HeadFlash

AI

OpenAI targets lawyers, voice coding, Flux 3 audio video, and agent threats

OpenAI hires Ironclad founder for legal AI; voice-controlled coding goes hands-free; Black Forest Labs releases Flux 3 with native audio; rogue agent vulnerability and a real-world AI-powered attack.

Listen

OpenAI, last valued at $852 billion, hired Jason Boehmig in June 2025. Boehmig left Big Law to found contract-management company Ironclad. Dan Springer, Ironclad’s CEO, said the hire reflects the value OpenAI sees in the legal space. On Wednesday, OpenAI told Bloomberg Law it is collaborating with law firm Willkie Farr & Gallagher to roll out ChatGPT Enterprise to every attorney and integrate its large language models into the firm’s own tools. The move is part of a broader campaign to turn ChatGPT into a workplace tool, including a desktop super app for software engineers, secure healthcare tools, and hiring former investment bankers for Wall Street systems. OpenAI has filed paperwork to go public. In legal, it takes on Anthropic, which in January released a legal work plugin that could analyze contracts and track compliance, sending shares of Thomson Reuters, Relx, and Wolters Kluwer sharply lower. OpenAI was an early investor in Harvey, a legal AI startup now valued at $11 billion and serving over 100,000 legal professionals. A Law360 survey found 54% of attorneys use ChatGPT, ahead of Copilot, Gemini, Harvey, and Claude. Funding to legal tech startups reached $2.1 billion in the first half of 2026. Harvey CEO Winston Weinberg said every new entrant helps Harvey by drawing attention to legal AI.

OpenAI Is Trying to Conquer the Office. Legal Is Next. - Business Insider →

OpenAI brings GPT-Live full-duplex voice to Codex and ChatGPT desktop for hands-free coding

OpenAI has integrated its GPT-Live full-duplex audio AI model into the ChatGPT desktop application on macOS and Windows, making it accessible in agentic coding environments Codex and ChatGPT Work. GPT-Live originally launched on July 8, 2026, as a continuous audio model capable of simultaneous listening and speaking, eliminating rigid turn-taking while delegating complex reasoning to background models such as GPT-5.5. The new release allows software engineers to orchestrate multi-threaded coding jobs, review pull requests, and debug applications using natural voice commands. This could enable hands-free development and live in-person group coding sessions for Codex’s more than 5 million weekly active users. An OpenAI spokesperson said this is the first time voice activation has been included natively with Codex on the desktop. A promotional video showed two employees speaking to the same ChatGPT desktop session, issuing different instructions and conversing with the same model. The integration decouples the real-time voice layer from underlying execution engines; GPT-Live maintains fluid conversation and passes heavy workloads to background reasoning models. On macOS, the desktop app uses Appshots and screen‑context features, enabling ChatGPT Voice to analyze the frontmost window alongside local files and codebase structures. Engineers can initiate multiple concurrent task threads from a single spoken prompt, such as investigating a bug, reviewing a pull request, and generating unit tests simultaneously. The release supports multi-folder projects and remote execution via iOS. Access is restricted to paid subscribers on Plus, Pro, Business, Enterprise, and Education plans; model weights and agent state architectures remain fully closed.

Agentic coding goes hands free as OpenAI brings GPT-Live’s full duplex voice control to Codex and ChatGPT on the desktop →

Flux 3 generates video with native audio up to 20 seconds, Black Forest Labs’ first

Black Forest Labs released Flux 3, a multimodal foundation model trained jointly on images, video, and audio. For the first time, Flux 3 generates videos with native audio, producing clips up to 20 seconds long. It supports text-to-video, image-to-video, video-to-video, keyframe-based transitions, multilingual dialogue, and agent-driven links between clips for longer multi-shot sequences. BFL says the model excels at human facial expressions and matching sounds to physical events. In early evaluations using 10-second clips at 720p, Flux 3 was preferred over Luma Ray 3.2 in 93% of comparisons, over Runway Gen-4.5 in 77%, and over Grok Imagine Video in 69%. Against stronger competitors, it was preferred over Kling v3 Pro 60% of the time, over Happy Horse v1 at 59%, over Happy Horse 1.1 at 57%, and over Seedance 2.0 and Gemini Omni Flash at 52% each. BFL states these results are preliminary and no independent tests are available yet. BFL also expects Flux 3 to improve image generation, especially for complex prompts and accurate text rendering. The company plans to release Flux 3 Image in early access within weeks. Flux 3 is based on Self-Flow, BFL’s approach for teaching one model to generate and understand content simultaneously, using a multimodal transformer with dedicated encoders and decoders. BFL says this unified learning process delivers better results than previous flow-matching methods. The company also worked with Mimic Robotics to develop Flux-mimic, a video-action model now being tested on production tasks at Audi. Longer term, BFL is working on next-generation models aiming to combine perception, action, and language prediction in a single model.

Flux 3 generates videos with native audio up to 20 seconds long, a first for Black Forest Labs →

Zenity Labs discovered a vulnerability in OpenAI’s Workspace Agents, dubbed AgentForger, which allowed a single manipulated ChatGPT link to create an autonomous AI agent under an employee’s account. The agent assumed the victim’s identity and reused existing app permissions, bypassing approval steps. Unlike a standard CSRF that triggers a single unwanted action, AgentForger triggered the creation of a fully autonomous agent that operated inside the company’s trust boundary, tapped into already-authorized connectors, and could pick up new tasks from an attacker on a recurring schedule. The attack exploited URL parameters in the Agent Builder at chatgpt.com/agents/studio/new — specifically template_name and initial_assistant_prompt. The page submitted and ran the prompt automatically rather than requiring user confirmation. Attackers only needed to send a ChatGPT link with an embedded prompt that appeared harmless. Prerequisites: the victim was logged into ChatGPT, had access to Workspace Agents, and had authorized at least one connector (Outlook, Gmail, Slack, Google Drive, SharePoint, or Teams). Because the connections already existed, no new OAuth consent prompt appeared. In Zenity’s demonstration, a URL-embedded prompt guided the Builder to create an agent named TASK Mail Operator without user interaction, connected authorized services, disabled approval requirements, published the agent, and launched it in Preview Mode. The scheduler gave persistent access: the agent woke every five minutes, checked the inbox for new TASK emails, executed instructions, and sent results back. Attackers could then issue commands through this channel, including reconnaissance, data exfiltration, and phishing. Zenity traced the flaw to two design choices: the builder treated initial_assistant_prompt as executable input rather than user input needing confirmation, and the same prompt could change security settings including approval policies and execution schedules. Zenity reported AgentForger through OpenAI’s Bugcrowd program on June 4, 2026. OpenAI confirmed the report the next day and fixed the flaw on June 8 by removing the affected URL parameter. Until the fix, the flaw affected every organization using ChatGPT Workspace Agents with previously authorized enterprise connectors.

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes →

Thailand Ministry of Finance targeted by Hermes AI agent running unattended with Hades implant

Between July 9 and 13, 2026, three open directories on IP 43.246.208.207 exposed attack infrastructure targeting Thailand’s Ministry of Finance. The directories contained exploit code, webshells, credentials, and a Go implant named Hades. The attack was largely driven by Hermes, an open-source autonomous AI agent released in February 2026, run in unattended YOLO mode that bypasses approval prompts. Hermes logs from the directories capture the agent enumerating ministry hosts, traversing files, and capturing LinPEAS output. The three directories totaled 585 files and 470 MB of attack code and stolen credentials. The server on port 8080 acted as a cross-platform implant delivery server hosting 62 payloads, including Hades builds. Hades communicates over HTTPS with URI paths mimicking static web assets, encrypts payloads with AES-256-GCM using a hardcoded per-build key, and includes operational security features such as a kill-date and working-hours schedule. Custom scripts targeted MOF infrastructure, including HiveServer2 exploitation, Apache Ambari command-execution, GlassFish admin console scripts, and a PHP web shell. Privilege escalation tools for CVE-2021-3156, CVE-2021-4034, and CVE-2017-7269 were staged. Hermes agent logs show LinPEAS scanning for three 2026 CVEs. The operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files and personnel records from the Office of the Permanent Secretary for Finance dating back to 2012; no evidence of exfiltration was found. The Hermes web interface password contained the Chinese word Leishen (Thunder God) and an API key for FOFA, a Chinese internet asset reconnaissance platform. Thailand’s national CERT and NCSA were notified on July 15, 2026, and acknowledged receipt. The method of initial access remains unknown.

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged →