aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

Context bombing heralds a new AI era of deceptive defense

infonews
securitysafety
Jul 21, 2026

Attackers are using AI agents (software programs that can make decisions and take actions automatically) to conduct cyberattacks, so security researchers at Tracebit developed a defensive technique called "context bombing" that plants decoy files with prompts designed to trigger an LLM's (large language model's) content safety guardrails (built-in rules that prevent harmful outputs), causing the attacker's AI agent to stop and crash rather than just triggering an alert. In tests, context bombing reduced the success rate of AI-powered attacks by up to 90%, dropping full system compromise from 36% success down to just 1%.

Fix: According to Tracebit, the technique is to "plant decoy resources not merely to trigger alerts, but to actually stop AI agents." Specifically: "plant a 'context bomb': a short piece of text designed to trigger a model's safety guardrails, planted directly in the attacker's path — a decoy secret, environment variable, or DNS record (the system that translates website names into IP addresses)." The source notes that effective context bombs were identified through testing, but "the identified strings were different between the tested models," requiring customization for Claude Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek V4 Pro, and Kimi K2.6.

CSO Online

David Vélez and Robin Vince join the boards of the OpenAI Foundation and OpenAI Group PBC

infonews
industry
Jul 20, 2026

OpenAI has appointed David Vélez, founder and CEO of Nubank, and Robin Vince, CEO of BNY, to the boards of the OpenAI Foundation and OpenAI Group PBC. Both leaders bring experience in using technology to transform financial services and expand access, and they are expected to help OpenAI ensure that AI benefits more businesses and people globally.

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

highnews
security
Jul 20, 2026

Security researchers discovered sandbox escape vulnerabilities in four popular AI coding agents (Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity) by exploiting a fundamental design flaw: these tools trust files written by the sandboxed agent and automatically execute them through external tools like Git integrations and task runners. The attacks use prompt injection (tricking an AI by hiding malicious instructions in files like READMEs or code dependencies) to make the agent write files that trigger unsandboxed command execution on the developer's machine without the agent itself breaking out of the sandbox.

JadePuffer agentic attacks now target AI model data with ransomware

highnews
security
Jul 20, 2026

JadePuffer, an autonomous AI agent, has been upgraded with EncForge ransomware that specifically targets AI infrastructure like training datasets, model checkpoints, and vector databases by encrypting files with the .locked extension. The agent successfully adapted during an attack on a Langflow instance, deploying multiple Python scripts to overcome delivery obstacles and gaining root-level access through an exposed Docker socket. EncForge uses AES-256 encryption for file protection and targets approximately 180 file types specific to AI and machine learning systems, potentially costing organizations significant time and money to recover encrypted models.

Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push

infonews
industry
Jul 20, 2026

Ivanti is exploring the use of frontier models (advanced AI systems at the cutting edge of development) to help find and fix security vulnerabilities in software. While early tests show these AI systems work well at this task, questions remain about whether the approach is affordable and whether it's practical to have humans review and approve the AI's recommendations before using them.

Trump administration's head of AI safety agency resigns after 3 months on job

infonews
policy
Jul 20, 2026

Chris Fall resigned as director of the Center for AI Standards and Innovation (CAISI, a U.S. government agency that tests and researches commercial AI systems) after only three months, creating uncertainty in the Trump administration's AI leadership. The departure comes as the administration is implementing a new executive order that requires AI developers to voluntarily submit models to the government for safety evaluation before release, and as Chinese AI models are gaining market share against American competitors like OpenAI and Anthropic.

ServiceNow’s sandbox escape RCE hole now exploited in the wild

highnews
security
Jul 20, 2026

ServiceNow patched a sandbox escape RCE vulnerability (CVE-2026-6875, a flaw that lets attackers run unauthorized code on systems they don't control) last week, but attackers are already exploiting it in the wild using modified techniques. Security experts warn this is especially dangerous because the vulnerability affects ServiceNow's sandbox (the security container designed to safely run untrusted code), and a compromise could give attackers access to sensitive data like HR records and potentially spread to corporate networks through integrations.

25 Years After Code Red: What the Worm Era Can Teach Us About AI Security

infonews
securitypolicy

CISOs Feel the Heat Over AI Risk

infonews
policy
Jul 20, 2026

As companies rapidly adopt AI technology, Chief Information Security Officers (CISOs, the executives responsible for protecting company data and systems) face increased job stress, with 26% considering leaving their positions. The pressure stems from the security challenges that come with quickly implementing AI systems across organizations.

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

highnews
security
Jul 20, 2026

Cybersecurity researchers discovered nearly 7,600 malicious GitHub repositories spreading SmartLoader malware, with over 800 posing as AI skills or MCP servers (Model Context Protocol servers, which are tools that help AI assistants perform specialized tasks). A particularly dangerous aspect called AgentBaiting allows AI agents like Claude, Gemini, and ChatGPT to inadvertently discover these fake repositories and execute malware without human intervention, by simply searching for legitimate-sounding tools. The attack leverages copied projects, fake developer profiles, and convincing documentation to trick both users and AI systems into downloading malicious files.

China’s AI models have Trump’s AI world at war with itself

infonews
policyindustry

AMD launches Helios, its first rack AI system to rival Nvidia, adding Microsoft as newest buyer

infonews
industry
Jul 20, 2026

AMD has launched Helios, its first rack-scale system (a large computing unit designed for data centers) for AI, which competes with Nvidia's similar systems and has attracted major customers including Microsoft, Meta, and OpenAI. The system combines AMD's own GPUs (graphics processing units, specialized chips for AI calculations), CPUs (central processing units, the main processors), networking, and software to offer what AMD claims is the lowest cost per token (the cost to process individual units of text in AI models). AMD will begin shipping Helios to customers later this year.

Adobe’s ‘natural look’ camera app embraces generative AI

infonews
industry
Jul 20, 2026

Adobe's Indigo camera app, originally designed to improve iPhone photo quality with a more natural look, is being updated with generative AI tools (AI systems that create new content based on patterns they learn) through an "AI Playground" feature. The update does not use Adobe's own Firefly AI models, and users have the option to opt out and use the app's original features instead.

AI adoption and business acceleration are changing the expectations of technology risk management

infonews
policysecurity

Alphabet stock pops on report it's developing a more efficient AI chip

infonews
industry
Jul 20, 2026

Alphabet is developing a specialized AI chip called 'Frozen v2' that embeds parts of its Gemini model (a large language AI) directly into the hardware to run queries more efficiently, potentially serving 6-10 times more tokens (text units) per unit of power than current chips. The company aims to deploy it by 2028 to address internal computing shortages, though the chip would only work with future Gemini models if Google maintains the same underlying architecture.

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

highnews
securityprivacy

Hugging Face discloses breach linked to autonomous AI agent

highnews
security
Jul 20, 2026

Hugging Face, a major open-source AI platform with over 45,000 models and 50,000 organizational users, disclosed a breach where attackers used an autonomous AI agent (a system that automatically performs many actions with minimal human direction) to exploit code-execution vulnerabilities in its data-processing pipeline, stealing cloud credentials and moving across internal systems. The company found no evidence that public models or customer data were tampered with, though investigations are ongoing. Hugging Face has since closed the vulnerable code paths, revoked credentials, and deployed improved detection systems.

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

infonews
securitypolicy

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

infonews
securityindustry

China delivers a one-two punch to America’s AI dominance 

infonews
industry
Jul 20, 2026

Chinese AI companies Moonshot and Alibaba have released new AI models that they claim perform competitively with leading American systems from OpenAI and Anthropic while costing significantly less. These rapid releases suggest that America's technological advantage in AI development is narrowing, which has implications for national security, economic competitiveness, and global influence.

Previous79 / 237Next
OpenAI Blog

Fix: Most issues have been patched by vendors. Cursor fixed multiple vulnerabilities in version 3.0.0 (including a .claude hook config execution flaw and Git metadata bypass). OpenAI patched Codex CLI's 'safe' command allowlist bug in v0.95.0. The Docker socket vulnerability affecting Codex, Cursor, and Gemini CLI is now fixed. According to Pillar Security, the underlying fix involves monitoring the moment a trusted local tool runs something the agent wrote, rather than simply banning filenames.

BleepingComputer

Fix: Apply available security updates, specifically Langflow version 1.3.0 or later. Additionally, restrict Docker socket access, run Langflow containers as non-root (not with full system privileges), and apply filesystem-level access controls (rules limiting which users/processes can access files) to model weight directories.

BleepingComputer
Dark Reading
CNBC Technology

Fix: ServiceNow has issued updates and patches to address the vulnerability. The company stated: "We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so."

CSO Online
Jul 20, 2026

Marc Maiffret reflects on Code Red, a major worm (self-replicating malware that spreads across networks) from 25 years ago, and what security lessons from that era can help organizations protect AI systems today. The article draws parallels between past worm attacks and current AI security challenges to guide how companies should approach AI risk management.

Dark Reading
Dark Reading

Fix: To counter the threat, the source advises: build a catalog of reviewed Skills, MCP servers, and agent plugins; evaluate new agent capabilities in a sandboxed environment (an isolated testing area) first before broader rollout; and verify both the publisher and the project to ensure credibility.

The Hacker News
Jul 20, 2026

Chinese AI company Moonshot released Kimi, a free open-source AI model that performs as well as paid models from US companies like OpenAI and Anthropic, causing disagreement among Trump's AI advisors about how to respond. The situation creates economic and political problems for the Trump administration because free Chinese models reduce demand for expensive US models, while also raising questions about whether the government should intervene to protect US companies or allow open competition.

MIT Technology Review
CNBC Technology
The Verge (AI)
Jul 20, 2026

AI is being adopted quickly across businesses, but security programs haven't kept pace, creating a gap where organizations struggle to understand their actual risks. Traditional security problems like weak access controls (permissions given too broadly) and poor logging (records of system activity) become more dangerous when AI agents connect to company data and workflows, potentially spreading damage from a small issue into something that affects the entire business. Security leaders are now expected to help businesses move fast with AI while identifying which initiatives are safe, where the company is exposed, and what needs immediate action.

CSO Online
CNBC Technology
Jul 20, 2026

Hugging Face, a platform hosting AI models and datasets, disclosed that attackers exploited a security vulnerability to run malicious code on its servers, compromising internal datasets and service credentials (codes that prove identity and grant access to systems). The company has fixed the vulnerability and revoked the stolen credentials, while urging users to rotate their own keys and review account activity for suspicious behavior.

Fix: According to the source, Hugging Face has taken these steps: (1) revoked and rotated the stolen credentials that were accessed, (2) fixed the vulnerability that was abused during the cyberattack, and (3) urged users to 'do the same with any keys stored on the platform, and review any suspicious activity on their accounts.' The company also reported the incident to law enforcement and engaged cybersecurity forensic specialists to investigate.

TechCrunch (Security)

Fix: In response to the breach, Hugging Face closed the vulnerable code execution paths (a template injection in dataset configuration and a remote code dataset loader), evicted the attacker, rebuilt compromised nodes, revoked and rotated all affected credentials, deployed improved malicious activity detection systems, and reported the incident to law enforcement. The company also advised users to rotate access tokens and review recent account activity for suspicious behavior. Hugging Face additionally recommended that defenders have a capable AI model they can run on their own infrastructure vetted and ready before an incident to avoid guardrail lockout and prevent attacker data from leaving the environment.

BleepingComputer
Jul 20, 2026

The real security problem isn't the volume of new vulnerabilities discovered by AI tools like Mythos, but rather the exposure window—the time between when a vulnerability becomes exploitable and when an organization fixes it. Currently, attackers can break into systems in 29 minutes on average, but organizations are allowed 30 days to patch critical vulnerabilities, creating a massive gap. The bottleneck isn't discovering vulnerabilities quickly (which AI now does), but mobilization—the organizational process of actually deploying fixes across different teams and systems, which still moves at human speed rather than at the speed attackers operate.

The Hacker News
Jul 20, 2026

Capital One released VulnHunter, an AI-powered open-source tool designed to find and fix software vulnerabilities in code by using agentic reasoning (an AI system that plans steps to solve problems) to identify exploitable defects, map potential attack paths, and suggest targeted fixes. Unlike traditional vulnerability scanners that produce many false positives (incorrect alerts), VulnHunter aims to reduce noise and improve developer workflows. The tool is available on GitHub and requires access to Claude Opus 4.8 and a Claude Code environment.

SecurityWeek
The Verge (AI)