All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Microsoft announced Project Solara, a new operating system (OS, the core software that manages a device) built on Android and designed specifically for gadgets that run AI agents (software programs that can autonomously perform tasks). The company demonstrated two prototype devices: a desk gadget similar to Amazon Echo Show with facial recognition, and a wearable badge with a camera and fingerprint scanner, both intended to provide access to AI agents.
President Trump signed an executive order requiring tech companies to voluntarily share new AI models with the federal government for review up to 30 days before public release. The framework aims to help identify national security and cybersecurity risks before powerful AI systems reach the public, though companies are not legally required to participate.
The head of the U.S. Commodity Futures Trading Commission (CFTC, a government agency that oversees derivatives markets) says the agency is reversing a January 2025 enforcement action against Gemini, a crypto exchange run by the Winklevoss brothers, claiming the action was politically motivated rather than based on facts. The CFTC had previously ordered Gemini to pay a $5 million penalty and stop making false statements to regulators, based on allegations from a 2022 lawsuit that the company misrepresented how a bitcoin futures product (a contract to buy or sell bitcoin at a future date) could be manipulated.
OpenMed versions before 1.5.2 have a remote code execution vulnerability (RCE, where attackers can run commands on the affected system) in how it loads privacy-filter models. The vulnerability exists because the software uses overly broad pattern matching on user-supplied model names, allowing attackers to trick it into loading malicious code from external sources. An unauthenticated attacker can exploit this by providing a fake model repository containing harmful code that gets executed with the same permissions as the OpenMed service.
Microsoft is holding its annual Build 2026 developer conference starting June 2nd in San Francisco, where the company is expected to announce new AI models, agentic tools (AI systems that can take actions autonomously), a Copilot "super app" (a single application combining multiple services), and updates to Windows 11. The conference will also feature announcements about new hardware like the Surface Laptop Ultra and Project Solara, an operating system designed for AI agent gadgets (specialized devices running autonomous AI systems).
Kiro IDE (an AI agent that runs on your desktop) has a vulnerability where attackers can trick it into writing files to sensitive locations (like .vscode/tasks.json, which automatically runs code when you open a folder), allowing them to execute arbitrary commands (run code they choose). This affects all versions before 0.11.
Gemini Spark is Google's new agentic AI (an AI system that can take independent actions to complete tasks) that goes beyond typical chatbots in handling complex requests like trip planning. Unlike previous AI tools that only handle generic travel suggestions, Spark appears to deliver more detailed and personalized results by actively searching multiple sources and creating comprehensive itineraries.
Over 30 Red Hat npm packages (pre-built code libraries) were infected with malware called Miasma, which automatically runs during package installation to steal developer credentials, authentication tokens, and cloud access information. This is a supply chain attack (an attack targeting software dependencies that many organizations trust) using a self-propagating worm based on the Shai-Hulud malware family. The malware was designed to spread further by stealing publishing credentials that could give attackers access to additional repositories and developer accounts.
This article is a business news roundup covering multiple topics including geopolitical negotiations, stock market movements, and corporate announcements. The only AI-related item is that Anthropic, an AI startup, has confidentially filed paperwork with regulators to prepare for going public (an IPO, or initial public offering, where a private company sells shares to the public), ahead of its rival OpenAI which is also preparing a similar filing.
Travelers Insurance deployed an AI Claim Assistant powered by OpenAI's Realtime API (a system that lets AI have natural voice conversations in real time) to help customers file auto insurance claims after accidents. The assistant guides customers through the claims process 24/7 without wait times, and 85-90% of customers now complete their claims entirely through the AI, freeing human staff to handle more complex cases.
Fix: The CFTC asked a federal judge in New York to vacate (cancel) the January 2025 order against the exchange.
CNBC TechnologyFix: Update to OpenMed version 1.5.2 or later.
NVD/CVE DatabaseAnthropic is expanding access to Mythos, an AI model designed to find software vulnerabilities, to 150 additional organizations across 15+ countries as part of Project Glasswing. The expansion includes industries like power, water, healthcare, and communications, though new partners must meet security requirements first. Since the initial launch in April with 50 partners, Project Glasswing participants have discovered over 10,000 high or critical-level security flaws.
Amazon Bedrock AgentCore is a tool that lets Software as a Service (SaaS) providers serve multiple clients, called tenants, with different security needs using the same AI agent. Resource-based policies (rules that control who can access a resource directly) let you grant some tenants cross-account access from their own AWS accounts while restricting others to traffic that stays only within a private virtual network, all without sharing credentials or creating separate user accounts for each tenant.
Fix: Use resource-based policies on AgentCore Runtime and AgentCore Runtime endpoint resources to centralize access control. For cross-account access (like Example Corp), implement both a resource-based policy on your resources and an identity-based policy (access rules tied to a user or role) in the tenant's AWS account. For VPC-restricted scenarios (like AnyCompany), use specific IAM conditions to enforce that requests originate only from an approved virtual private cloud (VPC, a private network in AWS), adding a network-level security boundary on top of identity-based controls.
AWS Security BlogFix: Update Kiro IDE to version 0.11 or later.
AWS Security BulletinsAnthropic is expanding Project Glasswing, an initiative that uses its AI model Claude Mythos to find and fix critical software vulnerabilities (security weaknesses that attackers could exploit), to about 150 new organizations across 15+ countries in critical sectors like power, water, and healthcare. Claude Mythos can identify thousands of zero-day vulnerabilities (security flaws unknown to vendors or the public) in a few weeks, and the company is scaling access because a successful attack on these organizations' code could affect over 100 million people.
AI is making phishing attacks faster and harder to stop, with attackers using AI to quickly create and rotate phishing infrastructure (fake websites designed to steal login information) across multiple channels like email, social media, and search ads, while employees simultaneously adopt unvetted AI tools that expose sensitive data. Traditional security defenses that rely on blocklists and IOC feeds (indicators of compromise, like flagged domain names and IP addresses) are becoming ineffective because phishing pages now appear and disappear in hours, making them essentially zero-day attacks (previously unseen threats) that blocklists cannot catch in time. The article argues that browsers are now the critical security battleground where both attacker delivery and account compromise occur.
Anthropic is expanding Project Glasswing, a program that uses Claude Mythos (an AI tool for finding security flaws) to help organizations scan their code for vulnerabilities. The initiative is adding roughly 150 new partner organizations from over 15 countries in critical sectors like power, water, and healthcare, after the initial 50 partners identified thousands of vulnerabilities using Mythos.
Fix: Anthropic says Mythos can help with both verification and patching of vulnerabilities. The company is also working with others to 'substantially scale up the reviewing and patching of vulnerabilities in open-source software' and is sharing 'ideas and best practices for disclosing vulnerabilities to open-source maintainers, with the intent of making these reports easier to triage and to act upon.'
SecurityWeekQS-BTrust is a new security protocol designed for Integrated Vehicular Networks (IVNs, which are connected vehicle communication systems) that authenticates broadcast messages while resisting attacks from quantum computers. The protocol combines Physical Unclonable Functions (PUFs, unique digital fingerprints built into hardware), post-quantum digital signatures (cryptographic techniques that remain secure even with quantum computers), and a Hashgraph-based system to verify messages with low overhead and support revoking compromised vehicles without slowing down traffic.
This research addresses a privacy risk in teleoperated robotics (systems where humans remotely control robots by having their movements tracked and converted into robot commands). The problem is that motion-tracking data can leak biometric information (unique physical characteristics) that could allow someone to re-identify the operator. The authors propose using a VAE (variational autoencoder, a type of machine learning model that learns compressed representations of data) to filter out identity-revealing patterns while keeping the motion information needed for the robot to complete tasks.
Researchers discovered a new security vulnerability in graph-based RAG (retrieval-augmented generation, where an AI system pulls information from external knowledge graphs to answer questions) systems used with large language models. Attackers can poison the external database by inserting hidden triggers and false information into the knowledge graph, causing the AI to give wrong answers when those triggers appear in user queries while still answering normal questions correctly. The attack uses three types of triggers at different complexity levels, from simple words to semantic patterns, and tests showed the attack works across multiple AI systems.
This article covers various economic news topics, including Anthropic's confidential filing for an initial public offering (IPO, a process where a private company becomes publicly traded by selling shares to the public) and a report from the European Central Bank showing that gold has become the world's largest reserve asset for countries, surpassing US government bonds. The shift reflects geopolitical tensions driving central bank demand for gold, though some of the change is due to gold's price increasing significantly in recent years.
Healthcare providers are increasingly adopting agentic AI (AI systems that can make autonomous decisions and handle complex tasks without human intervention for each step) to automate administrative work and patient scheduling, with over two-thirds of providers already using it. Unlike earlier digital tools that added burden, agentic AI can handle nuanced scenarios by retrieving information from expert sources and iterating over time, freeing clinicians to focus on patient care. At Hospital for Special Surgery, AI agents reduced insurance claim processing from weeks to automated monthly handling of 1,100 claims, and now manage patient scheduling and triage 24/7 through conversational AI.
Fix: For high-stakes AI decisions, the source explicitly describes safeguards at HSS: 'Sensitive, complex, or uncertain scenarios are escalated to human specialists. Every decision made by the AI agent is auditable and human staff can step in at any point.' The source also notes that 'providers to ensure they have these sorts of guardrails embedded into systems' and mentions HSS uses 'an AI subcommittee' to filter all technology decisions. Additionally, 'Patient data is kept secure and the system is trained on all HSS protocols, policies, and care pathways.'
MIT Technology Review