This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Welcome Automaters, 👋

Google just dropped a brand-new AI called Gemini 4 Argon, and according to them, it’s officially their most powerful creation yet. Sure, it handles your standard coding, deep-dive research, and writing tasks. But its actual superpower? Cybersecurity.

Google insists Argon was literally trained for defense. It can spot sneaky software bugs lurking in the dark, confirm that they’re actually real threats, and patch them completely on its own. 

Let’s take a look at the other bragging rights Google brought to the table. According to internal metrics, Argon apparently:

  • Smashed records in real-world software engineering.

  • Tied for first place in elite cybersecurity benchmarks.

  • Claimed the crown on a major test covering finance, legal, and professional expert work.

  • Outperformed heavy hitters like OpenAI’s GPT-6 Astra and Anthropic’s Fable and Opus across multiple industry benchmarks.

But hey, big claims require a heavy dose of skepticism, so yeah take those with a grain of salt.

And get this: Their internal engineering teams are already using Argon daily to debug code and slice through giant data piles. Even better? It’s quietly tidying up memory across Google’s massive data centers, magically freeing up hundreds of terabytes without requiring a single dollar of new hardware. Even quantum computing researchers have jumped on the bandwagon to use it.

So Who Gets it? Spoiler alert: definitely not us, at least not yet! Argon is rolling out in cautious little phases, starting exclusively with trusted cybersecurity partners through Google’s Fairwind Program. On top of that, Google is closely collaborating with the U.S. government to run rigorous safety checks before anyone else gets a peek. 

Here’s The Thing: While the tech specs are dazzling, let us look at the bigger picture. The intense competition to build the most powerful model on Earth keeps accelerating at a dizzying pace. At the same time, actual safety conversations and regulatory talks have stalled out completely, which honestly should terrify all of us just a little bit.

Will this new cyber genius save the internet, or is it secretly one step away from breaking into government websites and wreaking absolute havoc? Only time will tell. Grab your popcorn, because we’re definitely going to have to wait and watch how this plays out.

Here’s the last breakdown On Our YouTube Channel:

We will also be doing a livestream today at 3 PM PST/6 PM EST - so wake up with Tak in the YouTube comments section!

Here's what we have for you today

😱 OpenAI's Trusted Domains Hijacked in New Remote Access Trojan Campaign

Security researchers at Huntress just uncovered a jaw-dropping scheme where cybercriminals weaponized a Custom GPT right inside the official ChatGPT ecosystem to trap unsuspecting users. The scam strategy is known as ClickFix, and the scariest part is how fast it bounces right back. 

What Even Is a Custom GPT? 

If you have not played around with them yet, imagine building your own personalized version of ChatGPT. Instead of starting from scratch every single time, you feed the bot specific instructions, reference files, and custom tools. You even get to pick a fun name, a distinct personality, and conversation starters.

Turns out, building custom bots is super fun for the good guys. But spoiler alert: it’s also dangerously fun for the bad guys.

Here’s why this scam worked so terrifyingly well: Custom GPTs are hosted directly on chatgpt.com. When someone clicks a link buried in an email or a rogue message, the web address genuinely starts with chatgpt.com. Naturally, your brain says, "Oh, we’re safe here!"

The anonymous hackers behind this operation christened their creation "Plus 5.6." And because OpenAI uses names like GPT-3.5 and GPT-5 Pro, "Plus 5.6" sounds entirely legitimate to anyone who does not obsess over AI updates every single day. (Unlike us coffee-fuelled nerds! 👋)

  • The Trap: The rogue bot was hardcoded to give the exact same excuse no matter what you typed: claiming the main site was experiencing "limited availability" and begging you to visit a backup domain.

  • The Red Flag: That backup domain lived on Google Sites, a free builder anyone can use without writing a line of code. Sure, it helped the fake page look official at a glance, but let’s be real for a second: why would OpenAI ever use Google Sites as a backup when they practically own the internet?

  • The Fake CAPTCHA: Once you landed on the backup page, a fake Cloudflare-style verification popped up. It instructed visitors to copy a snippet of code and paste it directly into the Windows Run program. That’s the classic ClickFix move: manufacture a fake emergency and hand over a toxic "fix."

The Creepy Part: That lazy little copy-paste trick downloads and executes a nasty Remote Access Trojan (RAT) that Huntress has labeled "@input."

Once this thing claws its way into your machine, a complete stranger basically gets the keys to your digital kingdom. And here’s the nightmare fuel checklist of what they can pull off:

  • View your live screen activity and operate your device remotely.

  • Remotely trigger your webcam, microphone, and system audio to watch and listen in real time.

  • Search through every single file hiding inside your local documents.

  • Audit your installed security software, background apps, and network connections.

And because malware loves company, this RAT routinely downloads extra payload friends and separate threat strains in the background while victims sit there completely oblivious. To top it all off, it communicates through encrypted channels that mimic completely normal web traffic. Researchers note that the entire framework runs with the polish of a professional software outfit.

Just How Bad Was It? According to Huntress, this little campaign successfully ensnared dozens of users, with their security response team handling at least 40 distinct incidents tied to the specific Google Sites domain used in this attack.

Thankfully, the researchers flagged the issue to OpenAI, which swiftly took down the malicious Custom GPT on September 25. But true to form, a brand-new one crawled out of the digital woodwork just two days later. Talk about an exhausting game of malware whack-a-mole. 

The Big Picture: 

This whole saga highlights a terrifying modern trend: criminals are no longer bothering to hack through your firewalls. Instead, they’re simply exploiting trusted AI platforms to pull off elite social engineering stunts. In fact, TechRadar recently reported that ChatGPT has officially joined Microsoft and Google on the dubious hall-of-fame list of the internet's most-impersonated brands.

The Takeaway: A familiar web address is never a free pass to turn off your brain. If a random webpage suddenly hands you a mystery code and tells you to run it, slam the brakes immediately. Stay safe out there!

P.S. Want the full breakdown with all the receipts? Catch it on our YouTube channel, The Automated.

Why Most AI Tools Fail at B2B Customer Service

B2B customer issues rarely resolve in a single interaction. They move across teams, systems, and account history that most AI tools were never designed to track.

A new briefing paper from Harvard Business Review Analytic Services, sponsored by Front, looks at why AI built for high-volume consumer support creates new coordination gaps when it meets the multi-team reality of B2B service, and what leaders should ask before investing in their next AI tool.

Get the free briefing paper to see the three questions that separate tools built for your environment from tools that will create more work.

🧱 Around The AI Block

🤖 AI Workout Of The Day: The Ultimate Guide to Opting Out of AI Model Training on ChatGPT, Claude, and Gemini

Every single major AI chatbot on the block, whether you are team ChatGPT, Claude, Gemini, Copilot, or Grok, shares one deeply unsettling habit. It’s how they treat your juicy, vulnerable, middle-of-the-night prompt history as a free training playground for their models. 

So yes, unless you actively tell them to back off, they’re taking notes.

The good news? Fixing this takes about a single minute per platform. Because your personalization and memory settings live in completely separate buckets, locking this down won't ruin your day-to-day workflow.

Important Reality Check: Opting out is not retroactive. Whatever spicy secrets or frantic essay outlines you already fed these bots are fair game for past training runs. Furthermore, opting out does not magically erase your data, it just stops future harvesting, subject to each platform's unique retention policies.

Let’s break down how to shut down the data-mining machine for the big three, shall we?

1. ChatGPT: OpenAI has your account opted in by default, and they’re not exactly shouting it from the rooftops.

  • Where to find it: Head to Settings, then look for Data Controls, and toggle off Improve the model for everyone.

  • The silver lining: This applies across your entire account on both web and mobile, and your chat history will stay completely intact.

  • Pro-tip: For those moments you’re typing something you want to take to the grave, use the Temporary Chats feature. OpenAI purges those after 30 days and never touches them for training.

2. Claude: Anthropic used to keep their hands clean, but they rewrote the rules to bring every Free, Pro, and Max user under the data-harvesting umbrella.

  • Where to find it: Navigate to Settings, click on Privacy, and turn off Help improve our AI models.

  • The fine print: If you leave it on, they hoard your conversations for up to five years. Shutting it off drops you back down to a standard 30-day deletion window.

  • The catch: Just like OpenAI, turning this off protects your future chats, but they keep whatever they already learned from you.

3. Gemini: Google’s control panel has a shiny new name, Keep Activity, but it operates with the exact same default invasiveness.

  • Where to find it: Dive into your activity settings to switch off Keep Activity.

  • The plot twist: When this is enabled, not only do models train on your prompts, but a subset of chats are actually read by human reviewers. If a human eyeballs your chat, Google keeps it locked away for up to three years, even if you delete your history.

  • The aftermath: Turning the setting off stops future training and halts chat history logging. However, Google still clings to your conversations for 72 hours to keep the servers running, utilizing the final 24 hours just to give you contextual replies.

So, what’s the game plan? Go check your settings right now, slam the brakes on unwanted training, and keep your digital diary actually private.

Oh and, we'll be right back in your inbox tomorrow with the masterclass on locking down your chat history for Copilot, Grok, and Meta. Until then, stay safe out there, besties!

💡 Prompt To Try:

Go lock down your chats!

Is this your AI Workout of the Week (WoW)? Cast your vote!

Login or Subscribe to participate

That's all we've got for you today.

Did you like today's content? We'd love to hear from you! Please share your thoughts on our content below👇

What'd you think of today's email?

Login or Subscribe to participate

Your feedback means a lot to us and helps improve the quality of our newsletter.

More From The Automated

View more
caret-right