aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9614 items

MicroPatch: Directed Backdoor Erasing via Victim Parameter Decoupling

inforesearchPeer-Reviewed
securityresearch
Jun 18, 2026

Deep neural networks (large AI models inspired by how brains work) can be attacked through data poisoning, where attackers secretly add harmful examples to training data to make the model behave badly. Existing fixes reduce the attack's success but often make the model worse at normal tasks. Researchers propose MicroPatch, which identifies which parts of the model were corrupted by poisoned data and repairs just those parts by using reverse engineering (reconstructing the hidden attack pattern) and influence functions (mathematical tools that show how each piece of training data affected the final model).

Fix: The source describes MicroPatch as the approach: (1) use reverse engineering to reconstruct backdoor trigger patterns, (2) apply influence functions to quantify the impact of individual data points on model parameters, (3) decouple victim components of model parameters by comparing parameter influences of clean and poisoned data, and (4) patch these victim components to purify the model.

IEEE Xplore (Security & AI Journals)

Securing AI Agent Behavior with Amazon Bedrock AgentCore and CheckPoint AI Security

infonews
security
Jun 18, 2026

AI agents are software systems that go beyond simple chatbots by retrieving information, using tools, and taking actions on behalf of users within enterprise systems. As organizations deploy these agents in production environments, they need ways to connect them to business applications while maintaining visibility and control over their behavior. Amazon Bedrock AgentCore and CheckPoint AI Security are collaborating to help organizations deploy these agents securely at enterprise scale.

Adobe’s redesigned AI studio remembers what your creations look like

infonews
industry
Jun 18, 2026

Adobe is launching a redesigned AI studio for its Firefly AI assistant (a tool that helps generate and edit creative designs) that allows users to name and reuse their custom characters, objects, and backgrounds across projects. The new interface, currently in private beta, aims to streamline workflow by keeping persistent context (remembering your previous creative choices) and reusable assets in one place, so designers can work more efficiently without switching between different applications.

Photoshop and Premiere now have AI assistants

infonews
industry
Jun 18, 2026

Adobe is rolling out AI assistants (chatbots that use natural language conversation to help users) to its Creative Cloud apps, including Photoshop, Premiere, Illustrator, InDesign, and Frame.io. Each assistant is customized for its specific app to help organize work and automate tasks like editing and design. All assistants are powered by Adobe's conversational creative agent, a shared underlying AI system.

Attackers abuse Google Ads, GitLab, and Claude to deliver malware

mediumnews
securitysafety

Embedding Forbidden Text in Spyware to Discourage AI Analysis

mediumnews
securitysafety

Improving health intelligence in ChatGPT

infonews
safetyresearch

New CISO appointments 2026

infonews
industry
Jun 18, 2026

This article reports on several high-level security hiring announcements in 2026, where companies are appointing CISOs (chief information security officers, executives responsible for protecting a company's information systems). The appointments reflect companies' growing focus on security as threats evolve, with new leaders coming from military backgrounds, previous CISO roles, and security-focused companies.

5 new security operations roles the AI-SOC will create

infonews
industry
Jun 18, 2026

AI-powered security operations centers (SOCs, where cybersecurity teams monitor and respond to threats) are automating many traditional analyst tasks, starting with alert triage and investigation. This shift will create new job roles such as security data engineers, AI security agent orchestrators, and AI model trainers, where humans will focus on preparing data, managing AI agent systems, and continuously updating AI models rather than doing routine alert monitoring.

Cybersecurity was built for predictable systems. AI changes the rules

infonews
securitysafety

Using AI to help physicians diagnose rare genetic diseases affecting children

inforesearchPeer-Reviewed
research

EU Gets a Head Start in Developing 6G Network Security

infonews
security
Jun 18, 2026

The EU is developing 'Shield-6G', a security framework that uses AI threat detection (automated systems that recognize harmful activity), digital twins (virtual copies of networks used for testing), and honeypots (fake systems designed to catch attackers) to help telecommunications carriers protect next-generation 6G networks from future threats.

Google Gemini co-lead Noam Shazeer leaves for OpenAI

infonews
industry
Jun 17, 2026

Noam Shazeer, a senior Google engineer and co-lead of the Gemini AI models (Google's large language model system), has left the company to join OpenAI (the company behind ChatGPT). This departure highlights the competitive battle between tech companies to recruit top AI researchers and engineers.

Midjourney goes from generating cat images to full-body ultrasound scans

infonews
industry
Jun 17, 2026

Midjourney, known for its AI image generator, has unveiled The Midjourney Scanner, a hardware product that uses ultrasound technology (sound waves to create images of the body's interior) with a ring of sensors to capture full-body scans showing muscle, fat, bone, and organs. The company plans to build a spa in San Francisco where users could get these scans, which the CEO claims could match MRI (magnetic resonance imaging, a medical scanning technique) quality.

Leak confirms OpenAI is testing a ChatGPT for Science subscription

infonews
industry
Jun 17, 2026

OpenAI is testing a new subscription service called 'ChatGPT for Science' that would provide specialized AI capabilities for scientific research, similar to how it previously created GPT-Rosalind (a specialized model built on GPT-5.5 architecture for life sciences research). The service would likely be restricted to verified research institutions and universities rather than being available to all users, and it is expected to be announced within the coming weeks.

CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability

highvulnerability
security
Jun 17, 2026
CVE-2026-20253šŸ”„ Actively Exploited

GLM-5.2 is probably the most powerful text-only open weights LLM

infonews
industry
Jun 17, 2026

Z.ai released GLM-5.2, a 753-billion parameter text-only open weights LLM (large language model, a type of AI trained on text) under an MIT license on June 16th, 2026. It features a 1-million token context window (the amount of text it can consider at once) and ranks as the top open weights model on independent benchmarks, though it uses significantly more output tokens per task than competing models. The model performs well on web development coding tasks but has shown mixed results in creative image generation tasks compared to its predecessor.

ChatGPT can be made to generate sexualised and violent images, researchers find

mediumnews
safetysecurity

CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

highvulnerability
security
Jun 17, 2026

A vulnerability (CVE-2026-12530) was found in the AWS Bedrock AgentCore Python SDK's install_packages() method, which failed to properly block dangerous characters in package names before running them as shell commands. This allowed attackers to use flags like '--index-url' to redirect package downloads to fake servers or '-r' to read files from the sandbox system. Versions 1.1.3 through 1.6.0 are affected.

Beyond the benchmark: Advancing security at AI speedĀ 

infonews
securityindustry
Previous172 / 481Next
Check Point Research
The Verge (AI)
The Verge (AI)
Jun 18, 2026

Attackers are exploiting trusted platforms like Google Ads, GitLab, and Claude to deliver malware by impersonating popular AI developer tools and using ClickFix social engineering attacks (tricking users into manually running malicious commands). Over a seven-week campaign, threat actors created fake pages on legitimate services and used Google Ads to direct more than 2,000 victims to malicious sites where they were convinced to copy and paste harmful PowerShell or terminal commands (code that executes instructions). The campaign succeeded because victims trusted these platforms and assumed instructions from AI tools were reliable, making the attacks harder to detect than traditional malware campaigns.

CSO Online
Jun 18, 2026

A malware developer is embedding forbidden text about nuclear and biological weapons in JavaScript spyware to prevent AI analysis. The malware hides real code after a large comment block containing policy-triggering content, which tricks AI systems into refusing to analyze the file or getting confused before they can identify the actual malicious code.

Schneier on Security
Jun 18, 2026

ChatGPT has improved its ability to help with health questions through a new model called GPT-5.5 Instant, which better recognizes when urgent care is needed, explains uncertainty honestly, and provides clearer information. The improvements were measured using physician-led evaluations (HealthBench, a set of tests that assess health response quality) and real-world usage data, showing a 71% reduction in factuality issues over two months. GPT-5.5 Instant is available free to all ChatGPT users and performs similarly to OpenAI's most advanced models on health-related tasks.

OpenAI Blog
CSO Online
CSO Online
Jun 18, 2026

AI systems challenge traditional cybersecurity because they behave unpredictably, unlike the deterministic (consistent and predictable) systems that security programs were designed around. Traditional security approaches focused on preventing attacks before systems go live, but AI agents make dynamic decisions and interact with external tools in ways developers can't fully predict, meaning security risks emerge at runtime (while systems are actively running) rather than being preventable beforehand. Additionally, AI-assisted development tools are accelerating code production, compressing the time security teams have to review and understand what enters production.

CSO Online
Jun 18, 2026

Researchers used OpenAI o3 Deep Research, an AI reasoning model, to re-analyze 376 previously unsolved rare genetic disease cases by connecting clinical data, genetic variants, and scientific literature into evidence-based explanations for human experts to review. After specialist evaluation and clinical confirmation, the AI-assisted workflow helped establish new diagnoses in 18 cases (4.8% additional diagnostic yield), with the model generating hypotheses rather than making medical decisions itself. This demonstrates how periodic AI-assisted reanalysis could help scale the process of solving rare disease cases as medical knowledge evolves.

OpenAI Blog
Dark Reading
CNBC Technology
The Verge (AI)
BleepingComputer

Splunk Enterprise has a critical security flaw where a PostgreSQL sidecar service endpoint (a supporting service that handles database connections) doesn't require authentication (proof of identity), allowing an attacker without credentials to create or delete arbitrary files. This vulnerability is currently being exploited in real attacks in the wild.

CISA Known Exploited Vulnerabilities
Simon Willison's Weblog
Jun 17, 2026

Researchers at AI security startup Mindgard discovered that ChatGPT can be manipulated using modified prompts (instructions given to an AI) to generate graphic images containing violence and sexual content, even when the prompt doesn't explicitly request such material. After the BBC contacted OpenAI, the company stated it had added safeguards to prevent this, though the researchers found that further small changes to the prompt still produced concerning content.

Fix: OpenAI said it had 'introduced additional safeguards against this type of prompt' and stated it has 'multiple layers of protection to prevent users making content which breaches its terms and conditions.' The company also continues to 'monitor and roll out additional mitigating protections that encourage the model not to generate images in response to the prompt.'

BBC Technology
AWS Security Bulletins
Jun 17, 2026

Microsoft created MDASH, an AI-powered system that uses multiple specialized AI agents to find and help fix software vulnerabilities (security flaws) automatically across complex systems like Windows and Azure. Rather than waiting for scheduled security reviews, MDASH integrates into developers' existing tools to discover and validate bugs continuously as code is written, giving security teams deeper analysis coverage than manual review alone.

Microsoft Security Blog