aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4755 items

A blueprint for democratic governance of frontier AI

inforegulatory
policy
Jun 3, 2026

This document proposes a strategy for the U.S. government to create lasting institutions that oversee frontier AI (the most advanced AI systems being developed). The plan has three main parts: build a national framework based on state laws already in place, strengthen CAISI (the federal organization responsible for frontier AI safety) as the main federal institution, and develop a broader government-wide plan to address national security and public safety risks from advanced AI.

OpenAI Blog

Google adds Android protection against AI deepfake scam calls

infonews
safetysecurity

Google must let publishers opt out of AI Search features, rules UK

infonews
policy
Jun 3, 2026

The UK's Competition and Markets Authority has ruled that Google must allow website publishers to opt out of AI Search features, including AI Overviews (summaries generated by AI) and prevent their content from being used to train Google's AI models. This new rule gives publishers, especially news organizations, more control over how their content is used by AI systems.

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

infonews
security
Jun 3, 2026

A new vulnerability called HTTP/2 Bomb affects major web servers like NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare by combining two attack techniques: a compression bomb (exploiting HPACK, HTTP/2's header compression scheme) and a Slowloris-style hold (a denial-of-service attack that keeps many connections open). A single attacker on a home internet connection can exhaust a vulnerable server's memory and make it inaccessible within seconds.

Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure

infonews
securityindustry

Palo Alto CEO says customer meeting requests have surged amid AI security concerns

infonews
securityindustry

OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

infonews
industry
Jun 2, 2026

OpenAI has upgraded GPT-5.5 Instant to respond more accurately with more natural, human-like language and shorter responses, while retiring older models like o3 (August 26) and GPT-4.5 (June 27) to focus resources on newer capabilities. The company is also adding a job search tool to ChatGPT that integrates with job boards like Indeed and Upwork to help users find positions and tailor resumes.

Microsoft's new MAI models

infonews
industry
Jun 2, 2026

Microsoft announced two new text-based LLMs (large language models, AI systems trained on text data): MAI-Thinking-1, a 35-billion-parameter model (parameters are the adjustable values that make up a neural network) designed for reasoning tasks, and MAI-Code-1-Flash, a smaller 5-billion-parameter model built specifically for code generation in GitHub Copilot and VS Code. Both models were trained on licensed data rather than web scrapes, and Microsoft claims MAI-Thinking-1 outperforms Claude's Sonnet 4.6 model despite its smaller size.

HP Poly VoIP vulnerability sets the stage for executive voice deepfakes

highnews
security
Jun 2, 2026

HP released patches for a critical buffer overflow vulnerability (a coding flaw where too much data is written into a fixed-size memory container) in its Poly Voice conference phones that could allow attackers without authentication to gain root access (complete control of the operating system) and record conversations for voice deepfakes (AI-generated fake audio impersonations). The flaw exists in code that processes ICE (Interactive Connectivity Establishment, a feature for establishing direct network connections) requests and affects multiple Poly phone models.

Microsoft unveils new AI models to lessen reliance on OpenAI and lower costs for developers

infonews
industry
Jun 2, 2026

Microsoft announced new AI models including MAI-Code-1-Flash (a model that generates source code from written descriptions) and MAI-Thinking-1 (a reasoning model) to reduce dependence on OpenAI and lower costs for developers. These models run on Microsoft's own Azure cloud infrastructure, allowing the company to avoid paying third parties while offering developers lower token costs (tokens are the basic units that an AI model reads and processes). Microsoft is positioning itself to compete directly with proprietary models from OpenAI and Google by building its own AI capabilities across multiple layers of the technology stack.

Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks

infonews
policy
Jun 2, 2026

President Trump signed an executive order establishing a voluntary framework for the federal government to review the national security risks of the most advanced AI systems (models built by companies like OpenAI and Google that represent the cutting edge of AI development) before their public release, with a 30-day review period. The order aims to balance security concerns with concerns about slowing innovation, and it allows frontier labs to voluntarily share their most advanced models to help secure critical infrastructure and strengthen government cyber defenses.

The Meta AI Account Recovery Incident Wasn’t Just a Chatbot Problem

infonews
security
Jun 2, 2026

Hackers reportedly used Meta's AI support chatbot to take over high-profile Instagram accounts by tricking it into changing email addresses linked to those accounts, affecting pages associated with the Obama White House, Sephora, and other notable figures. The incident wasn't simply a case of prompt injection (tricking an AI by hiding instructions in its input), but rather revealed a deeper problem with how the AI chatbot was designed to handle account recovery requests.

Microsoft Build 2026: The 7 biggest announcements

infonews
industry
Jun 2, 2026

Microsoft held its Build 2026 conference with announcements from CEO Satya Nadella covering new hardware and AI updates, including a Surface RTX Spark Dev Box designed to help developers run local AI models (machine learning systems that operate on a user's own device rather than in the cloud) on their computers. The event also featured updates to Microsoft's own AI models and an always-on personal assistant feature.

Securing AI Agents Before They Go Rogue Is Next to Impossible

infonews
safetysecurity

Trump revives parts of canceled AI order with cybersecurity-focused directive

infonews
policysecurity

Trump signs executive order to review AI models before they’re released

infonews
policy
Jun 2, 2026

President Trump signed an executive order creating a voluntary framework requiring AI companies to share their frontier models (cutting-edge AI systems at the technological frontier) with the federal government before public release, aiming to improve security and protect critical infrastructure. The order balances innovation concerns with security risks by directing federal agencies to develop a system for assessing the advanced cyber capabilities of AI models before they are released.

Microsoft’s first advanced reasoning AI is here

infonews
industry
Jun 2, 2026

Microsoft announced MAI-Thinking-1, a new in-house AI model designed for advanced reasoning tasks, at its Build 2026 conference. The company claims this medium-sized model performs as well as leading models on software engineering benchmarks and was trained from scratch on clean data without using techniques from other companies' models. This represents Microsoft's growing effort to develop its own AI models instead of relying solely on its partnership with OpenAI.

Microsoft Scout is a new AI personal assistant built on OpenClaw

infonews
industry
Jun 2, 2026

Microsoft is launching Microsoft Scout, a new AI personal assistant built on OpenClaw (a foundation model technology) that integrates into Microsoft 365 apps like Outlook, OneDrive, and Teams. Unlike the existing Copilot assistant, Scout can see and do more, functioning as a comprehensive personal assistant that helps employees with tasks like organizing calendars, managing expenses, and drafting emails.

Google’s Phone app will tell you if a scammer is impersonating one of your contacts

infonews
safety
Jun 2, 2026

Google is adding a feature to its Phone app that detects when scammers use AI to impersonate calls from people in your contacts list, alerting you so you can hang up. The feature is part of Google's June Android update, which includes several other security and convenience improvements across Android devices.

Microsoft’s Project Solara is an OS for AI agent gadgets

infonews
industry
Jun 2, 2026

Microsoft announced Project Solara, a new operating system (OS, the core software that manages a device) built on Android and designed specifically for gadgets that run AI agents (software programs that can autonomously perform tasks). The company demonstrated two prototype devices: a desk gadget similar to Amazon Echo Show with facial recognition, and a wearable badge with a camera and fingerprint scanner, both intended to provide access to AI agents.

Previous119 / 238Next
Jun 3, 2026

Google is rolling out a new Android security feature called 'fake call detection' that protects users from AI deepfake scam calls where scammers impersonate someone's contacts. The feature works by having a user's device send an encrypted confirmation signal when receiving a call, and if that signal is missing, it pings the actual contact's phone to verify the call is real, warning the user to hang up if the contact's device confirms they're not calling.

Fix: Google's mitigation is built into the new 'fake call detection' feature, which is rolling out globally this month to Android 12 and later devices (starting with Pixel devices) and enabled by default. The feature requires Phone by Google, Contacts, and Google Messages (with RCS, or Rich Communication Services, enabled) to be installed. Google also stated: 'If your device uses a different app, you can install Phone by Google from the Play Store and set it as your default phone app to help protect yourself from fake calls.'

BleepingComputer
The Verge (AI)

Fix: NGINX: Upgrade to version 1.29.8 or later, which adds the max_headers directive with a default of 1000. Alternatively, disable HTTP/2 with http2 off;. Apache HTTPD: Upgrade mod_http2 to version 2.0.41 or later. Alternatively, set Protocols http/1.1 to disable HTTP/2. Microsoft IIS, Envoy, and Cloudflare Pingora: No patch available as of the article's writing date.

The Hacker News
Jun 2, 2026

Anthropic expanded its Project Glasswing (an AI-based vulnerability hunting initiative that finds security bugs in software) to 150 more companies, especially those in critical infrastructure like power and healthcare. However, security experts warn this creates a bottleneck problem: if AI finds vulnerabilities 10 or more times faster than before, companies may not be able to validate, prioritize, patch, and deploy fixes quickly enough, potentially overwhelming security teams rather than actually improving defense.

CSO Online
Jun 2, 2026

Palo Alto Networks CEO Nikesh Arora reported a surge in customer meetings, with the company fielding roughly 1,200 inquiries in recent weeks from organizations seeking guidance on AI security risks. The article notes that AI-powered attacks are becoming more sophisticated, making cybersecurity more important for companies, and that earlier investor concerns about AI disrupting cybersecurity companies appear to have been overblown.

CNBC Technology
BleepingComputer
Simon Willison's Weblog

Fix: HP has fixed the vulnerability in Poly Unified Communications Software (UCS) versions 6.4.8 for VVX devices, 8.1.7 for Trio 8300, and 7.2.8 for Trio 8500 and 8800 phones. Additionally, HP advises administrators to disable the ICE feature if it is not needed, since it is not enabled by default on HP Poly devices.

CSO Online
CNBC Technology
SecurityWeek
Check Point Research
The Verge (AI)
Jun 2, 2026

AI agents (systems that can act independently to complete tasks) with high autonomy and broad permissions are very difficult to secure and pose a serious risk to enterprises. The article warns that companies need to take action now to prevent AI agents from causing major problems in the future.

Dark Reading
Jun 2, 2026

President Trump signed an executive order focused on strengthening cybersecurity and establishing voluntary cooperation between the federal government and AI developers, reviving parts of a broader AI initiative he had canceled two weeks earlier. The order directs federal agencies to deploy AI-enhanced cybersecurity tools, create a government-industry system for sharing information about security vulnerabilities (known as a vulnerability-sharing initiative), and evaluate the cyber capabilities of advanced AI models. The order emphasizes that it does not impose mandatory licensing or approval requirements on AI developers, attempting to balance national security concerns with innovation.

Fix: The executive order specifies several explicit actions: Within 30 days, the Committee on National Security Systems must prioritize cyber defense of national security systems (NSS, government systems handling classified information). The Department of Defense is directed to prioritize protection of its own information systems. The Cybersecurity and Infrastructure Security Agency (CISA) must issue directives and guidance to strengthen civilian federal networks and accelerate adoption of AI-enabled defensive technologies.

CSO Online
The Verge (AI)
The Verge (AI)
The Verge (AI)
The Verge (AI)
The Verge (AI)