1 · Evidence grading.
IBM reported that 92% of companies hit by an AI security incident had inadequate access controls on their AI systems. What does that figure support?
A· That the AI models themselves, rather than the surrounding systems, were the root cause in most of these incidents.
B· That weak access control was near-universal among the breached companies — not that it caused the breaches.
C· That 92% of all companies running AI systems have inadequate access controls.
D· That securing the model matters more than securing the systems and accounts around it.
2 · What happened.
Google reported a large-scale use of AI agents on Chrome security. What did the company say the agents did?
A· They found 1,072 Chrome security bugs, which human engineers then fixed over 60 days.
B· They audited 1,072 Chrome security bugs previously reported by outside researchers.
C· They found and fixed 1,072 Chrome security bugs in 60 days.
D· They blocked 1,072 attempted attacks against Chrome users over 60 days.
3 · Error catching.
Statements about Apple's dispute with the bug-bounty platform Bynario:
§1· Apple and the bug-bounty platform Bynario are publicly at odds following a security report.
§2· The flaw at issue was in macOS, and a language model, GPT-5.5, was used to find it.
§3· Apple maintains that the finding was not a genuine security bug.
§4· Apple has recently capped how many reports a researcher can have open at the same time.
§5· That cap limits concurrent open reports rather than the total a researcher may file.