aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4755 items

Anthropic Silently Patches Claude Code Sandbox Bypass

highnews
security
May 20, 2026

Anthropic patched a vulnerability in Claude Code's network sandbox (a restricted environment that controls where the AI can send data) that could have allowed attackers to bypass security controls and steal sensitive information. The vulnerability, called a SOCKS5 hostname null-byte injection issue (a trick where attackers hide a malicious server address using special characters to fool the security filter), was silently fixed in version 2.1.88 released on March 31, 2025, but was never publicly disclosed or assigned a tracking identifier.

Fix: The vulnerability was fixed in Claude Code version 2.1.88, released on March 31, 2025. According to Anthropic, the fix was included in a public commit to the 'sandbox-runtime' repository on March 27, 2025.

SecurityWeek

Why some security fixes never reach your vulnerability dashboard

infonews
security
May 20, 2026

A malicious version of Bitwarden CLI was published on npm for 90 minutes in April 2026, stealing developer credentials through a compromised GitHub Action (an automated workflow tool). The incident received a CVE (common vulnerabilities and exposures, an official vulnerability identifier), but the CVE only notified defenders after the fact rather than providing a patch to apply, highlighting how CVE has drifted from its original purpose of identifying code flaws with fixable versions to tracking security incidents.

What It'll Take to Make AI BOMs Usable in a Modern Security Program

infonews
policysecurity

Singapore inks AI deals with Google, OpenAI as ChatGPT-maker commits $234 million to local ecosystem

infonews
industrypolicy

Google announces glasses are back and search is getting an AI makeover

infonews
industry
May 19, 2026

Google announced updates to its search engine that will use AI more heavily, allowing users to ask longer, more natural questions that get answered by Google's chatbot instead of traditional search results. The company also revealed new smart glasses (wearable devices with computer capabilities) for consumers, marking its return to the hardware market over a decade after its previous glasses faced public criticism. These changes are powered by Google's new Gemini 3.5 AI model.

The next phase of OpenAI’s Education for Countries

infonews
industrypolicy

How Ramp engineers accelerate code review with Codex

infonews
industry
May 19, 2026

Ramp engineers use Codex (an AI code review tool) with GPT-5.5 to give substantive feedback on pull requests (code changes) in minutes instead of hours, catching bugs that human reviewers miss. Beyond code review, they're also using Codex to build internal tools like On-Call Assistant, which helps manage the complex demands of on-call engineer shifts (when engineers respond to system emergencies). The tool stands out because it deeply analyzes the codebase and reasons through complex problems, reducing manual work that would otherwise require significant mental effort.

llm-gemini 0.32

infonews
security
May 19, 2026

N/A -- The provided content only contains a title and version number (llm-gemini 0.32) with no substantive information about any security issue, vulnerability, or problem to analyze.

Gemini 3.5 Flash: more expensive, but Google plan to use it for everything

infonews
industry
May 19, 2026

Google released Gemini 3.5 Flash, a new AI model now available to billions of users through Google apps and to developers via APIs (application programming interfaces, tools that let software communicate). The model is significantly more expensive than previous Flash versions, costing 3-6 times more, bringing it close in price to Google's more advanced Gemini 3.1 Pro model.

What Will Make AI BOMs Real?

infonews
policysecurity

OpenAI announces new Guaranteed Capacity offering for customers to secure compute

infonews
industry
May 19, 2026

OpenAI announced a new Guaranteed Capacity offering that lets customers lock in long-term access to compute (the computational power needed to train and run AI models) by committing to one, three-year contracts with increasing discounts based on the commitment length. CEO Sam Altman said this helps OpenAI plan ahead while giving customers certainty about capacity availability, though the offering is only available until current allocation sells out.

From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

infonews
securityindustry

Google’s AI future demands trust — and your personal data

infonews
privacypolicy

datasette-llm-accountant 0.1a4

infonews
industry
May 19, 2026

datasette-llm-accountant 0.1a4 is a software release, but the provided content contains only a title and version number with no description of features, functionality, or issues.

llm-gemini 0.32a0

infonews
industry
May 19, 2026

This item references llm-gemini version 0.32a0, which appears to be a software package or library for working with Google's Gemini AI model. Without additional context about a specific issue, vulnerability, or problem, no technical analysis can be provided from the content given.

Introducing OpenAI for Singapore

infonews
industry
May 19, 2026

OpenAI announced a partnership with Singapore's government called 'OpenAI for Singapore,' backed by over S$300 million, to help the country become an AI-powered economy. The initiative will establish OpenAI's first Applied AI Lab outside the United States, create over 200 technical jobs, and focus on deploying frontier AI (cutting-edge AI systems), developing local AI talent, and expanding AI access across organizations in sectors like healthcare, finance, and public services.

datasette-llm 0.1a8

infonews
industry
May 19, 2026

datasette-llm 0.1a8 is an early-stage release (indicated by the 'a' in the version number, meaning alpha or pre-release software) announced by Simon Willison in May 2026. The source text does not provide details about what this software does, what problems it solves, or any security issues associated with it.

Roundtables: Inside the Musk v. Altman Trial

infonews
policy
May 19, 2026

Elon Musk lost a lawsuit against OpenAI in which he claimed that CEO Sam Altman and President Greg Brockman had misled him about the company's non-profit status. MIT Technology Review hosted a discussion with AI reporter Michelle Kim and editor Mat Honan to examine the trial details and what the outcome means for competition in the AI industry.

Polymarket launches private company trading so investors can speculate on Anthropic, OpenAI

infonews
industry
May 19, 2026

Polymarket is launching prediction markets (contracts where traders bet on whether specific events will happen) tied to private companies like OpenAI and Anthropic, allowing regular investors to speculate on milestones such as IPO timing and company valuations without actually owning shares. Nasdaq Private Market will provide the data to determine whether these contracts pay out, and for the first time will make valuation data publicly available for free. This addresses a frustration where ordinary investors are typically excluded from investing in private companies that have created enormous value before going public.

AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

highnews
security
May 19, 2026

The npm (node package manager, a repository for reusable code libraries) registry was attacked on May 19 when hackers compromised a maintainer account and published 637 malicious versions of 317 packages, including the popular AntV data visualization tool used by Alibaba. The malware, called Mini-Shai-Hulud worm, steals credentials like npm tokens, GitHub tokens, and passwords from cloud platforms and wallets. After detection, AntV's maintainers deleted the infected packages and marked remaining ones as deprecated, advising users to download only the latest verified versions.

Previous130 / 238Next
CSO Online
May 19, 2026

This article discusses AI Bills of Materials (BOMs, which are detailed lists of components and dependencies used in AI systems), and how security leaders can prepare to use them effectively in their organizations. The piece focuses on five strategies that CISOs (Chief Information Security Officers, the executives responsible for security) can use to both adopt AI BOMs and help shape how they're created in the future.

Dark Reading
May 19, 2026

Singapore has signed separate agreements with Google and OpenAI to strengthen its position as a global AI hub and speed up AI deployment in public services, healthcare, education, and business. OpenAI will invest over $234 million in Singapore's AI ecosystem and establish its first applied AI lab outside the U.S., while Google will focus on solving societal challenges, building an AI-ready workforce, and creating a secure AI ecosystem (systems designed to prevent harmful outcomes from AI).

CNBC Technology
The Guardian Technology
May 19, 2026

OpenAI is launching 'Education for Countries,' a program to help governments deploy AI tools like ChatGPT and Codex (a code-generation AI) in schools through research partnerships, teacher training, and localized systems. The program aims to improve learning outcomes while ensuring responsible adoption by measuring real-world impact in classroom settings and building educator confidence.

OpenAI Blog
OpenAI Blog
Simon Willison's Weblog
Simon Willison's Weblog
May 19, 2026

This article discusses AI BOMs (bill of materials, a detailed list of components and dependencies in an AI system), exploring what factors will encourage more organizations to create and use them. The content examines the forces and motivations driving adoption of this practice for better AI transparency and management.

Dark Reading
CNBC Technology
May 19, 2026

Ocean, a new startup founded by former Israeli cybersecurity researcher Shay Shwartz, has raised $28 million to fight AI-powered phishing attacks (fraudulent emails designed to steal information). The company argues that AI makes phishing easier and faster by automating the research and targeting process that previously required manual effort, so traditional email security tools are insufficient. Ocean's solution uses a small language model (a scaled-down AI trained for specific tasks) to analyze incoming emails for fraud and impersonation by understanding context and the sender's intent.

Fix: Ocean built a small language model tailored to quickly analyze emails, understand the sender's intent, and evaluate it against the user's specific organizational context. According to the founder, this approach works like 'having a guard in every door' to make the inbox safe.

TechCrunch (Security)
May 19, 2026

Google is promoting new AI tools like Gemini Spark (an always-on AI agent that helps organize events and brief you on your day) and expanded Gmail AI features that draft emails and create to-do lists, but these tools rely on processing large amounts of personal data. The article raises concerns about whether users should trust Google with this personal information to power its AI-powered future.

The Verge (AI)
Simon Willison's Weblog
Simon Willison's Weblog
OpenAI Blog
Simon Willison's Weblog
MIT Technology Review
CNBC Technology

Fix: According to AntV's GitHub warning, the infected packages have been deleted and remaining ones marked as deprecated. Users should identify and download the latest versions from a list of compromised packages. Beyond this, experts recommend developers look for signs of compromise in CI/CD (continuous integration/continuous deployment, automated systems that build and deploy code) environments and repositories, and rotate all credentials.

CSO Online