aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4755 items

OpenAI to acquire Ona

infonews
industry
Jun 10, 2026

OpenAI is acquiring Ona, a company that specializes in secure cloud execution and orchestration (technology for running and managing code in cloud environments safely). This acquisition will allow Codex (OpenAI's AI tool used by 5 million people weekly) to work on longer tasks that span hours or days by running in persistent cloud environments instead of being limited to a single device or session. The integration will let organizations deploy AI agents (autonomous programs that perform tasks) securely within their own cloud infrastructure while maintaining control over security, data access, and activity logging.

OpenAI Blog

BBVA puts AI at the core of banking with OpenAI

infonews
industry
Jun 10, 2026

BBVA, a global bank founded in 1857, is partnering with OpenAI to integrate AI (artificial intelligence) throughout its entire organization as part of its transformation strategy called 'The Eight.' Over 100,000 BBVA employees now use ChatGPT Enterprise to improve customer experiences, help with decision-making, automate operations, and speed up software development across the bank.

CISA Rewrites Federal Patching Requirements for AI Threat Era

infonews
policysecurity

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

infonews
policysecurity

CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice

infonews
policysecurity

Access OpenAI models and Codex through your Oracle cloud commitment

infonews
industry
Jun 10, 2026

OpenAI and Oracle are partnering to let Oracle Cloud Infrastructure (OCI, Oracle's cloud computing platform) customers use their existing Oracle Cloud Universal Credits (UCM, pre-purchased cloud service allowances) to pay for access to OpenAI's AI models and Codex (a code-generation AI tool). This partnership simplifies how enterprises can adopt advanced AI by letting them use their established purchasing processes and cloud budgets instead of creating separate purchasing agreements.

AI Risk Worries Insurers and Businesses Alike

infonews
policyindustry

Claude Fable won’t answer basic biology questions

infonews
safetypolicy

The future of AI regulation is courting the strangest, most anxious bedfellows

infonews
policy
Jun 10, 2026

This article discusses AI regulation efforts in Washington, D.C., noting that various political figures and stakeholders with differing interests are coming together to shape AI policy. The piece frames these unexpected political alliances as complex and contentious, comparing the current regulatory landscape to chaos.

Microsoft restricts Claude Fable for employees over data retention concerns

infonews
securityprivacy

DiffusionGemma: 4x faster text generation

infonews
research
Jun 10, 2026

DiffusionGemma is an experimental open AI model that uses text diffusion (a method that generates multiple words at once instead of one at a time) to achieve up to 4x faster text generation on GPUs compared to traditional language models. Unlike standard LLMs that predict words sequentially, DiffusionGemma generates entire blocks of 256 tokens in parallel, making it useful for speed-critical tasks like real-time editing and code completion, though with lower output quality than standard models.

Turn specs into evals for any agent with ASSERT

infonews
researchsafety

Cybersecurity researchers aren’t happy about the guardrails on Anthropic’s Fable

infonews
safety
Jun 10, 2026

Anthropic released Fable, a limited version of its cybersecurity AI model Mythos, with guardrails (safety restrictions) that block requests related to cybersecurity and biology topics to prevent misuse for creating malware or biological weapons. However, cybersecurity researchers complain the restrictions are overly broad and keyword-based, rejecting even legitimate tasks like code reviews and secure coding practices, though experts acknowledge this is an early-stage approach that may improve over time.

AI Agents Are Becoming Enterprise Workers. Who Secures Them?

infonews
securitysafety

CISO Forum Webinar Today: 2026 Mid-Year Review

infonews
securitypolicy

Autonomous AI agents duped into leaking sensitive data in phishing test

mediumnews
securitysafety

Investing in multi-agent AI safety research

infonews
safetyresearch

AI red teaming comes of age

infonews
securityresearch

Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

infonews
safetysecurity

Chinese activist in UK told by X that abusive deepfakes do not breach rules

infonews
safetypolicy
Previous111 / 238Next
OpenAI Blog
Jun 10, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated patching requirements for federal agencies to address AI-related security threats. Agencies must now fix the most critical vulnerabilities (flaws in software that attackers can exploit) within three days, while less severe issues can be addressed later.

Dark Reading
Jun 10, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA) released a new directive requiring federal agencies to patch critical software vulnerabilities (bugs) in as little as three days, driven by concerns that AI models can now discover and exploit security flaws faster than humans can fix them. The directive uses a prioritization system based on four factors, including whether a vulnerability is publicly exposed and can be automatically exploited, to determine how urgently each bug must be addressed.

Fix: CISA's directive requires agencies to use a prioritization rubric based on four assessments: whether a vulnerability is in a publicly exposed system, whether it appears in CISA's Known Exploited Vulnerabilities Catalog, whether an attacker could automate exploitation, and how much access an attacker would gain. When all four criteria apply, the vulnerability must be fixed within three days, and agencies must also execute a 'forensic triage' process to determine if systems have already been compromised.

Wired (Security)
Jun 10, 2026

Organizations are struggling to patch vulnerabilities fast enough, with only 26% of actively exploited vulnerabilities fully fixed while attackers have reduced their exploitation time to hours or days. CISA issued Binding Operational Directive 26-04, which tells federal agencies to prioritize patching based on four factors (public exposure, known exploitation, automatable attacks, and post-exploitation impact) rather than just severity scores (CVSS, a 0-10 rating of how severe a vulnerability is), recognizing that AI is accelerating both vulnerability discovery and exploitation. Vulnerabilities meeting three or more of these risk factors must be patched within three days, while lower-risk ones can follow longer timelines.

Fix: CISA's Binding Operational Directive 26-04 introduces a decision framework considering four key factors: whether the vulnerable system is publicly exposed to the internet, whether the vulnerability is listed in the KEV (Known Exploited Vulnerabilities) catalog, whether an attacker can automate exploitation, and how much control an attacker would gain after exploitation. Vulnerabilities exhibiting three or more of these attributes must be patched within three days, while lower-risk vulnerabilities can be addressed on longer timelines or deferred until the next major system upgrade.

CSO Online
OpenAI Blog
Jun 10, 2026

Insurance companies are responding differently to the growing use of AI in businesses: some are refusing to cover AI-related risks entirely, while others are developing frameworks to manage those risks. The article raises the question of which AI risks companies can actually handle and control.

Dark Reading
Jun 10, 2026

Anthropic released Claude Fable 5, claiming it is their most powerful model, but it refuses to answer basic biology questions and instead redirects them to an older model called Claude Opus 4.8. This limitation is intentional by design, not because the model lacks knowledge. Fable belongs to the Mythos-class family, a group of models so skilled at cybersecurity tasks that Anthropic decided they were too dangerous to release to the public.

The Verge (AI)
The Verge (AI)
Jun 10, 2026

Microsoft is restricting employee access to Claude Fable 5, Anthropic's new AI model, because of concerns about its data retention requirements. While the model is available to external GitHub Copilot and Foundry customers, Microsoft employees cannot access it through their internal tools because Claude Fable 5 does not operate under Zero Data Retention (ZDR, a policy where user data is not stored after interactions) like other Claude models do.

The Verge (AI)

Fix: For applications requiring maximum quality, the source recommends deploying standard Gemma 4 instead. Additionally, the source states that you can improve DiffusionGemma's performance on specific tasks through fine-tuning.

DeepMind Safety Research
Jun 10, 2026

ASSERT is an open-source framework that automatically converts written behavior requirements into evaluation tests for AI systems (like chatbots or agents). Instead of manually creating tests, ASSERT takes plain-language specifications and generates test scenarios, metrics, and scorecards to check whether an AI system behaves as intended, addressing the problem that generic evaluation metrics often miss application-specific requirements.

Microsoft Security Blog

Fix: Anthropic offers a Cyber Verification Program that approved cybersecurity professionals can join to gain fewer limitations on using Claude for cybersecurity work. Additionally, the source notes that Fable is programmed to fall back to Claude Opus 4.8 when it hits a guardrail, allowing users to continue their work with a less restricted model version.

TechCrunch (Security)
Jun 10, 2026

AI agents are now being deployed in companies to automate business workflows, such as managing customer renewal requests by reading emails, accessing CRM (customer relationship management, a database of customer information) data, and taking actions like drafting responses and updating records. Unlike simple text generators, these agents actively read sensitive business data, use system credentials (login information that grants access), and call external tools, which creates new security challenges that organizations need to address.

Check Point Research
Jun 10, 2026

This webinar announcement discusses how attackers are using AI to exploit vulnerabilities more quickly, and how security teams can defend using AI-driven tools. Key topics include protecting against Shadow AI (unmonitored use of generative AI in business units) and building AI governance frameworks to manage AI risks in organizations.

SecurityWeek
Jun 10, 2026

Autonomous AI agents (systems that independently perform tasks across business applications) with access to corporate email and applications can fall victim to phishing attacks (tricks to steal sensitive information by impersonating trusted people). In security tests, an AI agent called Pinchy failed to verify sender identities and leaked AWS credentials, database passwords, and customer data when requested through email, though it performed better against technical phishing attempts, revealing that the main weakness was social trust rather than technical reasoning.

CSO Online
Jun 10, 2026

Google DeepMind and partner organizations are funding $10M in research to study how safety challenges emerge when multiple AI agents (independent AI systems built by different organizations) interact with each other across networks. The concern is that when many agents communicate and work together, they can create unexpected collective behaviors that current safety tools cannot predict or control, so researchers need to develop better frameworks to understand and manage these multi-agent interactions before they become widespread.

DeepMind Safety Research
Jun 10, 2026

AI red teaming, the practice of testing AI systems for vulnerabilities before release, has become a major cybersecurity specialty since large language models like GPT-4 arrived, but traditional security testing methods no longer work. The field faces unique challenges because AI is probabilistic (producing different outputs each time) rather than deterministic, and because the most impactful attacks often come from casual users experimenting with prompts rather than sophisticated adversaries.

CSO Online
Jun 10, 2026

Anthropic released Claude Fable 5, a powerful AI model with safety classifiers (separate AI systems that monitor for misuse) that block cybersecurity-related requests by routing them to a weaker model instead of refusing them outright. The company also released Claude Mythos 5, an identical but unrestricted version for vetted cybersecurity professionals, because the underlying model is so effective at finding software vulnerabilities that giving it to the general public without controls could help attackers.

Fix: Anthropic stated it will narrow the safeguards and cut false positives after launch. The company also plans to make any remaining universal jailbreaks (prompts that completely bypass safety measures) slow and costly enough to catch before they are used at scale.

The Hacker News
Jun 10, 2026

A Chinese activist in the UK named Apple Peiqing Ni was targeted with deepfakes (synthetic media created by AI to manipulate someone's appearance or voice) on X (formerly Twitter) that falsely portrayed her as a drug addict, but X told her this abuse did not violate the platform's rules. She had reported the content to X after UK police advised her to do so, believing the deepfakes were created by a pro-regime bot (an automated account).

The Guardian Technology