BriefTechNews

Meta dumps Google Chat for Slack, Atlassian starts metering AI, and Dropbox breach hits via Lenovo

7 min read · 12 sources

TL;DR
  • Meta is migrating its internal communications from Google Chat to Slack after AI chief Alexandr Wang called Slack a "rich conversational interface for agents."
  • Atlassian's expanded usage-based pricing, effective December 3, will meter Rovo credits, flow automation steps, and AI-agent outcomes while keeping Rovo Search and inline summaries free.
  • A Dropbox breach tied to roughly 5,000 accounts exploited a Lenovo email-verification flaw to authenticate without the Dropbox password.
  • Anthropic's Enterprise Frontier Safeguards combine zero data retention with abuse detection by keeping monitoring data in customer-controlled cloud infrastructure.
  • Chrome 153 ships September 8 as the first two-week stable release, with Extended Stable holding at eight weeks for enterprise.

Meta’s AI chief told the company in a memo that Slack is a “rich conversational interface for agents, mature developer tooling and strong 3P [third-party] integrations.” That was the line, and Meta is moving its internal communications off Google Chat and onto Slack. For engineers inside Meta, the implication is that the chat client is no longer just a place to argue about lunch - it is becoming the runtime where agents read context, call tools, and hand work back to humans.

The news is also a tailwind for Salesforce, which paid $27.7 billion for Slack in 2021. Its stock surged nearly 23% after an Anthropic partnership and strong results, and Meta’s move gives Slack a flagship reference that no other collaboration vendor has.

A Dropbox breach tied to roughly 5,000 accounts exploited a Lenovo email-verification flaw to authenticate without the Dropbox password entirely.

Atlassian starts metering AI like infrastructure

Source: atlassian.com ↗

Atlassian is expanding usage-based pricing effective December 3, 2026. The new meters cover Rovo credits (Rovo Chat, Confluence AI Slides, Jira Coding Agent, Teamwork Graph queries), automation steps inside flows, and outcome-based AI agent resolutions. Rovo Search and inline summaries stay free. Built-in allowances come with paid cloud plans, and admins get controls to cap spend, pre-pay for credits, or pay-as-you-go.

For IT and FinOps teams, this is the moment to stop treating Atlassian as a flat per-seat line item. Atlassian’s own customer numbers give a sense of the multiplier: one reporting process ran 40x faster and another saved 400 hours per month via automations. The new model turns those gains into a billable surface, so budgeting AI and automation alongside seats and storage is now part of running Jira cleanly.

A Dropbox breach that rode a Lenovo integration

Source: bleepingcomputer.com ↗

Dropbox disclosed a breach affecting roughly 5,000 accounts between August 4 and 21. Attackers exploited a flaw in Lenovo’s email verification flow, registered fraudulent Lenovo IDs against victims’ email addresses, and then used those IDs to access linked Dropbox accounts without ever supplying a Dropbox password. The root cause was Dropbox trusting Lenovo’s identity assertion without requiring an existing Dropbox login confirmation.

Lenovo characterised it as a “legacy integration” limited to Dropbox, not Lenovo customers. Dropbox has now expired Lenovo-ID sessions and forces a Dropbox password for any Lenovo ID login. The lesson for security teams is that federated identity risk extends well past your primary IdP: every OAuth-style “Sign in with X” partner is a potential bypass, and the trust decision lives in the relying party, not the identity source.

Cisco is rewriting the CIO job description

Source: cio.com ↗

Cisco EVP of operations Thimaya Subaiya argues the CIO role is moving away from UX integration and build-vs-buy judgement and toward a harder question: should the process exist at all? Subaiya, who runs IT, security, supply chain, and AI strategy at Cisco, created a Chief AI Officer role 2.5 years ago by consolidating AI functions, intends to fold it back into IT, and pointed at Cisco’s internal “AI framework for MCP connectors” as the connective tissue.

Cisco is currently hiring for the seat. The company’s stated preference is for a candidate who may not come from a traditional IT background, which is a signal in itself: the bar is shifting toward people who can redesign work, not just keep the systems lit.

Rezolve AI's margins tell the enterprise sales story

Source: industrycontents.com ↗

Rezolve Ai’s first-half revenue jumped to $130.8 million from $6.3 million, driven by acquisitions and expansion. Gross margin fell to 48.9% over the same period, and the company has not disclosed how much of the top line is partner-driven. The trade-off is the lesson: enterprise AI vendors are leaning harder on cloud providers, distributors, consultancies, and systems integrators because those partners already hold the contracts, the procurement approvals, and the delivery teams. The margin cost is the price of admission to the deal.

Anthropic's Enterprise Frontier Safeguards

Source: anthropic.com ↗

Anthropic announced Enterprise Frontier Safeguards (EFS), a stack that pairs zero data retention with automated detection of serious misuse of frontier models. EFS stores monitoring data in customer-controlled cloud infrastructure and sends signals back to customer teams, with phased rollout beginning later this fall and interim ZDR on Fable 5 and 5.1 for eligible customers until EFS is generally available. AWS, Google Cloud, Azure, and over 100 customers across financial services, healthcare, and other regulated industries helped design the approach.

The product sits on Claude Code, Claude Enterprise, Bedrock, and Microsoft Foundry, and targets the core conflict in regulated AI adoption: you want long-term telemetry to catch abuse, but the regulator wants nothing retained. EFS is Anthropic’s answer to that, and it is one of the first vendor stacks to put the trade-off on the buyer’s side of the line.

Adobe puts Creative Cloud inside Slack

Source: techcrunch.com ↗

Adobe launched an MCP integration that puts Firefly, Photoshop, Premiere, Acrobat, Illustrator, Lightroom, and 70+ other tools inside Slack via Slackbot. Available initially to Slack Business+ and Enterprise+ teams, the integration can route Slack conversations and Canvas content into Adobe tools to produce PDFs, images, or videos, and edit Creative Cloud assets in-chat. It follows similar Adobe hooks into ChatGPT and a planned Gemini integration.

For IT, the near-term question is governance: who can fire off a Premiere render from a Slack thread, and where does that asset land? Adobe’s framing - users want to “save time” and reach Adobe “wherever they’re already working” - is true, but it also means the data flow now runs through Slack, which becomes another system to audit.

Google Workspace Studio picks up Drive, Gmail, and Chat actions

Source: workspaceupdates.googleblog.com ↗

Workspace Studio is gaining automation steps for copying or moving Drive files, replying to Gmail threads, and posting replies in Google Chat. Two controls matter for IT: admins can disable individual actions outright, and they can require user approval when a workflow would push data outside the organisation. Both give a way to stop the worst exfiltration patterns before they ship.

Chrome is moving to a two-week stable cycle

Source: developer.chrome.com ↗

Chrome is cutting its stable release cycle from four weeks to two starting with Chrome 153 on September 8. Chrome has shipped milestone releases every four weeks since 2021, layered weekly security updates on top in 2023, and added an early stable channel; the new schedule covers Desktop, Android, and iOS with no changes to Dev or Canary. Extended Stable stays at eight weeks for enterprise and embedder rollouts. The concrete shift: M154 stable moves from October 20 to September 22. For change-management teams, the practical effect is a tighter review window - half the time between stable builds means the same headcount has to handle twice the cadence.

Okta puts AI agents on the identity map

Source: okta.com ↗

Okta added AI agent discovery to Identity Security Posture Management for all existing subscriptions. The feature inventories shadow AI agents, unmanaged OAuth grants, and MCP servers, with agent and MCP server discovery via a CrowdStrike integration in early access, and inventory for homegrown agents built in Salesforce Agentforce, Microsoft Copilot Studio, and Amazon Bedrock/Agentcore. OAuth grant discovery runs through the Okta Browser Plugin, and ISPM now unifies human and non-human identities under one posture view with a dedicated “AI agent risk” category and dashboard count. New tenants get it immediately; existing customers get it on a rollout.

For security teams, the practical value is simple: every agent you cannot see is an identity you cannot revoke, and Okta is betting that posture management is where that visibility has to live.

Security notes: CrossRAT and Defender false positives

Source: objective-see.org ↗

Objective-See published a deep technical look at CrossRAT, a Java-based, cross-platform implant (Windows, macOS, Linux) tied to the Dark Caracal espionage campaign documented by EFF and Lookout. Dark Caracal has hit governments, militaries, utilities, financial institutions, and defense contractors across 21+ countries via social media phishing and physical access, alongside the Windows Bandook RAT. The write-up covers Java package names like cross/rat/ClassPacker, persistence via scheduled tasks, LaunchAgents, and cron, and C2 domains including dmf-iraq[.]com and kernelpdf[.]com. Useful as a reference for detection engineering against an implant that does not behave like the usual Windows-first tooling.

Separately, Microsoft is investigating incident MO1465962, in which Defender for Office 365 Safe Links is misclassifying legitimate Google search URLs as malicious. The wrong verdict can block users from opening links they pasted by hand, and it generates related incidents inside the Defender portal and Microsoft Sentinel. Microsoft blames an “inaccurate security classification” and is working on remediation. For IT and SOC teams, expect extra helpdesk tickets and a bump in Defender false-positive volume - and another reminder that Safe Links can both miss real phishing and block safe traffic in the same week.

Get the brief

Liked this one? The rest of today's stack — AI, crypto, fintech, infra — lands in your inbox tomorrow morning. Five minutes, no hype.

About Me Author

My name is

BriefTechNews

A daily digest of what actually moved in AI, tech, crypto and fintech, assembled and written with AI, and reviewed before it publishes. Read More
Tags

You May Also Like