
Scammers used AI to clone executives' voices well enough to go after some of the sharpest trading desks on Wall Street this week. If a scam like that can target professional risk managers, it's worth five minutes of your attention today. Underneath that story, a federal court just expanded what AI shopping bots can do on your website without asking first, and a security firm found most of the connectors linking AI agents to business tools wide open. Here's what actually happened and what to do about it.
Your employees are connecting AI to everything. Now what?
ChatGPT and Claude don't just answer questions anymore. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack. The AI can read, write, and take actions on company data. Most IT and security teams have no visibility into any of it.
Harmonic Security Connectors changes that. It sits inline with every AI-to-app connection, so you see each call, control what data moves, and block destructive actions before they happen. Employees notice nothing different.
See what's actually running across your business in a live demo.
AI Voice Clones Just Targeted Wall Street's Sharpest Traders
What happened: Attackers used AI-cloned voices to impersonate senior executives and target employees at major hedge funds, including Citadel, Two Sigma, and Point72, in a coordinated phishing campaign, according to Cybernews. The attacks were convincing enough that FINRA's Fusion Center, the group that coordinates a response when Wall Street firms are hit by the same threat at once, was activated. No firm has confirmed a financial loss, but security teams say the attempts were realistic.
Why it matters to you: These attackers went after firms with some of the best security money can buy. If AI voice cloning is good enough to target professional risk managers, it's good enough to target your bookkeeper, your office manager, or you.
What to do about it: Set a rule right now: any request to move money, share credentials, or change payment details gets confirmed through a second channel, a callback to a known number or an in-person check, no matter how real the voice sounds.
A Court Just Ruled AI Shopping Bots Can Visit Your Site Without Asking
What happened: A federal appeals court vacated an injunction that had blocked Perplexity's AI shopping assistant, Comet, from browsing Amazon on behalf of its users, according to Courthouse News. The Ninth Circuit ruled that it's the person using the AI agent, not the company that built it, who is legally "accessing" a website under the Computer Fraud and Abuse Act, a 1986 law originally written to police hacking. Digital rights groups backed Perplexity in the case; Amazon and other publishers argued the opposite.
Why it matters to you: This case was about Amazon, but the reasoning applies to any website. Courts are starting to say AI agents can browse and act on your site on a customer's behalf, whether or not you built your business to allow it.
A Security Firm Found 143,000 Holes in the Tools Connecting AI to Your Business Software
What happened: Data science company Anaconda acquired AI security startup Enkrypt after Enkrypt scanned 25,000 MCP servers, the increasingly common connectors that let AI models plug into outside apps, email, and data, and found more than 143,000 vulnerabilities across 73% of them, according to Anaconda's own announcement. MCP servers have become a standard way to connect AI assistants to business tools over the past year.
Why it matters to you: If you or your team connected an AI assistant to your inbox, calendar, or business software using one of these connectors, there's a real chance it has a known, unpatched security gap.
What to do about it: Before connecting any AI tool to something sensitive, ask what data and permissions it actually needs, and don't grant it more than that.
ChatGPT Just Removed Its Message Limits for Free Users
What happened: OpenAI eliminated the text chat limits that used to cap how much free ChatGPT users could talk to the model each day, rolling out the change alongside an upgraded GPT-5.6 model, according to TechCrunch. Paid subscribers also got new features, including more control over how much the model "thinks" before answering.
Why it matters to you: If you or your team have been paying for ChatGPT Plus mainly to avoid hitting the free daily limit, that reason just disappeared.
What to do about it: Before your next AI subscription renews, check whether the free tier now covers what you actually use it for.
Google Maps Can Now Order Your Food and Book Your Hotel
What happened: Google expanded its "Ask Maps" AI assistant so it can order food through delivery partners, book hotel rooms, buy event tickets, and pull from a connected Gmail and Calendar to help plan a trip, according to Google's own announcement.
Why it matters to you: If your business takes orders or bookings and shows up on Google Maps, AI is increasingly what stands between a customer and your ordering system, not your own website or app.
What to do about it: Check that your hours, menu, pricing, and booking links on Google are accurate. That's what the AI reads before it acts on a customer's behalf.
Texas Just Hit Pause on New AI Data Centers
What happened: Texas Governor Greg Abbott moved to halt approval of new AI data center projects until the state finishes a grid audit, after utilities reported nearly 474 gigawatts of proposed data center demand, roughly 5 times the state's current peak electricity load, according to TechCrunch.
Why it matters to you: Data center demand is a real factor in rising electricity costs in some regions. When a state government hits pause because even it isn't sure the grid can handle the AI buildout, that's worth knowing if your business runs on tight margins and a power bill.
Job Interviews Now Test Whether You Can Actually Use AI
What happened: A three-year study from American University's Kogod School of Business found the share of employer interview questions asking candidates to demonstrate AI skills jumped from 11.6% in 2024 to 42.6% today, while more than 80% of business students now use AI regularly for coursework, according to Kogod's own research report.
Why it matters to you: If you're hiring, "comfortable with AI tools" is quickly becoming as basic a requirement as knowing how to use email. If you're not testing for it, you could hire someone who can't keep up.
What to do about it: Add one practical AI task to your next interview, something like asking a candidate to use ChatGPT to solve a real problem from your business, and watch how they work through it.
Google's Free AI Model Called a Hurricane's Path a Day Early
What happened: Google DeepMind's WeatherNext model now forecasts a hurricane's track and intensity together instead of separately, and the company says it correctly flagged a major storm's landfall about a day before official warnings went out. The underlying model is now public, according to Google DeepMind's own blog.
Why it matters to you: It's peak hurricane season. Extra lead time on a storm's path and strength means more time to protect inventory, move a shipment, or reschedule a job. This is one AI story you don't need to touch directly to benefit from.
The Bottom Line
Here's the pattern under today's headlines: the guardrails keep arriving after the fact. Voice clones got convincing enough to target hedge funds before anyone built a standard defense against them. A security firm found most AI connectors wide open before most businesses even knew to check. Courts are still deciding what AI agents are allowed to do on your website while agents are already doing it. None of this means unplug everything and hide from AI. It means stop assuming the guardrails are already there, and verify for yourself, the same way you'd check a stranger's story before wiring them money. That's the ride. Buckle up, and let's get off the parts that don't matter.
Enjoying the Ride?
If this issue helped you catch a scam before it caught you, forward it to one person who needs the same heads up. New here? Subscribe to get tomorrow's issue in your inbox.
Talk tomorrow,
Mark Shilensky
Follow me personally on Social Media:
Facebook: https://www.facebook.com/MarkShilenskyPage
Instagram: https://www.instagram.com/markashilensky/
Threads: https://www.threads.com/@markashilensky
LinkedIn: https://www.linkedin.com/in/shilensky/
X: https://x.com/markshilensky
TikTok: https://www.tiktok.com/@mark.shilensky
BlueSky: https://bsky.app/profile/markshilensky.bsky.social



