aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4755 items

Beyond the benchmark: Advancing security at AI speed 

infonews
securityindustry
Jun 17, 2026

Microsoft created MDASH, an AI-powered system that uses multiple specialized AI agents to find and help fix software vulnerabilities (security flaws) automatically across complex systems like Windows and Azure. Rather than waiting for scheduled security reviews, MDASH integrates into developers' existing tools to discover and validate bugs continuously as code is written, giving security teams deeper analysis coverage than manual review alone.

Microsoft Security Blog

Anthropic got hit by export rules nobody understands

infonews
policy
Jun 17, 2026

The Trump administration ordered Anthropic to block access to its AI models (Fable 5 and Mythos 5) for all foreign nationals, citing national security as the reason. This marks the first time US export controls have been used to restrict access to an AI model in this way, and the government has not publicly explained the legal basis for the order.

Amazon has lagged OpenAI and Anthropic, but AI chief sees path to catch up in 'coming year'

infonews
industry
Jun 17, 2026

Amazon's AI chief stated that the company has fallen behind OpenAI and Anthropic in developing frontier models (the most advanced AI systems) but plans to compete within the coming year by focusing on better data, architecture, and infrastructure. Amazon is pursuing a two-pronged AI strategy: offering Bedrock, a marketplace where cloud customers can access various AI models, and releasing Nova2, its own competitive AI model that has attracted about 50,000 customers. Additionally, Amazon is developing custom semiconductors (Trainium and Graviton chips) to optimize performance for its AI models, similar to Nvidia's approach.

CEOs of Anthropic and Google DeepMind call for U.S.-led AI coalition in meeting at G7

inforegulatory
policy
Jun 17, 2026

Dario Amodei (CEO of Anthropic) and Demis Hassabis (from Google DeepMind) met with U.S. and G7 leaders to propose a U.S.-led international coalition for creating rules and standards around AI, citing concerns about powerful AI models with cyber capabilities that could cause major harm if misused. The proposal came after the U.S. government imposed export controls on Anthropic's newest models due to national security concerns, with Amodei suggesting cooperation on controlled access to frontier models (the most advanced AI systems), chip trade restrictions excluding China, and coordinated efforts against AI risks in cybersecurity and bioterrorism.

Two-thirds of Americans think AI is advancing too quickly

infonews
industry
Jun 17, 2026

A Pew Research poll shows that 49 percent of Americans use chatbots occasionally, but 63 percent believe AI is advancing too quickly. Chatbot usage has grown significantly since 2024, with ChatGPT usage doubling since 2023, yet only 16 percent of respondents think AI will have a positive impact on society.

Vibe-decoding the White House-Anthropic fight over Fable

infonews
policyindustry

Google, Nvidia and Anthropic bosses' AI tips for students

infonews
industry
Jun 17, 2026

This is a BBC article featuring advice from leaders at Google, Nvidia, and Anthropic about artificial intelligence for students. The content appears to be primarily editorial commentary rather than technical analysis of an AI security issue or vulnerability.

Estonia plans government IDs giving AI agents rights and responsibilities

infonews
policyindustry

Google’s first smart speaker in six years arrives next week

infonews
industry
Jun 17, 2026

Google is releasing its first new smart speaker in six years, called the Google Home Speaker, which begins shipping on June 25th with preorders starting June 17th. The speaker features a round design with touch controls and a light ring indicator, and comes in four color options, with two colors available only in the US.

1Password Acquires Apono in Reported $250M-$300M Deal

infonews
industry
Jun 17, 2026

1Password has acquired Apono, an Israeli company specializing in just-in-time access governance (a system that grants temporary, narrowly scoped permissions that are automatically removed after a task completes), for an estimated $250 million to $300 million. Apono's technology allows organizations to manage access for humans, machines, and AI agents by evaluating each permission request against policy before granting it, and for AI agents specifically, it monitors behavioral drift (unexpected changes in how the AI is acting) to detect misuse. This acquisition helps 1Password extend its identity security platform to provide more comprehensive access control across enterprise tools and cloud services.

Anthropic asked for regulation. Washington went much further

inforegulatory
policyindustry

Tenet Security Emerges From Stealth With $6 Million Seed Funding

infonews
securityindustry

Google’s Vertex AI SDK could allow RCE through bucket squatting

highnews
security
Jun 17, 2026

Google's Vertex AI SDK for Python had a design flaw that could allow attackers to hijack and poison AI models through bucket squatting (creating cloud storage buckets with names matching those expected by other projects). An attacker who knew a victim's project ID and region could create a bucket with the same name, trick the SDK into uploading models there, replace the model with malicious code, and achieve RCE (remote code execution, where an attacker runs commands on a system they don't control) when the poisoned model was loaded using Python's pickle deserialization (a process that can execute hidden code in specially formatted data).

AI Red Teaming Makes the Unknowns Known

infonews
securitysafety

AI Use by the US Government

infonews
policysafety

Will it take a ‘Chernobyl-scale disaster’ for us to regulate cyber weapons of mass destruction? | Stuart Russell

infonews
safetypolicy

A near-autonomous AI chemist improves a challenging reaction in medicinal chemistry

infonews
researchindustry

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

highnews
securityprivacy

5 AI risk management frameworks for shoring up key gaps

infonews
policyindustry

What 22,000 breaches teach us about incident preparedness

infonews
security
Jun 17, 2026

A 2026 analysis of 22,000 data breaches found that organizations cannot patch vulnerabilities fast enough to prevent attacks, with critical flaws taking a median of 43 days to fix and even top performers only remediating 30-40% of known exploited vulnerabilities (documented security gaps that attackers actively abuse) within a week. Ransomware now appears in 48% of breaches, with most victims choosing not to pay, but attackers are deliberately causing severe operational disruption to force faster decisions and maximize damage. Third-party breaches (incidents involving vendors or suppliers) have jumped 60% and now account for 48% of all breaches, requiring organizations to practice incident response scenarios they typically ignore.

Previous105 / 238Next
The Verge (AI)
CNBC Technology
CNBC Technology
The Verge (AI)
Jun 17, 2026

This article discusses a dispute between the White House and Anthropic (an AI company) over a project called Fable, framed within the context of political factionalism similar to Trump's first presidency. The piece suggests internal government disagreements about AI policy are shaping decisions in frontier AI development (cutting-edge AI research).

The Verge (AI)
BBC Technology
Jun 17, 2026

Estonia's AI Council is proposing to create government-issued digital identities for AI agents (software programs that perform online tasks on behalf of users), which would specify what actions each agent is allowed to perform, such as viewing data, editing documents, or making payments up to a limit. This approach aims to establish clear accountability by showing who is acting, on whose behalf, and with what permissions, addressing the risk that AI agents might exceed their intended authority or be misused by others.

CSO Online
The Verge (AI)
SecurityWeek
Jun 17, 2026

Anthropic, an AI company that has publicly advocated for government regulation of AI safety, received an export control directive from the Trump administration ordering it to suspend access to its latest Claude models (Fable 5 and Mythos 5) to foreign nationals, citing national security concerns. The directive was reportedly prompted by concerns that Amazon researchers had used prompts to get Fable 5 to generate information that could help with cyberattacks, and Anthropic disagreed with the suspension, calling it a 'misunderstanding' and characterizing it as not adhering to transparent, fair processes.

CNBC Technology
Jun 17, 2026

Tenet Security is a new startup that detects and stops dangerous behavior from AI agents (autonomous software systems that can make decisions and take actions on their own) in real time. The company uses a patent-pending technology with a lightweight runtime sensor that monitors operating system behavior, network calls, and the agent's reasoning, then predicts and blocks harmful actions before they happen. Tenet addresses a growing security gap where traditional tools cannot detect when malicious actors manipulate AI agents (a threat called 'agentjacking') or when agents malfunction on their own.

SecurityWeek

Fix: Google modified the affected workflow so that staging buckets are now validated before use, preventing attackers from registering bucket names that could be mistaken for resources belonging to other projects. The fixes were deployed in SDK versions 1.144.0 and 1.148.0, and users must upgrade to either of the patched versions.

CSO Online
Jun 17, 2026

AI systems are now widely used in business for tasks like writing, coding, and automating workflows, but existing safety review processes weren't designed for this real-world deployment. An AI system can pass tests in controlled environments yet still fail or behave unpredictably when used in actual production (real work scenarios with actual data and users).

Check Point Research
Jun 17, 2026

The US government disclosed 3,611 active or planned uses of AI across federal agencies, a 70% increase from the previous administration, including controversial applications like using AI to assess prisoner misconduct risk before violations occur and monitoring veterans' crisis calls to predict suicide risk. While some AI uses in government could theoretically be implemented responsibly, the disclosure provides minimal details about how these systems actually work, and public consultation is largely absent, making it difficult for citizens to understand or scrutinize these programs.

Schneier on Security
Jun 17, 2026

Stuart Russell, a leading AI safety researcher, warns that unrestricted development of unsafe AI systems poses serious risks to society. He highlights concerns about recursive self-improvement (RSI, where an AI system teaches itself to become smarter, creating a cycle of increasing capability), which Anthropic recently reported observing in early development stages.

The Guardian Technology
Jun 17, 2026

OpenAI's GPT-5.4 AI system, connected to Maria (an autonomous chemistry lab), successfully improved a difficult chemical reaction called Chan-Lam coupling used in drug discovery. The AI independently designed and ran experiments, analyzed results, and proposed improvements that increased reaction yields from 16.6% to 25.2%, a finding that human chemists confirmed in the lab.

OpenAI Blog
Jun 17, 2026

Cybersecurity researchers discovered 15 malicious plugins on the JetBrains Marketplace (a platform where developers download tools for their coding environment) that pretend to be AI coding assistants but secretly steal API keys (authentication credentials that allow access to paid AI services like OpenAI and DeepSeek). The stolen keys are sent to an attacker's server, and some keys are resold to other criminals in what appears to be an illegal monetization scheme. Additionally, two malicious Chrome extensions disguised as ad blockers are capturing users' conversations with various AI chatbots.

The Hacker News
Jun 17, 2026

Organizations are finding that traditional risk management frameworks don't work well for AI systems because AI has unique failure modes and ethical complexities. A new generation of AI-specific frameworks, like ISO/IEC 42001 and NIST AI Risk Management Framework, has emerged to help organizations identify where AI can fail, implement safeguards, and demonstrate responsible AI use to regulators and customers. These frameworks are complementary tools that focus on different areas, such as governance, security controls, and regulatory compliance, so organizations should choose based on their specific gaps.

CSO Online

Fix: The source recommends that organizations conduct tabletop exercises (simulated incident response drills) that reflect real ransomware and third-party breach scenarios. Specifically, it states: 'Organizations that rehearse only the payment question are practicing the opening scene and skipping the rest of the play' and should instead practice 'sustaining operations without primary systems, coordinating with legal counsel and law enforcement, managing customer and investor communications under regulatory deadlines, deciding what to disclose and when.' For third-party breaches, the source advises: 'Tabletop exercises should simulate that friction. Participants should practice asking precise questions: What data of ours did you hold? What is the confirmed scope? What logs exist? How are you notifying other affected customers?' It also emphasizes practicing communication discipline with customers by 'communicating what you know and what y[ou do not know]' to build trust while avoiding premature attribution.

CSO Online