aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDataset
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
1237 items

What are the types of ransomware attacks?

infonews
security
Feb 24, 2026

Ransomware is a type of malware that cybercriminals use in different ways to extort money from victims, including crypto ransomware (which encrypts data), double extortion (which steals and threatens to leak data), locker ransomware (which blocks system access), and others. The source explains how different ransomware strains work and that crypto ransomware is the most common type because it combines encryption with pressure on victims to pay. Detection methods include behavior analysis (watching how files act suspiciously), signature-based detection (identifying known ransomware code patterns), heuristic analysis (finding new or modified threats), and deception technology (using fake files as bait to catch ransomware early).

Fix: A layered approach that includes behavior analysis, signature-based detection, heuristic analysis, and deception technology is described as 'the best way to defend against ransomware' to protect against both known and unknown threats.

CSO Online

Take control: Locking down common endpoint vulnerabilities

infonews
security
Feb 24, 2026

Endpoints (network-connected devices like laptops and servers) face common vulnerabilities that attackers exploit, particularly exposed Remote Desktop Protocol (RDP, a tool for remote access) which allows brute force attacks on passwords, and phishing emails that trick users into revealing credentials or installing malware. Both threats are preventable with proper security practices.

Anthropic won’t budge as Pentagon escalates AI dispute

inforegulatory
policyindustry

Anthropic faces Friday deadline in Defense AI clash with Hegseth

inforegulatory
policy
Feb 24, 2026

Defense Secretary Pete Hegseth has given Anthropic (an AI company that develops Claude models) until Friday to allow the military broad access to its AI systems, threatening to label the company a 'supply chain risk' (a designation that would require DoD vendors to stop using Anthropic's products) or invoke the Defense Production Act (a law allowing the president to control domestic industries for national security) if it refuses. Anthropic wants safeguards preventing its models from being used for autonomous weapons or mass surveillance, while the DoD wants unrestricted access to 'all lawful use cases' without limitations.

Why AMD's megadeal with Meta shows Nvidia is still the best game in town

infonews
industry
Feb 24, 2026

N/A -- This content is a footer/navigation page from CNBC with no substantive article text about AMD, Meta, Nvidia, or any AI/LLM-related technical issue. The provided material contains only website metadata, subscription prompts, and legal information.

Cursor announces major update to AI agents as coding tool battle heats up

infonews
industry
Feb 24, 2026

Cursor, an AI coding tool startup, announced updates to its AI agents (software that can complete tasks automatically on a user's behalf) that allow them to test changes, run multiple tasks in parallel on cloud-based virtual machines (remote computers), and work across different platforms like Slack and GitHub. The update aims to help Cursor compete with rivals like OpenAI and Anthropic in the rapidly growing market for AI-powered coding assistants.

RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN

highnews
securitysafety

OpenAI COO says ‘we have not yet really seen AI penetrate enterprise business processes’

infonews
industry
Feb 24, 2026

OpenAI's COO Brad Lightcap stated that AI has not yet been widely adopted into enterprise business processes at scale, despite powerful AI systems being available to individual users. To address this, OpenAI launched a new platform called OpenAI Frontier, which allows enterprises to build and manage agents (AI systems that can perform tasks autonomously) and helps complex organizations integrate AI into their workflows by measuring success through business outcomes rather than just user seat licenses.

Microsoft adds Copilot data controls to all storage locations

infonews
securityprivacy

Software stocks rebound as Anthropic announces new partnerships

infonews
industry
Feb 24, 2026

Anthropic announced new partnerships and updates to Claude (its AI assistant), allowing companies to integrate it into enterprise software tools like Slack, Gmail, and Salesforce. This announcement reassured investors that AI won't completely replace existing software systems, causing software and cybersecurity stocks to rebound after recent declines driven by fears that AI tools could disrupt traditional software businesses.

Anthropic’s Claude Cowork is plugging AI into more boring enterprise stuff

infonews
industry
Feb 24, 2026

Anthropic announced updates to Claude Cowork, an AI tool that helps with office tasks, allowing it to connect with popular apps like Google Workspace, Docusign, and WordPress through new plug-ins. These plug-ins can automate work across different fields such as HR, design, and finance, and Claude can now handle multi-step tasks across Excel and PowerPoint by passing context between the two applications.

Oura launches a proprietary AI model focused on women’s health

infonews
industry
Feb 24, 2026

Oura, a health tracking company, released a custom AI model designed specifically for women's health questions, powering its chatbot called Oura Advisor. The model uses established medical research reviewed by doctors and combines it with users' biometric data (measurements like heart rate and sleep patterns) to provide personalized guidance on topics like menstrual cycles and menopause. The company emphasizes the model is hosted on its own servers and designed to be supportive rather than replace actual medical doctors.

Identity-First AI Security: Why CISOs Must Add Intent to the Equation

infonews
securitypolicy

Anthropic launches new push for enterprise agents with plugins for finance, engineering, and design

infonews
industry
Feb 24, 2026

Anthropic announced a new enterprise agents program that lets companies deploy pre-built AI agents (software programs that can perform tasks autonomously) to handle common business work like financial research and HR tasks. The program includes a plugin system, pre-made agents for specific departments, and integrations with tools like Gmail and DocuSign, along with controls that corporate IT departments need for managing software safely.

Anthropic updates Claude Cowork tool built to give the average office worker a productivity boost

infonews
industry
Feb 24, 2026

Anthropic has released new connectors and plugins for Claude Cowork, its AI productivity tool for office workers, allowing organizations to integrate it with existing software like Google Drive and Gmail. The update marks Claude Cowork's transition from a research project to an enterprise-grade product, with customizable plugins designed to encode institutional knowledge and workflows across different business domains.

How Claude Code Claude Codes

infonews
industry
Feb 24, 2026

Claude Code is a developer tool created by Anthropic that has unexpectedly become popular with non-developers across various industries who have learned to access their terminal (the text-based interface for giving computer commands) to build projects. The tool has achieved significant product-market fit (strong demand and adoption), though the article questions whether users will eventually move beyond using the terminal interface.

New Relic launches new AI agent platform and OpenTelemetry tools

infonews
industry
Feb 24, 2026

New Relic launched a no-code AI agent platform designed specifically for data observability, allowing companies to deploy and manage AI agents that monitor data systems to catch bugs before they cause problems. The platform supports the model context protocol (MCP, a system that connects AI applications to external data sources) and integrates with other New Relic tools. The company also released new tools for OpenTelemetry (OTel, an open-source observability framework that helps track how software performs), allowing enterprises to manage OTel data streams alongside other data sources in a single place to reduce fragmentation problems.

This Chainsmokers-approved AI music producer is joining Google

infonews
industry
Feb 24, 2026

ProducerAI, an AI platform that helps musicians generate sounds, create lyrics, and remix songs using artificial intelligence, is being acquired by Google and will be integrated into Google Labs. The platform will now use Google's new Lyria 3 music-making AI model instead of its original AI system.

New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM

criticalnews
security
Feb 24, 2026

A new supply chain attack called 'Sandworm_Mode' has been discovered in NPM (Node Package Manager, a repository where developers download code libraries). The malicious code spreads automatically like a worm, corrupts AI assistants that might use the infected code, steals sensitive information, and includes a destructive mechanism that can cause damage when activated.

Nimble raises $47M to give AI agents access to real-time web data

infonews
industry
Feb 24, 2026

Nimble, a startup that raised $47 million in funding, has developed a platform using AI agents to search the web in real time, validate results, and structure them into organized tables that work like databases. The company addresses a key problem with AI agents: while they can search and analyze web data, they often return plain text results and suffer from hallucinations (when an AI confidently produces false information), making it difficult for enterprises to use web data reliably alongside their existing data systems.

Previous33 / 62Next

Fix: For RDP vulnerabilities: don't expose RDP to the public internet unless necessary, restrict admin rights, enforce multi-factor authentication (MFA, a security method requiring multiple forms of verification) for RDP sessions, apply Windows security configurations beyond defaults, and monitor for suspicious logins. For phishing attacks: conduct regularly scheduled security awareness training (SAT) to help users recognize malicious emails, use MFA to reduce damage if credentials are compromised, and don't respond directly to suspicious sender emails.

CSO Online
Feb 24, 2026

Anthropic, an AI company, is refusing to give the U.S. military unrestricted access to its AI model because of concerns about mass surveillance and autonomous weapons, despite the Pentagon threatening to declare the company a "supply chain risk" (a serious designation usually reserved for foreign adversaries) or invoke the Defense Production Act (a law giving the president power to force companies to prioritize production for national defense). The dispute highlights tension between corporate AI safety policies and government demands for military access, with experts warning that using these extreme measures could signal the U.S. is becoming unstable for business.

TechCrunch
CNBC Technology
CNBC Technology
CNBC Technology
Feb 24, 2026

A vulnerability called RoguePilot in GitHub Codespaces allowed attackers to inject hidden malicious instructions into GitHub issues, which GitHub Copilot (an AI code assistant) would automatically execute when a developer opened a Codespace from that issue, potentially leaking the GITHUB_TOKEN (a credential that grants access to repositories). The flaw is an example of prompt injection (tricking an AI by hiding instructions in its input), and attackers could hide their malicious prompts using HTML comments to avoid detection.

Fix: The vulnerability has since been patched by Microsoft following responsible disclosure.

The Hacker News
TechCrunch
Feb 24, 2026

Microsoft is expanding data loss prevention (DLP, rules that block AI from accessing sensitive documents) controls to protect files stored on local devices, not just in cloud storage like SharePoint or OneDrive. The change, rolling out between March and April 2026, will prevent the Microsoft 365 Copilot AI assistant from reading or processing documents marked as confidential. This update addresses a recent bug where Copilot Chat accidentally read confidential emails despite DLP protections being active.

Fix: Microsoft will deploy the enhancement through the Augmentation Loop (AugLoop, an Office component that helps Copilot access documents) between late March and late April 2026. The fix enables Office clients to provide sensitivity labels directly to AugLoop rather than requiring a call to Microsoft Graph using file URLs, allowing DLP enforcement to apply uniformly across all storage locations, including local files. Organizations with DLP policies already configured to block Copilot from processing sensitivity-labeled content will have this protection automatically enabled without requiring administrative action or changes.

BleepingComputer
CNBC Technology
The Verge (AI)
TechCrunch
Feb 24, 2026

AI agents in enterprises now perform critical operations like provisioning infrastructure and approving transactions, but they are often not governed as distinct identities—instead inheriting broad privileges from their creators. Traditional identity and access management (IAM, the systems that control who can access what) is insufficient because AI agents are dynamic and can take unpredictable paths to achieve their goals, so a new approach called intent-based permissioning is needed, which checks not just who the agent is but why it is requesting access and whether that purpose justifies the action at that moment.

BleepingComputer
TechCrunch
CNBC Technology
The Verge (AI)
TechCrunch
The Verge (AI)
SecurityWeek
TechCrunch