aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4767 items

10 questions to ask when using AI models to find vulnerabilities

inforegulatory
policysecurity
May 11, 2026

This article presents ten critical questions organizations should ask before using AI models to find vulnerabilities in their systems. Rather than offering a specific technical fix, it emphasizes that simply finding vulnerabilities doesn't improve security without proper processes, prioritization, and risk management in place. Key concerns include data leakage risks, whether AI is truly the best approach compared to basic security hygiene like patching, and ensuring your organization has the people and processes to actually fix discovered issues.

UK NCSC

OpenAI to give EU access to new cyber model but Anthropic still holding out on Mythos

infonews
policysecurity

LLMs and Text-in-Text Steganography

infonews
securityresearch

AI security is repeating endpoint security’s biggest mistake

infonews
securitypolicy

OpenAI Campus Network: Student club interest form

infonews
industry
May 11, 2026

This is an interest form from OpenAI for university student clubs to join their Campus Network program. The form collects information about the club's activities, current use of AI tools, and what kinds of support or opportunities the club members are interested in exploring.

8 guiding principles for reskilling the SOC for agentic AI

infonews
industrypolicy

1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolution

highnews
security
May 11, 2026

Over 1,800 MCP servers (Model Context Protocol servers, tools that connect AI assistants to external systems) are publicly exposed without requiring authentication, meaning anyone can see what internal tools an organization has connected to their AI. Security researchers found that production systems with access to financial databases, social media accounts, and customer data are vulnerable to attacks like EchoLeak (a zero-click exploit that hides malicious instructions in documents) and mcp-remote (a supply chain attack using a widely-downloaded package with a command injection vulnerability).

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

highnews
security
May 11, 2026

A fake repository on Hugging Face (a platform for sharing AI models) impersonated OpenAI's Privacy Filter model and tricked 244,000 users into downloading malware disguised as a legitimate tool. The malicious repository copied the real project's description verbatim and included a loader script that deployed an information stealer, a type of malware that harvests sensitive data like passwords, screenshots, and cryptocurrency wallet information from Windows machines.

OpenAI launches DeployCo to help businesses build around intelligence

infonews
industry
May 11, 2026

OpenAI is launching the OpenAI Deployment Company, a new business unit staffed with Forward Deployed Engineers (FDEs, specialists in integrating AI systems into organizations) to help businesses build and deploy AI technology across their operations. The company, backed by $4 billion in initial investment and partnerships with major investment firms and consulting companies, acquired Tomoro to bring approximately 150 experienced FDEs on board and aims to help organizations redesign workflows and infrastructure around AI to achieve measurable results.

Hackers abuse Google ads, Claude.ai chats to push Mac malware

highnews
security
May 10, 2026

Attackers are running a malware campaign that uses Google Ads and fake Claude.ai shared chats to trick Mac users searching for Claude into downloading malware. The malicious chats pretend to be official installation guides and trick users into pasting commands in Terminal that download and run hidden malware, which steals browser passwords, cookies, and data from macOS Keychain (the system that stores passwords and sensitive information on Macs).

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

criticalnews
security
May 10, 2026

Ollama, a popular framework for running large language models locally, has a critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS score 9.1) that allows attackers to leak sensitive data like API keys and conversation history from process memory by uploading a specially crafted GGUF file (a file format for storing language models). The vulnerability affects versions before 0.17.1 and potentially impacts over 300,000 servers globally.

What I saw at the Musk-OpenAI trial: petty billionaires, protests and a stern judge

infonews
policy
May 9, 2026

This article describes a legal trial between Elon Musk and OpenAI's leadership taking place in Oakland, focusing on disputes over the future of artificial intelligence. The piece is a journalistic account of the courtroom drama, featuring prominent tech figures and highlighting tensions between wealthy individuals and companies in the AI industry.

Fake OpenAI repository on Hugging Face pushes infostealer malware

highnews
security
May 9, 2026

A fake OpenAI repository on Hugging Face (a platform where developers share AI models and code) disguised itself as a legitimate project and tricked users into downloading a malicious loader script that steals sensitive data like passwords, cryptocurrency wallets, and browser cookies. The fake repository reached the top of Hugging Face's trending list with 244,000 downloads before the platform removed it after researchers reported the threat.

Musk v. Altman week 2: OpenAI fires back, and Shivon Zilis reveals that Musk tried to poach Sam Altman

infonews
policy
May 8, 2026

This article covers week two of a lawsuit where Elon Musk is suing OpenAI and its leaders, claiming they broke promises to keep the company as a nonprofit dedicated to safe AI development. OpenAI's president Greg Brockman countered that Musk actually pushed for the company to become for-profit and wanted majority control, and that Musk is suing because he left the company in 2018 and now sees it as a competitor to his own AI company, xAI (an artificial intelligence system). Musk is seeking $134 billion in damages and wants to remove the current leadership and undo OpenAI's recent restructuring.

Using Claude Code: The Unreasonable Effectiveness of HTML

infonews
research
May 8, 2026

This article discusses using HTML instead of Markdown when requesting output from Claude, an AI assistant. HTML allows Claude to create richer explanations by including SVG diagrams, interactive widgets, and better navigation, which was less practical with older language models that had strict token limits (tokens being units of text that count toward a model's processing capacity).

A Framework for AI Threat Readiness

infonews
securitypolicy

Anthropic's Mythos set off a cybersecurity 'hysteria.' Experts say the threat was already here

infonews
securityindustry

PlayStation sees AI as a ‘powerful tool’ to help make games

infonews
industry
May 8, 2026

Sony views generative AI (machine learning systems that can create new content like images or text) as a useful tool for game development, particularly for automating repetitive tasks. The company emphasizes that AI should enhance developer creativity rather than replace human talent, and that the artistic vision and emotional impact of games will continue to come from Sony's studios and performers.

Microsoft was worried OpenAI would run off to Amazon and ‘shit-talk’ Azure

infonews
industry
May 8, 2026

Court documents from a lawsuit between Elon Musk and Sam Altman revealed that Microsoft's executives were worried OpenAI might leave to work with Amazon instead and publicly criticize Microsoft's cloud service (Azure, Microsoft's platform for running applications online). The documents show communications between Microsoft CEO Satya Nadella and OpenAI CEO Sam Altman from 2017 when they were beginning to discuss a partnership to fund OpenAI's AI research.

Everybody wants to rule the AI world

infonews
industry
May 8, 2026

This article discusses the chaotic leadership transition at OpenAI in 2024, when Sam Altman was removed as CEO under unclear circumstances involving video calls and informal communications between current and former leadership. The situation's complexity is now being revealed through an ongoing legal dispute between Elon Musk and Altman.

Previous140 / 239Next
May 11, 2026

OpenAI announced it will give the European Union access to GPT-5.5-Cyber, a specialized AI model designed for cybersecurity defense, while Anthropic has not yet granted similar access to its competing model called Mythos. The EU plans to review OpenAI's model closely to address security concerns, though discussions with Anthropic about accessing Mythos are still at an earlier stage.

CNBC Technology
May 11, 2026

This blog discussion explores steganography (hiding secret messages within other content) involving LLMs through techniques like white text on white backgrounds and deliberately misspelling words to confuse AI models. Commenters note that LLMs handle these obfuscation attempts easily, and discuss broader steganography methods including TEMPEST (electromagnetic emissions security), with mention that modern software-defined radios (SDRs, affordable radio receivers programmable via software) have made older defensive techniques less effective.

Schneier on Security
May 11, 2026

AI security is currently focused on posture-based controls (checking configurations, access rules, and input filters), similar to how endpoint security relied on antivirus signatures in the early 2000s, but this approach is incomplete because the AI attack surface is expanding faster than teams can secure it. The article argues that organizations need to shift toward behavior-based detection, which monitors what AI systems actually do (API calls, data retrieval, system actions) rather than just checking if security policies are in place, because the blast radius of a compromised AI agent affects multiple systems downstream.

CSO Online
OpenAI Blog
May 11, 2026

This article discusses how security leaders should prepare their teams for agentic AI (AI systems that can autonomously perform tasks), emphasizing that it will become essential as cyber attackers increasingly use AI at machine speed. Key principles include having leaders embrace agentic AI adoption through hands-on experimentation and training, setting organizational culture around rapid iteration, and addressing staff resistance to the technology shift.

CSO Online
CSO Online

Fix: Access to the malicious model has since been disabled by Hugging Face.

The Hacker News
OpenAI Blog
BleepingComputer

Fix: Update to Ollama version 0.17.1 or later. Additionally, the source recommends: limit network access to Ollama instances, audit running instances for internet exposure, isolate and secure them behind a firewall, and deploy an authentication proxy or API gateway in front of all Ollama instances since the REST API does not provide authentication by default.

The Hacker News
The Guardian Technology

Fix: Users who downloaded files from the malicious repository are advised to reimage the machine (completely reinstall the operating system), rotate all stored credentials, replace cryptocurrency wallets and seed phrases, and invalidate browser sessions and tokens.

BleepingComputer
MIT Technology Review
Simon Willison's Weblog
May 8, 2026

AI models can now autonomously discover zero-day vulnerabilities (previously unknown security flaws), create working exploits, and combine multiple weaknesses together, making vulnerabilities appear faster and get exploited more quickly than before. Organizations need to respond by acting faster to identify and fix vulnerabilities, and by having complete visibility across their entire environment (cloud systems, code, infrastructure, and software supply chain). The framework recommends reducing unnecessary exposure, prioritizing what can actually be exploited, patching quickly, and using AI-driven scanning to continuously validate every exposed system.

Fix: The source recommends a four-pillar framework but does not describe explicit fixes or patches. The closest guidance is: 'organizations need to move faster in how they assess exposure, prioritize what matters, and remediate issues before they can be exploited,' and 'scan every exposure with AI' to 'continuously scan every exposure, determine whether it can be exploited.' The source also cites the Firefox team as an example: 'after scanning with Mythos, the Firefox team fixed more security bugs in April than they had in the entire previous year.' However, no specific software update, patch version, or concrete mitigation technique is provided in the text.

Wiz Research Blog
May 8, 2026

Anthropic released Mythos, an AI model that can find thousands of previously unknown software vulnerabilities (flaws in code that haven't been patched yet), which sparked concern among banks, governments, and tech companies about a new wave of AI-enabled cyberattacks. However, cybersecurity experts say this vulnerability-finding capability already exists in older, publicly available AI models from Anthropic and OpenAI, and can be achieved through orchestration (coordinating multiple tools or models to work together on a task).

CNBC Technology
The Verge (AI)
The Verge (AI)
The Verge (AI)