LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

zeroday.news ·

Photo: Wonderlane from Seattle, USA (CC0) via Wikimedia Commons

Microsoft has reportedly committed to implementing new, comprehensive privacy rules and guardrails for its artificial intelligence tools when used in educational settings. This agreement was reached following negotiations with the American Federation of Teachers, signaling a potentially significant shift in how AI technologies are managed within the academic sphere.

The core of this commitment is understood to focus on enhancing the privacy of student data and ensuring responsible deployment of AI within schools. While specific technical details of these guardrails were not disclosed in the reporting, such agreements typically involve measures to restrict how student data collected by AI systems can be used, stored, and shared. This often includes prohibitions on using student data for targeted advertising, commitments to data minimization, and clear policies on data retention and deletion.

For AI products deployed in schools, privacy concerns are paramount due to the sensitive nature of student information and the potential for these systems to collect vast amounts of behavioral and academic data. This class of agreement often addresses issues such as consent mechanisms, ensuring that both students and parents understand and agree to the terms of data collection and usage. It may also involve provisions for regular security audits and transparency reports to build trust with educational institutions and families.

The affected products would be Microsoft's various AI-powered tools and services that are integrated into educational platforms or directly used by students and educators. This could encompass a range of applications, from AI assistants in productivity suites to adaptive learning platforms and content generation tools. The scope of this commitment is likely broad, aiming to cover all AI functionalities within Microsoft's educational offerings.

Typical mitigation guidance for privacy concerns in AI deployments often includes robust data encryption, strict access controls, and anonymization or pseudonymization techniques where feasible. Furthermore, clear data governance policies, regular privacy impact assessments, and comprehensive training for users and administrators on responsible AI use are standard recommendations for organizations deploying AI in sensitive environments.

This development highlights the growing scrutiny on AI's role in education and the broader push for ethical AI development and deployment. As AI technologies become more integrated into daily life, particularly for younger populations, industry-wide standards for data privacy and responsible use are increasingly being sought by advocacy groups and regulatory bodies. The question now remains whether other major technology providers will follow Microsoft's lead in establishing similar, explicit privacy commitments for their AI offerings in the education sector.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and