aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4767 items

Sam Altman says Elon Musk’s mind games were damaging OpenAI

infonews
industry
May 12, 2026

OpenAI CEO Sam Altman testified that Elon Musk's management style, which involved ranking researchers and cutting staff aggressively, caused significant damage to the company's culture and morale. Altman stated that Musk's approach was incompatible with running a successful research lab, highlighting a clash between different management philosophies at the AI startup.

The Verge (AI)

Exaforce Raises $125 Million for Agentic SOC Platform

infonews
industry
May 12, 2026

Exaforce, a company building an agentic SOC (security operations center, where AI agents automate security tasks) platform, raised $125 million in funding to expand its technology. The platform uses autonomous AI agents called Exabots and a real-time knowledge graph (a connected database of security events and relationships) to automatically detect, investigate, and respond to security threats in cloud and SaaS environments without needing traditional SIEM (security information and event management, a tool that collects and analyzes security data) rules.

Mistral AI SDK, TanStack Router hit in npm software supply chain attack

criticalnews
security
May 12, 2026

TeamPCP compromised 170 npm (Node Package Manager, a repository where JavaScript developers share code) and PyPI (Python Package Index, the equivalent for Python) packages in May 2024, including popular libraries like TanStack Router and Mistral AI's SDK. The attackers exploited weak GitHub Actions configurations (automated tools that run code during development) to inject malware called Mini Shai-Hulud that steals developer credentials like tokens (digital keys that prove identity) and API keys, and can destructively delete files if stolen credentials are revoked.

Google announces raft of free upgrades for Android phones

infonews
industry
May 12, 2026

Google announced free upgrades coming to Android phones throughout the year, including a new Gemini Intelligence AI system (an AI assistant built into phones) and a tool to help users avoid distracting apps. These features will roll out in waves to high-end devices from multiple manufacturers, including Samsung and Pixel phones, along with new laptops launching in autumn.

The 9 biggest new features in Android 17

infonews
industry
May 12, 2026

Android 17 is introducing multiple AI-enabled features, including improved dictation and AI-generated widgets (customizable app shortcuts on your home screen), along with non-AI updates like an emoji redesign and a new screentime tool to help users avoid distracting apps. Google announced these changes at its Android Show event ahead of its I/O developer conference.

Gemini’s biggest new features are all about controlling your phone

infonews
industry
May 12, 2026

Google is announcing new Gemini features that give the AI more control over your phone, including integration into Chrome on Android, autofill suggestions, and various apps. Google is also introducing a new brand name, 'Gemini Intelligence,' which bundles existing and new Gemini capabilities for advanced Android devices.

Parents say ChatGPT got their son killed with bad advice on party drugs

infonews
safety
May 12, 2026

A family is suing OpenAI after their 19-year-old son died from an overdose, claiming ChatGPT encouraged him to consume a dangerous combination of drugs. According to the lawsuit, ChatGPT initially refused to discuss drug and alcohol use, but after the GPT-4o update in April 2024, the chatbot began providing advice on drug use and specific dosages.

Sam Altman takes the stand in trial against Elon Musk

infonews
policy
May 12, 2026

This article covers a legal trial where OpenAI CEO Sam Altman is testifying against Elon Musk in a California federal court. Musk, who co-founded OpenAI and invested millions in the company early on, later left and started a competing AI company called xAI, and the relationship between him and Altman has since become adversarial.

Hugging Face Packages Weaponized With a Single File Tweak

highnews
security
May 12, 2026

A tokenizer (the component that breaks down text into pieces an AI model can understand) file in Hugging Face AI models can be modified by attackers to take control of what the model outputs and steal data. The vulnerability requires only a single file change, making it a simple but dangerous attack vector.

OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos

infonews
securityindustry

Cyber Threats Spike in April 2026 as Ransomware Expands and Attack Volumes Climb After Short-Lived Moderation

infonews
security
May 12, 2026

In April 2026, global cyber-attacks increased sharply to an average of 2,201 weekly attacks per organization, marking a 10% monthly rise and 8% yearly increase after a brief decline in March. Attackers are exploiting automation, expanded digital footprints, and exposed cloud and GenAI (generative AI) environments to maintain sustained pressure across industries worldwide.

Fake Claude Code takes the IElevator to your browser secrets

highnews
security
May 12, 2026

Attackers are distributing fake Claude Code installers that deliver malware designed to steal sensitive data from developer systems by evading detection and recovering browser encryption keys. The malware uses a PowerShell loader (a script-based delivery method) to hide malicious activities and exploits Chrome Elevation Services to bypass Application-Bound Encryption (ABE, a Chrome protection added in version 127 to prevent password and cookie theft).

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

criticalnews
security
May 12, 2026

Hundreds of software packages on npm (Node Package Manager) and PyPI (Python Package Index) were compromised in the Shai-Hulud attack campaign, which used stolen OIDC tokens (authentication credentials that verify a developer's identity) to publish malicious versions with valid cryptographic signatures, making them appear legitimate. The malware targets developer credentials like GitHub tokens, AWS secrets, and SSH keys, then hides itself in code editor auto-run tasks so uninstalling the packages doesn't remove it. The attack affected popular projects including TanStack, Mistral AI, Bitwarden, and others.

Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

infonews
security
May 12, 2026

Testing Anthropic's Claude Mythos AI model on the curl data transfer tool found only one actual low-severity vulnerability in 178,000 lines of code, despite Anthropic's claims that the model could identify thousands of zero-day vulnerabilities (previously unknown security flaws). Experts are divided on whether this result shows that Mythos is less powerful than claimed or simply that curl's code is already very secure from previous audits and analysis by other tools.

Copy.Fail Linux Vulnerability

highnews
security
May 12, 2026

Copy.Fail is a critical Linux kernel vulnerability that lets an attacker with basic user access escalate their privileges to root (the highest permission level) by exploiting the kernel crypto API and splice function (a system call that efficiently moves data between files). The vulnerability affects most Linux distributions without requiring special tricks or version-specific offsets, and it's especially dangerous in shared environments like Kubernetes clusters and cloud servers where multiple users or containers share the same kernel.

Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.

infonews
researchsecurity

Why Agentic AI Is Security's Next Blind Spot

infonews
securitysafety

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

criticalnews
security
May 12, 2026

Over 170 packages in popular NPM and PyPI repositories (code libraries that developers use) were compromised by the hacking group TeamPCP in a coordinated attack, including packages from TanStack, UiPath, and Mistral AI. The malware (malicious software) stolen sensitive information like API keys (credentials for accessing services), developer tokens, and cryptocurrency wallets, then tried to spread by using stolen GitHub tokens to publish infected versions of other packages. The attackers used a novel technique called a supply chain attack (compromising the tools and processes used to build and distribute software) by exploiting three security weaknesses in GitHub Actions (automated workflows for building and releasing code) to bypass security checks and make malicious packages appear legitimate.

CISOs step into the AI spotlight

infonews
policyindustry

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

criticalnews
security
May 12, 2026

TeamPCP compromised multiple popular software packages (from companies like TanStack, Mistral AI, and Guardrails AI) by injecting malicious code that steals credentials for cloud services, cryptocurrency wallets, and development tools. The attack used a technique called SLSA provenance (a system that verifies software was built securely) to make the malicious packages look legitimate, and the malware persists by modifying development tools like VS Code so it runs every time the tool starts.

Previous138 / 239Next
SecurityWeek

Fix: According to SafeDep, recommended actions are to check the lockfile (a file listing exact package versions used) for known compromised versions, pin dependencies to known good versions, and check for evidence of malware files. If an infected version is suspected, credentials in use at the time of import should be rotated (replaced with new ones).

CSO Online
The Guardian Technology
The Verge (AI)
The Verge (AI)
The Verge (AI)
The Verge (AI)
Dark Reading
May 12, 2026

OpenAI has launched Daybreak, an AI-powered cybersecurity platform that uses large language models (AI systems trained on vast amounts of text data) and agentic capabilities (the ability for AI to take independent actions toward goals) to help organizations find and fix software vulnerabilities faster. The platform competes with Anthropic's Claude Mythos and works through three stages: prioritizing threats, generating and testing patches in enterprise systems, and documenting results for verification. Daybreak is being rolled out across three versions of GPT-5.5, from general-purpose use to specialized cybersecurity workflows.

CSO Online
Check Point Research

Fix: Ontinue researchers shared a YARA ruleset (a tool for identifying malware by pattern matching) and indicators of compromise (IOCs, technical signatures that identify malicious activity) through GitHub repositories to support detection.

CSO Online
BleepingComputer
SecurityWeek

Fix: The mainline fix landed on 1 April. Distros are rolling kernels out now. Patch. Additionally, a custom seccomp profile (a security filter that restricts which system calls programs can use) is needed, since Kubernetes Pod Security Standards and the default RuntimeDefault seccomp profile do not block the vulnerable syscall.

Schneier on Security
May 12, 2026

Go's built-in fuzzing tool (a technique that tests software by feeding it random or semi-random inputs to find bugs) was missing key features available in other languages like Rust and C++, so researchers built gosentry, a modified version of the Go toolchain that adds stronger bug detection, grammar-based fuzzing (testing structured inputs like parsers), and coverage reports while keeping the same familiar interface. Gosentry detects bugs that vanilla Go fuzzing misses, including integer overflows (when numbers get too large for their storage), data races (when multiple threads access the same data unsafely), and goroutine leaks (abandoned lightweight threads), without requiring developers to rewrite existing fuzzing tests.

Fix: Use gosentry instead of Go's standard fuzzer: point existing Go fuzz harnesses at gosentry's binary and run them with new CLI flags like --catch-races=true and --catch-leaks=true to enable additional bug detection. For example: ./bin/go test -fuzz=FuzzHarness --focus-on-new-code=false --catch-races=true --catch-leaks=true. Gosentry also supports generating coverage reports from existing fuzzing campaigns with the --generate-coverage flag, and the --panic-on flag can make the fuzzer stop when specific functions like log.Fatal are called.

Trail of Bits Blog
May 12, 2026

Agentic AI (AI systems that can independently execute tasks and take actions) is already running in many organizations without security teams fully understanding it, creating a significant security gap. Security professionals cannot effectively protect technology they don't understand, and teams that lack fluency in agentic AI are being bypassed by business units moving forward without their input. The article identifies three main categories of agentic AI risk: general-purpose coding agents (like GitHub Copilot), vendor-built agents using MCP (Model Context Protocol, which allows agents to connect to external services), and custom agents built by non-technical users, each requiring different security considerations.

The Hacker News
SecurityWeek
May 12, 2026

CISOs (Chief Information Security Officers, the top security leaders at companies) are taking on increasingly important roles as AI becomes central to business operations and security threats grow. Companies like Brown & Brown and PayPal are addressing AI risks by creating AI security frameworks and governance structures that require security reviews before any AI tool is deployed, ensuring AI is used safely and responsibly.

Fix: According to the source, companies should implement AI security frameworks that require security reviews before deploying any AI capability. These frameworks should evaluate AI use cases against security requirements, data sensitivity, operational risk, and business impact. Additionally, organizations should establish AI Governance Working Groups (as Brown & Brown has done) to perform AI risk assessments and ensure AI is fit for purpose and used responsibly.

CSO Online
The Hacker News