aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4767 items

OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation

infonews
securityindustry
May 12, 2026

OpenAI launched Daybreak, a new tool that uses AI models to help organizations find and fix software vulnerabilities before attackers can exploit them. Daybreak combines OpenAI's AI capabilities with Codex Security to automate tasks like code review, threat modeling, and patch validation. However, the article notes that AI tools have created a problem where vulnerabilities are discovered faster than developers can fix them, leading to 'triage fatigue' (where maintainers get overwhelmed sorting through many vulnerability reports, some of which may be false alarms generated by AI).

Fix: According to the source, Daybreak addresses the remediation bottleneck by incorporating 'patch validation' and 'remediation guidance into the everyday development loop so software becomes more resilient from the start.' Additionally, the text states that 'companies like Anthropic, Google, and OpenAI have increasingly positioned AI security agents as a new operational layer to address the remediation bottleneck and safeguard digital infrastructure from potential exploitation.' However, no specific technical steps or implementation details are provided in the source text.

The Hacker News

Linux kernel maintainers suggest a ‘kill switch’ to protect systems until a zero-day vulnerability is patched

infonews
security
May 11, 2026

Linux kernel maintainers are proposing a 'kill switch' that would let system administrators disable a vulnerable function in the OS kernel (the core software that manages hardware and system resources) until a patch for a zero-day vulnerability (a previously unknown security flaw) is ready. The proposal aims to protect servers during the gap between when a vulnerability is discovered and when a patched kernel can be built, tested, and restarted on systems, though security experts debate whether this approach is practical or creates new risks.

How NVIDIA engineers and researchers build with Codex

infonews
industry
May 11, 2026

NVIDIA engineers and researchers use Codex, an AI coding tool built on GPT-5.5, to automate complex engineering tasks and machine learning research workflows. The tool can work autonomously for long sessions, finding bugs and writing code that earlier models couldn't, and has enabled teams to build production systems and run experiments much faster than before. Codex integrates with remote infrastructure (SSH, or secure shell protocol, which lets users securely connect to distant computers) and can even test its own code as it's being built.

AutoScout24 scales engineering with AI-powered workflows

infonews
industry
May 11, 2026

AutoScout24 Group, a large European and Canadian online car marketplace, implemented AI tools like ChatGPT and Codex (an AI coding assistant) across its 2,000 employees to speed up software development and improve code quality. By embedding Codex directly into engineering workflows and creating an "AI Champions" network for knowledge sharing, the company reduced development timelines from 2-3 weeks to 2-3 days for some projects while maintaining reliability.

OpenAI just released its answer to Claude Mythos

infonews
securityindustry

Here’s what Mira Murati’s AI company is up to

infonews
industry
May 11, 2026

Thinking Machines, an AI company founded by former OpenAI CTO Mira Murati, is developing 'interaction models' that can process audio, video, and text simultaneously and respond in real time, unlike current AI models that wait passively for users to finish typing or speaking before responding.

Google says it likely thwarted effort by hacker group to use AI for 'mass exploitation event'

infonews
security
May 11, 2026

Google's security team reported that it stopped hackers from using AI models to find and exploit a zero-day vulnerability (a software flaw unknown to developers) as part of a planned large-scale attack that would have bypassed two-factor authentication (a security method using two verification steps). The incident highlights a growing concern that criminals are using available AI tools to discover software weaknesses in ways that could harm companies and organizations.

OpenAI revenue chief Dresser says enterprise AI adoption is 'at a tipping point'

infonews
industry
May 11, 2026

OpenAI's Chief Revenue Officer announced that enterprise AI adoption is reaching a 'tipping point' and introduced a new Deployment Company to accelerate business adoption of AI technology. The company acquired Tomoro, an AI consulting firm, bringing about 150 forward-deployed engineers (specialists who work directly with clients to integrate AI into their business processes) who will help organizations understand their workflows and implement AI solutions.

Using LLM in the shebang line of a script

infonews
research
May 11, 2026

A developer demonstrated how to use an LLM (large language model) directly in the shebang line (the first line of a script that tells the system how to run it) of executable text files, allowing scripts to be written as natural English prompts instead of traditional code. The approach uses the LLM tool with various options to generate outputs like SVG images, incorporate external tools, and even execute YAML templates that define custom Python functions.

OpenAI trial: Nadella says Musk never raised concerns to him about Microsoft investment

infonews
industry
May 11, 2026

Microsoft CEO Satya Nadella testified in a lawsuit that Elon Musk never contacted him about concerns that Microsoft's investments in OpenAI violated any agreements or commitments. Musk sued OpenAI and its leaders in 2024, claiming they abandoned the company's nonprofit mission, and he alleges Microsoft's $13 billion in investments to OpenAI helped enable this breach of charitable trust. Nadella stated that Microsoft's investments were commercial partnerships with clear business benefits, not donations, and that he believed the company acted appropriately.

Google stopped a zero-day hack that it says was developed with AI

infonews
security
May 11, 2026

Google discovered and blocked a zero-day exploit (a previously unknown security flaw) that was created with AI assistance, which criminals planned to use for mass attacks on a web administration tool. Researchers identified AI involvement by finding signs in the Python script like artificial CVSS scores (severity ratings) and text patterns typical of AI language models.

How ChatGPT adoption broadened in early 2026

infonews
industry
May 11, 2026

OpenAI's Q1 2026 data shows ChatGPT adoption expanded beyond early adopters, with growing usage among older age groups, users with typically feminine names, and people in emerging markets across Latin America, Asia-Pacific, and Africa. Workplace use evolved to focus on specialized tasks like content creation and health documentation rather than just general writing. Overall, ChatGPT became a more mainstream tool used by diverse people in more countries for recurring tasks.

AI-powered hacking has exploded into industrial-scale threat, Google says

infonews
security
May 11, 2026

According to Google's threat intelligence group, AI-powered hacking (using AI models to help create and scale cyberattacks) has rapidly grown from a minor issue to a large, organized threat in just three months. Criminal groups and state-sponsored actors are now using commercial AI models to write code and find vulnerabilities (weaknesses in software that can be exploited) more effectively and at a much larger scale.

Joanna Stern is not a robot, but she lived with them

infonews
industry
May 11, 2026

This is a podcast interview transcript where tech journalist Joanna Stern discusses her new book 'I Am Not a Robot,' in which she spent a year integrating AI into every aspect of her life to evaluate the technology's current state. She found that many hyped AI products, especially humanoid robots (physical machines designed to look and act like humans), are not yet ready for real-world use, though she is optimistic about wearable AI (AI embedded in portable devices like smartwatches) as a potential breakthrough application.

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

highnews
securityresearch

Cerebras bumps up IPO range as it looks to raise up to $4.8 billion

infonews
industry
May 11, 2026

Cerebras Systems, an AI chipmaker, increased its IPO (initial public offering, when a private company sells shares to the public for the first time) price range to $150-$160 per share, up from $115-$125, potentially raising $4.8 billion. The company makes specialized chips that compete with Nvidia's GPUs (graphics processing units, hardware that processes AI calculations) and claims its chips are faster and cheaper, with major backing from OpenAI.

Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program

infonews
securityindustry

Google discovers weaponized zero-day exploits created with AI

highnews
securitysafety

Hackers Use AI for Exploit Development, Attack Automation

infonews
security
May 11, 2026

Attackers are increasingly using large language models (AI systems trained on vast amounts of text that can generate human-like responses) to create exploits (tools that take advantage of software vulnerabilities) and automate complex attacks. While adversaries have used AI for a while, this represents a shift toward more sophisticated automation of the attack development process.

Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads

highnews
security
May 11, 2026

A fake AI model repository on Hugging Face (a platform for sharing AI models) impersonated OpenAI's Privacy Filter and tricked 244,000 users into downloading it before removal. The malicious repository contained a loader.py file that delivered infostealer malware (software that steals passwords and credentials) to Windows systems, highlighting risks in how companies source and validate AI models from public repositories.

Previous139 / 239Next

Fix: The proposed mitigation, as described by Sasha Levin, is: 'for many such issues, the simplest mitigation is to stop calling the buggy function.' Levin suggests that 'the cost of this socket family stops working for the day is much smaller than the cost of running a known vulnerable kernel until the fix lands.' A proposed version of a kernel kill switch has been provided by Levin and a colleague, though the source does not detail the technical implementation of this kill switch.

CSO Online
OpenAI Blog
OpenAI Blog
May 11, 2026

OpenAI launched Daybreak, an AI security initiative designed to find and fix vulnerabilities (weaknesses in software that attackers could exploit) before attackers discover them. Daybreak uses the Codex Security AI agent to analyze an organization's code, identify potential attack paths (ways an attacker could compromise the system), and automatically detect high-risk vulnerabilities.

The Verge (AI)
The Verge (AI)
CNBC Technology
CNBC Technology
Simon Willison's Weblog
CNBC Technology
The Verge (AI)
OpenAI Blog
The Guardian Technology
The Verge (AI)
May 11, 2026

Threat actors are increasingly using AI and large language models (LLMs, systems trained on massive amounts of text to generate human-like responses) to discover vulnerabilities, create malware, and conduct cyberattacks at industrial scale, with groups linked to China, North Korea, and Russia demonstrating significant AI-enabled capabilities. AI is being used both as an attack tool (for generating exploits, evading defenses, and creating deepfakes) and as a target for compromise, with attackers seeking unauthorized access to AI systems through supply chain attacks and illicit model access. Google's Threat Intelligence Group reports these threats are advancing from experimental to mature operations, including autonomous malware like PROMPTSPY that can dynamically adapt to victim systems.

Fix: Google mitigates AI model abuse by disabling malicious accounts accessing Gemini. Additionally, Google employs AI agents like Big Sleep to identify software vulnerabilities and uses Gemini's reasoning capabilities through CodeMender to automatically fix vulnerabilities, while enhancing product safeguards to offer scaled protections to users.

Google Threat Intelligence
CNBC Technology
May 11, 2026

OTT Cybersecurity LLC announced that its product Lyrie.ai has been accepted into Anthropic's Cyber Verification Program, and released the Agent Trust Protocol (ATP), an open cryptographic standard (a set of math-based rules for secure communication) that allows systems to verify the identity, permissions, and integrity of autonomous AI agents operating on the internet. ATP addresses a security gap by letting organizations confirm who an AI agent is, what it's authorized to do, and whether it has been tampered with.

CSO Online
May 11, 2026

Google's Threat Intelligence Group discovered the first confirmed AI-crafted zero-day exploit (a previously unknown security flaw) in the wild, which was a Python script that bypassed two-factor authentication (a security method requiring two forms of verification) on a web-based system administration tool. The exploit exploited a logic flaw that the AI model found by understanding the developers' intent rather than just finding basic coding mistakes. As AI models become more advanced at reasoning about complex code, such AI-generated exploits may become more common, and threat actors are also attempting to abuse AI systems like Google's Gemini to discover vulnerabilities in firmware (the low-level software in devices) and other systems.

CSO Online
Dark Reading
CSO Online