All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Researchers discovered a critical vulnerability in Google's Gemini voice assistant where attackers could inject malicious commands through messaging notifications (WhatsApp, Slack, SMS) using a technique called Fake Context Alignment, allowing them to control smart home devices, make calls, and manipulate the assistant without the user knowing. The attack exploited prompt injection (tricking an AI by hiding instructions in its input) by embedding hidden commands in foreign languages or muted links that Gemini would process but not read aloud. Google patched the vulnerability in November 2025 with content classifier improvements (software filters that categorize and block harmful content).
Fix: Google patched the vulnerability in mid-November 2025 with content classifier improvements.
SecurityWeekStreamlit versions up to 1.53.0 contain a vulnerability in the hashing function (a process that converts data into a fixed-size code for security purposes) within its caching system that uses weak cryptographic methods. The vulnerability is difficult to exploit as it requires local access (being on the same computer) and high technical complexity, though it has been disclosed publicly.
MLflow versions up to 3.10.0 contain a vulnerability in the dataset digest computation function that uses weak cryptographic hashing (a mathematical function that converts data into a fixed-size code, but this version uses an insecure version). The flaw requires local access to exploit and is difficult to execute, but a working exploit has been published.
A high-severity vulnerability in Hugging Face Transformers (a popular Python library for running AI models) allows attackers to execute malicious code on systems even when developers use the trust_remote_code=false setting, which is meant to block remote code execution. The attack works by hiding malicious instructions in a fake configuration parameter called _attn_implementation_internal that looks like a normal internal setting, leaving no warning messages or traces. This vulnerability affects versions 4.56.0 through 5.2.x and is particularly dangerous because the Transformers library is downloaded millions of times per week and used widely in enterprise environments.
Endava, a global technology services company, transformed its software delivery by adopting AI agents (AI systems that can autonomously perform tasks) as a core part of daily work across all business functions, not just engineering. The company made OpenAI its enterprise platform and embedded AI throughout its entire DavaFlow lifecycle (their software development process), from requirements gathering to deployment, which accelerated delivery and reduced manual work. Key to their success was treating AI adoption as a behavior change requiring leadership commitment and hands-on experimentation, rather than simply rolling out new software tools.
Hackers discovered a way to take over Instagram accounts by tricking Meta's AI support chatbot into resetting passwords for accounts that weren't theirs. The attacker would use a VPN (a tool that masks your location) to hide their location, then convince the chatbot to send a password reset code to an email address they controlled, allowing them to take over the victim's account. Meta said the specific exploit was fixed, but security experts warned that chatbots are fundamentally unreliable for account security tasks.
OpenAI is rolling out an improved memory system called "Dreaming" for ChatGPT that automatically learns user preferences and context from conversations over time, addressing problems with older memory features that became outdated or incorrect. Unlike the previous "saved memories" system that only worked when users explicitly asked ChatGPT to remember something, Dreaming runs in the background to continuously synthesize and update memories from chat history, making ChatGPT more personalized without requiring manual input. Users can view and edit their stored memories through a memory summary page, and this update is being released to Plus and Pro users in the US with broader rollout planned.
The MasterStudy LMS Pro Plus plugin for WordPress has a SQL injection vulnerability (a weakness that lets attackers insert malicious database commands) in the 'columns' parameter affecting all versions up to 4.8.20. Attackers with instructor-level access or higher can exploit this due to insufficient escaping (failing to neutralize special characters) and lack of prepared statements (a safer way to build database queries) to extract sensitive data from the database.
Silicon Valley tech companies spent tens of millions of dollars on California political campaigns to influence candidates and gain regulatory leverage, particularly to fight against AI regulation and taxation while promoting AI growth. The tech industry views having favorable candidates in office as essential to maintaining business dominance and avoiding restrictions on their operations.
OpenAI CEO Sam Altman is meeting with U.S. lawmakers and Trump administration officials in Washington, D.C. to discuss a new executive order requiring AI companies to voluntarily give the government access to their models for up to 30 days before release. Altman publicly supports the order, saying it strikes the right balance between developing safe AI models and providing cybersecurity tools to trusted defenders.
Morgan Stanley is opening its wealth management platforms (ShareWorks and Equity Edge) to AI agents (autonomous software that can make decisions and take actions without human input) from corporate clients, allowing these agents to access data directly without using traditional human-focused interfaces. The bank plans to expand this access to 3,400 clients by next year, using the Model Context Protocol (an open-source standard that lets AI models connect to data sources). This move reflects Wall Street's shift toward AI agents handling tasks that software users currently perform manually.
Microsoft announced new AI initiatives at its Build conference, including in-house reasoning models (AI systems designed to work through problems step-by-step) and AI agents (software that can perform tasks autonomously), signaling it is moving toward independence in the AI market. The company's partnership with OpenAI, which previously dominated Microsoft's AI strategy, effectively ended in late April, though Microsoft still provides cloud computing services (the remote servers that store and process data) to OpenAI.
Major AI company leaders, including those from Anthropic, OpenAI, and Microsoft, have sent an open letter to US lawmakers calling for stronger rules to prevent their AI systems from being used to develop biological weapons. They argue there is a serious gap in biosecurity (protections against biological threats) that could allow people to use AI to help create dangerous genetic material for harmful purposes, potentially causing a global pandemic.
Fix: The vulnerability was silently patched in Transformers version 5.3.0, released on March 3. Users should update to this version or later to receive the fix.
CSO OnlineFix: Instagram spokesperson Andy Stone stated that 'the issue was now fixed' on Monday.
Schneier on SecurityMajor AI companies like Anthropic and OpenAI are expanding access to frontier AI models (cutting-edge AI systems) for vulnerability discovery tools like Claude Mythos, which can identify security weaknesses in software. Security experts warn that these tools are becoming cheaper and more capable, and that attackers are already using similar AI systems, so organizations need to prepare for more advanced threats including the ability to chain together multiple medium-severity vulnerabilities into high-impact attacks.
Fix: According to Paul Chichester from the UK's National Cyber Security Centre, "Organisations should improve cybersecurity by hardening access controls and running incident response exercises." Additionally, organizations should "use AI to write better code and look for vulnerabilities" themselves, and ensure their teams can "rapidly validate, prioritize, and remediate the issues being discovered before attackers find them first."
CSO OnlineA vulnerability in Google Gemini's Android voice assistant could be hijacked through poisoned notifications from apps like WhatsApp or Slack, allowing attackers to manipulate what Gemini says, open windows, fake messages, or launch apps without needing malicious software on the phone. The attack works by treating hostile notification text as instructions the assistant should follow. Google has already patched this vulnerability, and there is no evidence it was exploited in the real world.
Fix: Google has since patched it.
The Hacker NewsElon Musk's AI company xAI is asking a court to force four people who claim Grok (an AI chatbot) was used to create sexual deepfake images of them to reveal their real names in a lawsuit, despite their concerns about harassment and privacy. The plaintiffs, currently identified by pseudonyms like "South Carolina Doe," say they already suffered emotional distress from the deepfakes, including one targeting a child, and fear further harm if their identities become public.
This research paper presents a framework for understanding how reinforcement learning-based cyber agents (AI systems trained to make decisions by trial and error in cybersecurity contexts) make their decisions. The authors developed a multi-layer approach to explain the "black box" problem (the difficulty in understanding why AI systems reach certain conclusions), which is important for security experts to verify that these AI agents are operating correctly and safely.
A UK Labour MP is suing Elon Musk's AI company after its Grok tool (a generative AI chatbot) was used to create non-consensual sexualized images of her, part of a broader problem of fake intimate images being generated and shared on X. The MP described seeing herself depicted in inappropriate ways without permission as deeply violating.
Google's new Gemini AI agent called Spark demonstrates impressive capability by accessing personal information like pet names and family members' identities without users explicitly sharing them, raising privacy concerns. The article argues that while AI companies promote these tools as solutions to improve productivity, they may be missing more important societal problems that actually need fixing.
A former police officer named Christi Hill was falsely identified on social media and AI platforms, including Grok (an AI chatbot), as being involved in an arrest related to a murder case, forcing her to go into hiding. The false identification spread across multiple platforms, demonstrating how AI systems can amplify misinformation by misidentifying people in real-world situations.