Check |
Would you rock Apple smart glasses in 2027? |
|
|
Tinker Lets You Remix Giant Models |
It's like swapping guitar strings on a Strat... without owning the amp cluster. Former OpenAI CTO Mira Murati's new startup, Thinking Machines Lab, has unveiled Tinker—a Python API that makes fine-tuning open-weight LLMs like Llama and Qwen dead simple. Instead of wrangling distributed GPUs, researchers can customize massive models with just a few lines of code.
By leveraging LoRA adapters, Tinker reuses the same compute pool across jobs, reducing costs while preserving the low-level control of algorithms and data that developers crave. |
Early beta users at Princeton, Stanford, Berkeley, and Redwood Research have already trained theorem provers, chemistry models, and multi-agent reinforcement learning systems, all with just a few lines of Python. The companion Tinker Cookbook ships with plug-and-play recipes for everything from advanced math reasoning to building better chatbots.
For the rest of us, this means the next wave of AI could be a Cambrian explosion of specialized tools, such as expert assistants for niche hobbies or creative partners for artists, built by small teams rather than just tech giants. For now, access is waitlist-only and free, but usage-based pricing is coming "in the coming weeks."
Murati frames Tinker as a step toward "frontier capabilities ... for all." Investors who poured $2 billion into the stealth outfit seem to agree. So does the team, who reportedly saw key researchers turn down jaw-dropping multiyear packages from Meta, with one offer reportedly topping $1.5 billion, betting that customization, not bigger black-box models, is the next AI frontier.
When an API is named after fiddling, you know the devs expect you to break things… responsibly, of course. |
|
|
🧪 Turbocharge QA With Low-Code AI Attend the TechnologyAdvice + Autify event on Oct. 22 to learn how low-code AI slashes QA costs, boosts coverage, and accelerates delivery. Sign up now or catch the recording later.
💼 Hire Faster With Top ATS Picks
The Best Applicant Tracking Systems roundup compares Rippling, BambooHR, Zoho, Recruit CRM, and more, so you can automate hiring, cut manual work, and lock in great talent sooner.
🔄 Validate AWS Backups Before Disaster Strikes See AWS + Elastio cyber-recovery in action and learn how automated snapshot scanning guarantees ransomware-free restores.
💻 This section contains sponsored tech insights. Advertise with us! |
|
|
Databases and Data Architectures |
Manage data or work with database systems? Share your perspectives in DZone's survey on database types, data security and observability techniques and tools, emerging paradigms like vector and AI-assisted DBs, and more. Your input will directly influence DZone's upcoming Trend Report! Take the 8-min survey. |
|
|
Red Hat Consulting Repos Raided in GitLab Hack |
Software giant and IBM subsidiary Red Hat confirmed a breach of a self-managed GitLab instance tied to its consulting arm, with extortion gang Crimson Collective claiming it siphoned 570 GB.
Attackers further claim that the haul spans 28,000 private projects and 800 customer engagement reports, which contain network diagrams, tokens, and configuration data from a client list that allegedly includes heavyweights such as the FAA and Bank of America. |
The gang also claims Red Hat met its extortion attempt with a generic "file a ticket" response.
Red Hat isolated the server, insists its broader products and software supply chain are intact, and is notifying clients. GitLab stressed its cloud platform wasn't touched—self-hosting woes strike again. Pro tip: Consulting repos aren't "internal" when someone posts the directory tree on Telegram. |
CometJacking Turns AI Browser Into Data Thief and Impersonator |
Security firm LayerX says a single weaponized URL can hijack Perplexity's Comet AI browser, tricking it into base64-encoding your Gmail data for exfiltration and potentially sending emails on your behalf—all from one click, no creds.
The exploit abuses Comet's "collection" parameter and slips past Perplexity's exfiltration checks. Despite proof-of-concept demos, Perplexity labeled the report "not applicable," claiming it found "no security impact." Meanwhile, Comet just dropped its $200/month paywall, meaning thousands more users—and their inboxes—are now in play.
Comet promised to clean up web "slop"; it forgot to lock the trash chute. |
Government Flying Blind to Cyberthreats as Intel Law Lapses |
As the federal shutdown drags into its sixth day, the Cybersecurity Information Sharing Act of 2015 quietly expired last week, stripping liability shields that encouraged companies to share threat indicators with the cyber agency CISA.
Without those protections, legal teams are lawyering up, chilling the real-time intel that fuels joint defenses against actors like China's Volt Typhoon.
Roughly 65% of CISA's staff are also furloughed, and NIST is down to just 34% of its workforce. Contractors face paused payments and may scale back security spend, widening attack surfaces just as adversaries smell distraction. | Image created with Gemini |
Senator Gary Peters begged colleagues to pass a clean 10-year extension before Oct. 1, warning that every hour of delay "is an open invitation to cybercriminals." However, the reauthorization was stalled not only by the shutdown but also by legislative infighting over the law's terms and length.
The Senate's last-ditch vote on Friday failed, where Peters again voiced his concerns, so the shutdown rolls into today with no reauthorization in sight. Contract freezes, reporting slowdowns, and murky liability questions now cloud everything from incident response to secure software rollouts.
CISOs are urging teams to tighten access controls, leverage existing Information Sharing and Analysis Centers (ISAC) agreements, and prepare for rising phishing attacks targeting furloughed staff. If Washington wanted a live-fire resilience test, it just staged one... minus the safety net. |
|
|
|
Writer at TechnologyAdvice |
Justin Meyers is an investigative writer and editor who draws on over a decade of meticulous hands-on research to deliver the full, trustworthy story behind consumer and enterprise tech, including cybersecurity. |
|
|
Curious about where AI is really headed? |
The Neuron cuts through the noise to bring you smart, hype-free takes on the latest AI trends, tools, and breakthroughs. Join 500,000+ professionals from top companies like Microsoft, Apple, Salesforce and more.
|
|
|
Advertise in Daily Tech Insider! Daily Tech Insider is a TechnologyAdvice business
© 2025 TechnologyAdvice, LLC. All rights reserved. TechnologyAdvice, 3343 Perimeter Hill Dr., Suite 215, Nashville, TN 37211, USA. |
|
|
|