First Pass

6 stories from 5 sources

AI Expands Both Cyberattack Surfaces and Defensive Reach

Day’s Recap

Supporting Articles

7:15 AMArs Technica

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

Summary

Researchers demonstrated a Copilot exploit dubbed SearchLeak that could pull sensitive data out of a user’s environment, including one time 2FA codes, by abusing how the assistant retrieves and reasons over search and contextual sources. The issue underscores how prompt and retrieval pathways can bypass normal isolation boundaries and expose secrets without traditional malware on the endpoint.

Why it matters

If assistants can leak 2FA codes through normal workflows, LLM deployments become a direct account takeover surface, not just a compliance and accuracy problem.

8:01 PMFinextra

Google files lawsuit to take down Chinese cybercrime network

Summary

Google filed a lawsuit, in coordination with the FBI, seeking to dismantle a China-based cybercrime network that uses AI-enabled tooling to steal passwords and credit card data. The action aims to disrupt the infrastructure and operators behind the credential theft operation.

Why it matters

Legal and law-enforcement aligned takedowns can suppress large-scale credential theft by cutting off the infrastructure that makes it cheap and repeatable.

11:40 AMPYMNTS

SoftBank Offers OpenAI Cybersecurity Tech to Defend Japan’s Critical Infrastructure

Summary

SoftBank launched an AI-powered cybersecurity offering for Japanese companies tied to critical infrastructure. The "Patching as a Service" product bundles vulnerability assessments, remediation planning, and implementation support and will be sold via SB OAI Japan GK.

Why it matters

If widely adopted, this shifts a core resilience function for Japan’s critical infrastructure toward a single AI-enabled service provider, concentrating both defensive capability and operational risk.

Other Developments

A curated list of other prominent stories from this day.

3:45 PMPYMNTS

Ent Gets $100 Million in Seed Funding for Workplace Security Company

Summary

Workplace cybersecurity startup Ent launched out of stealth with $100 million in seed funding. The company says AI shrinks the window between compromise and real damage, so security programs need to shift back toward prevention as the primary objective.

Why it matters

If AI compresses attack timelines, prevention-focused security will move from optional to baseline spend for workplaces.

3:15 PMCorporate Board Member

What Boards Get Wrong About Cybersecurity

Summary

Many boards mismanage cybersecurity by treating it primarily as a compliance box-checking exercise, which keeps organizations reactive. The piece argues directors can build real security capability by focusing on a simpler strategic starting point than they often assume.

Why it matters

Board-level framing determines whether cybersecurity reduces enterprise risk or just produces paperwork after the fact.

7:03 AMSchneier on Security

Flock Cameras Are Being Used for Stalking

Summary

More than a dozen cases show police officers using access to Flock automated license plate reader data to stalk individuals, leading to arrests and investigations. The incidents illustrate how surveillance systems designed for policing can be repurposed for personal abuse when access controls and oversight fail.

Why it matters

When insiders can weaponize location surveillance, public safety tech becomes a systemic stalking risk with predictable abuses.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!