aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
3,710
[LAST_24H]
1
[LAST_7D]
1
Daily BriefingSaturday, May 16, 2026

No new AI/LLM security issues were identified today.

Latest Intel

page 91/371
VIEW ALL
01

I have always seen myself as ‘progressive’ – but with AI it’s time to hit the brakes | Peter Lewis

policyindustry
Apr 2, 2026

This article discusses concerns about the rapid advancement of AI technology and argues that progressive voices are not adequately addressing the risks of automation and economic disruption. The author expresses skepticism about AI industry leaders, using Anthropic's CEO as an example, questioning whether their stated commitment to safe AI development should be trusted despite their public statements about safety concerns.

The Guardian Technology
02

Microsoft’s new ‘superintelligence’ game plan is all about business

industry
Apr 2, 2026

Microsoft has reorganized its AI leadership, with Mustafa Suleyman taking on a new role as the company's first CEO of AI focused specifically on pursuing superintelligence (AI systems that would surpass human intelligence across all tasks). The company's renegotiated contract with OpenAI has enabled this strategic shift, which Suleyman says he had been planning for nearly a year.

The Verge (AI)
03

Google Home’s latest update makes Gemini better at understanding your commands

industry
Apr 2, 2026

Google has released an update to its Home app that improves Gemini (Google's AI assistant) at understanding natural language commands for controlling smart home devices. The update allows users to describe desired settings in more natural ways, such as requesting "the color of the ocean" for lighting or specifying exact temperatures and humidity levels, and improves Gemini's ability to identify which devices are being controlled.

The Verge (AI)
04

Erratum: Adversarial Machine Learning in IoT Security: A Comprehensive Survey

research
Apr 2, 2026

This is an erratum (correction notice) for an academic survey paper about adversarial machine learning in IoT security (the practice of deliberately fooling AI systems used to protect internet-connected devices). The notice appears in ACM Computing Surveys journal, Volume 58, Issue 10, published in July 2026.

ACM Digital Library (TOPS, DTRAP, CSUR)
05

OpenAI acquires TBPN

industry
Apr 2, 2026

OpenAI has acquired TBPN, a media platform that covers AI news and hosts conversations with influential figures in tech and business. The acquisition aims to help OpenAI communicate more effectively about AI's impact on society while keeping TBPN's editorial independence intact.

OpenAI Blog
06

Codex now offers more flexible pricing for teams

industry
Apr 2, 2026

OpenAI has introduced more flexible pricing for Codex, a code-generation AI tool that helps developers write software faster. Teams can now add Codex-only seats with pay-as-you-go pricing (meaning you only pay for what you use based on tokens, the small units of text the AI processes) instead of paying a fixed fee per person, and ChatGPT Business pricing has been lowered from $25 to $20 per seat annually. The company is also offering $100 in credits per new Codex-only user (up to $500 per team) to help teams try out the tool.

OpenAI Blog
07

Cybersecurity in the age of instant software

securitysafety
Apr 2, 2026

AI is making software development faster and easier, creating a future where custom applications can be written and deleted on demand, but this also means AI tools are getting better at finding and exploiting vulnerabilities in code. Both attackers and defenders are using AI for cybersecurity, creating an 'arms race' where attackers can automatically discover and exploit flaws while defenders can use similar AI tools to find and patch vulnerabilities before attackers exploit them.

CSO Online
08

Variance Raises $21.5M for Compliance Investigation Platform Powered by AI Agents

industry
Apr 2, 2026

Variance, a company building a compliance investigation platform that uses AI agents (autonomous AI systems that can perform tasks independently), has raised $21.5 million in new funding, bringing its total funding to $26 million. The funding will be used to grow the platform's capabilities.

SecurityWeek
09

Tools, um MCP-Server abzusichern

security
Apr 2, 2026

Model Context Protocol (MCP, a system that connects AI agents to data sources) has become popular in businesses but faces security risks like prompt injection (tricking an AI by hiding instructions in its input), token theft, and data leaks. While progress has been made with features like OAuth support and an official MCP Registry, companies need tools to implement proper access controls, authorization checks, and detailed logging to protect sensitive data.

CSO Online
10

GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

security
Apr 1, 2026

The lodash library has a code injection vulnerability in its `_.template` function (a tool that generates reusable text templates with dynamic values). Attackers can inject malicious code through the `options.imports` parameter, either by passing untrusted input as key names or by exploiting prototype pollution (a technique where attackers modify the default object properties that all objects inherit from). This allows arbitrary code to run when a template is compiled.

Fix: Users should upgrade to lodash version 4.18.0. The fix validates import key names using the same security checks applied to the `variable` option, and it changes how imports are merged to prevent inherited properties from being included.

GitHub Advisory Database
Prev1...8990919293...371Next