aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4769 items

Curity looks to reinvent IAM with runtime authorization for AI agents

infonews
securitypolicy
Apr 14, 2026

Traditional identity and access management (IAM) tools, which control who can access systems and resources, were not designed to secure AI agents (autonomous software programs that perform tasks independently), which operate at high speed with unpredictable access patterns. Curity announced Access Intelligence, a new security layer that grants agent permissions at runtime (during execution, not beforehand) and uses OAuth tokens (credentials that allow access to specific resources) to carry information about each agent's purpose, ensuring agents can only access resources matching their intended task.

CSO Online

April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs

infonews
security
Apr 14, 2026

April's Patch Tuesday includes 167 security updates, with three particularly critical issues: a zero day (actively exploited vulnerability) in Microsoft SharePoint that allows attackers to spoof (impersonate) the service and access sensitive data, a critical SQL injection vulnerability (a type of attack where malicious code is inserted into database queries) in a SAP product, and a 9.8 CVSS score (a 0-10 severity rating) vulnerability in Windows Internet Key Exchange (IKE, a protocol for secure communications) that could let attackers run remote code. Security teams are urged to prioritize patching these actively exploited flaws in widely-used applications rather than relying solely on severity scores.

Secure AI agent access patterns to AWS resources using Model Context Protocol

infonews
securitypolicy

5 trends defining the future of AI-powered cybersecurity

infonews
securityindustry

In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy

infonews
securitypolicy

Anthropic co-founder confirms the company briefed the Trump administration on Mythos

infonews
policyindustry

The attacks on Sam Altman are a warning for the AI world

infonews
safetypolicy

DA wants Sam Altman arson suspect Daniel Moreno-Gama held without bail

infonews
security
Apr 14, 2026

A 20-year-old man was arrested for allegedly throwing a Molotov cocktail (an improvised incendiary weapon) at OpenAI CEO Sam Altman's home and threatening to burn down OpenAI's headquarters because of his opposition to AI technology. The suspect possessed a document listing names and addresses of other AI executives and warned of humanity's extinction from AI, leading prosecutors to request he be held without bail due to public safety concerns.

Chrome now lets you turn AI prompts into repeatable ‘Skills’

infonews
industry
Apr 14, 2026

Google is adding a new feature to Chrome called 'Skills' that lets you save your favorite Gemini prompts (instructions you give to AI) and reuse them across different webpages with a single click, instead of typing the same prompt repeatedly. This saves time when you want to perform the same AI task, like asking for vegan recipe substitutions, on multiple pages.

EU regulators largely denied access to Anthropic Mythos

infonews
policysecurity

Has Google’s AI watermarking system been reverse-engineered?

infonews
security
Apr 14, 2026

A developer claims to have reverse-engineered Google DeepMind's SynthID system, which is a watermarking technology that embeds hidden marks in AI-generated images to prove their origin. The developer says they can strip these watermarks from images or add fake ones, though Google disputes this claim.

‘Mythos-Ready’ Security: CSA Urges CISOs to Prepare for Accelerated AI Threats

infonews
securitysafety

AI companies make powerful tech – but they’re also savvy marketers

infonews
industry
Apr 14, 2026

This article discusses how AI companies like Anthropic use marketing to promote their capabilities, using Claude as an example of technology that may be overhyped despite being genuinely advanced. The piece cautions readers against getting swept up in marketing claims about AI's power without critical evaluation.

How AI is transforming threat detection

infonews
industry
Apr 14, 2026

AI is transforming threat detection by processing massive amounts of security data and identifying suspicious patterns faster than humans alone, with 50% of threat detection platforms expected to use agentic AI (AI systems that can take independent actions) by 2028. Organizations are already automating routine tasks like alert review and investigation work, seeing 40-50% efficiency gains for lower-level security operations, while AI agents reduce alert fatigue by clustering similar alerts and prioritizing them based on risk.

The AI inflection point: What security leaders must do now

infonews
securityindustry

Man charged with attempted murder over attack on home of OpenAI's Sam Altman

infonews
security
Apr 13, 2026

A 20-year-old Texas man has been charged with attempted murder and federal felony charges after allegedly throwing a Molotov cocktail (a homemade incendiary weapon) at OpenAI CEO Sam Altman's San Francisco home and attempting to set fire to OpenAI's headquarters. Authorities found the suspect carrying documents that opposed AI development and called for violence against AI executives and investors. OpenAI and law enforcement officials condemned the violence, with OpenAI calling for debate through democratic processes rather than violence.

Daniel Moreno-Gama is facing federal charges for attacking Sam Altman’s home and OpenAI’s HQ

infonews
security
Apr 13, 2026

Daniel Moreno-Gama was arrested and charged with federal crimes after traveling from Texas to California and attacking OpenAI's facilities and CEO Sam Altman's home with a Molotov cocktail (an incendiary weapon made from a bottle of flammable liquid). He also attempted to break into OpenAI's headquarters and stated he intended to burn down the building and kill people inside. His charges include attempted destruction of property using explosives and illegal possession of a firearm.

Trusted access for the next era of cyber defense

infonews
securitypolicy

Texas man accused of throwing molotov cocktail at Sam Altman home charged

infonews
security
Apr 13, 2026

A 20-year-old Texas man was arrested after throwing an incendiary device (a weapon designed to start fires) at OpenAI CEO Sam Altman's home and attempting to set fire to OpenAI's headquarters in San Francisco. Police found the suspect with an anti-AI document containing threats against Altman, multiple incendiary devices, and other materials, leading federal prosecutors to investigate whether this constitutes an act of domestic terrorism.

Anthropic’s Mythos signals a structural cybersecurity shift

infonews
securitysafety
Previous164 / 239Next

Fix: For the Windows IKE vulnerability (CVE-2026-33824), Microsoft recommends two temporary mitigations for admins who cannot immediately install the security update: (1) block inbound traffic on UDP ports 500 and 4500 for systems that do not use IKE, or (2) for systems that require IKE, configure firewall rules to allow inbound traffic on UDP ports 500 and 4500 only from known peer addresses. Microsoft notes these actions reduce attack surface but do not replace installing the security update. For SharePoint and other vulnerabilities, the source text does not explicitly describe mitigation steps beyond applying the patches.

CSO Online
Apr 14, 2026

AI agents access AWS resources through the Model Context Protocol (MCP, a system that lets AI tools interact with cloud services), but unlike traditional software with predictable behavior, agents can dynamically choose different actions based on context. The main security risk is that agents operate at machine speed and will use any permissions (IAM roles, API keys, or OAuth scopes) they're granted, so misconfigured access controls can cause large-scale damage quickly. The source recommends three security principles for controlling AI agent access to AWS resources, with an emphasis on using MCP servers rather than direct API access because MCP provides better monitoring and control.

Fix: The source recommends architecting agents to use MCP servers rather than direct service access where possible, because MCP servers provide a layer of abstraction that enables differentiation controls and creates additional monitoring capabilities through AWS CloudTrail. For agents on developer machines, developers should configure which AWS credentials the agent uses in their mcp.json file by specifying a named profile (which can use credential helpers and the credential provider chain for short-lived credentials), environment variables, or explicit credential configuration, rather than allowing agents to inherit broad developer admin credentials.

AWS Security Blog
Apr 14, 2026

AI is transforming cybersecurity by becoming both a tool for attackers and defenders, forcing organizations to shift from outdated perimeter-based security (the "castle and moat" approach) to continuous cyber resilience (the ability to detect threats in real-time and keep operations running during attacks). The industry is consolidating toward unified security platforms, automating repetitive analyst tasks to reduce burnout, and facing increasing regulatory pressure to demonstrate resilience and rapid recovery capabilities.

CSO Online
Apr 14, 2026

OpenAI announced GPT-5.4-Cyber, a new AI model designed specifically for cybersecurity professionals, along with a three-part strategy to manage risks as AI becomes more powerful. The announcement comes after competitor Anthropic released a more limited version of its Claude Mythos model, citing concerns that advanced AI could be exploited by attackers, though OpenAI argues that current safeguards are sufficient for broad deployment of today's models.

Fix: OpenAI's strategy includes three components: (1) 'know your customer' validation systems combined with Trusted Access for Cyber (TAC), an automated system introduced in February that allows controlled access to new models; (2) iterative deployment, a careful process of releasing and refining capabilities while monitoring for resilience to jailbreaks (techniques that trick AI into ignoring its safety guidelines) and other adversarial attacks; and (3) investments supporting software security and digital defense, including the Codex Security application security AI agent, a cybersecurity grants program begun in 2023, a donation to the Linux Foundation for open source security, and the Preparedness Framework designed to assess and defend against severe harm from advanced AI capabilities.

Wired (Security)
Apr 14, 2026

Anthropic confirmed it briefed the Trump administration about its new Mythos model, an AI system so dangerous it won't be released publicly due to powerful cybersecurity capabilities. The company is engaging with the government on AI safety issues while simultaneously suing the Department of Defense over a supply-chain risk label and disagreement over military access to Anthropic's systems.

TechCrunch (Security)
Apr 14, 2026

Recent physical attacks targeting AI industry leaders, including an alleged Molotov cocktail attack on OpenAI CEO Sam Altman's home and gunfire at an official who supported a data center project, have raised concerns about safety in the AI industry. These incidents appear connected to activist concerns about AI's risks, including extinction fears and opposition to infrastructure expansion.

The Verge (AI)
CNBC Technology
The Verge (AI)
Apr 14, 2026

Anthropic's new Mythos model is an AI designed for cybersecurity that can identify and exploit technical vulnerabilities better than most humans, but European regulators have been largely denied early access to it. The company limited initial access through Project Glasswing to a few US tech companies like Apple, Microsoft, and Amazon for security reasons, while most EU countries were excluded. European officials worry that private companies controlling access to such powerful technology raises concerns about national security and who should have influence over these systems.

CSO Online
The Verge (AI)
Apr 14, 2026

AI models like Mythos are making cyberattacks faster and more dangerous by shortening the time between when security flaws are discovered and when attackers exploit them. Security leaders (CISOs, chief information security officers) need to prepare urgently for this new threat environment where attacks happen at high speed.

SecurityWeek
The Guardian Technology
CSO Online
Apr 14, 2026

AI is moving from experimentation to production deployment in cybersecurity, and security leaders must treat it as a fundamental shift in how security operations work, not just an added tool. Attackers are using AI to conduct faster intrusions (some occurring in under 30 seconds), which exceeds the speed of human-only security responses, making AI deployment urgent for defenders. There is currently a limited window where defenders and attackers have roughly equal access to AI technology, but advantage will go to those who operationalize it most effectively and quickly.

CSO Online
BBC Technology
The Verge (AI)
Apr 13, 2026

OpenAI is expanding its Trusted Access for Cyber (TAC) program to provide AI tools to thousands of cybersecurity defenders and teams protecting critical software. The company has created GPT-5.4-Cyber, a specialized version of its AI model designed specifically for defensive cybersecurity work, and is implementing cyber-specific safeguards (built-in restrictions to prevent misuse) in model deployments. This effort aims to help defenders find and fix security vulnerabilities faster while preventing attackers from misusing the same AI capabilities.

Fix: The source explicitly mentions the following measures: cyber-specific safeguards included in model deployments starting in 2025; the Preparedness Framework (strengthened in 2023); identity verification and KYC (know-your-customer, a process to confirm who someone is) to control access to advanced capabilities; Codex Security tool to identify and fix vulnerabilities at scale; iterative deployment with continuous updates to models and safety systems based on learning about capabilities and risks; and improvements in resilience to jailbreaks (techniques that try to bypass AI safety restrictions) and other adversarial attacks.

OpenAI Blog
The Guardian Technology
Apr 13, 2026

Anthropic's Mythos is an AI system that can autonomously find and exploit vulnerabilities (security flaws in software) much faster than before, completing tasks in hours that previously took weeks or months. Security experts warn this represents a fundamental shift in cybersecurity, not an isolated incident, and that defenders must close the gap between how quickly vulnerabilities are discovered and how quickly organizations can patch and respond.

Fix: The AI Security Institute recommends that organizations strengthen security fundamentals by: regularly applying security updates, implementing robust access controls, securing security configuration, and maintaining comprehensive logging. The source also emphasizes that investment in cyber defense is vital now, before future AI models become even more capable.

CSO Online