aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

7 skills and traits of elite security engineers

infonews
securityindustry
Jul 15, 2026

Security engineers design and deploy systems to protect organizations from cyber threats, and their role is evolving due to AI. Elite security engineers need skills in using AI-powered tools (software that uses machine learning to automate security tasks), understanding AI-related threats like prompt injection (tricking an AI by hiding instructions in its input) and model poisoning (corrupting training data to make AI systems malfunction), and balancing security with business performance goals. As AI automates detection and vulnerability scanning work, security engineers are shifting from responding to incidents toward interpreting AI findings and deciding on appropriate responses.

CSO Online

Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug

infonews
security
Jul 14, 2026

Microsoft released a record 569 patches in a single month, with 59 rated as critical, partly because AI models can now help discover vulnerabilities faster. The company is recommending that customers speed up their patching schedules to address critical flaws more quickly. Separately, SAP patched a critical memory corruption bug with a CVSS score (a 0-10 rating of how severe a vulnerability is) of 9.9.

Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal

infonews
security
Jul 14, 2026

Cribl acquired CardinalOps to help security operations teams map their detection rules (the specific checks that catch attacks) to the MITRE ATT&CK framework (a standardized list of real-world hacking techniques). This lets SecOps teams see where their defenses have gaps and turn threat intelligence (information about current attacks) into actual security actions.

OpenAI may announce a ChatGPT smart speaker this year

infonews
industry
Jul 14, 2026

OpenAI is planning to release a smart speaker device that lets users speak to ChatGPT and includes a camera and sensors to understand the surrounding environment, though it will have no screen. The device will have a rechargeable battery for portability and smart home control features, though this announcement comes amid legal disputes with Apple over alleged hardware theft.

Global cooperation needed to tackle AI threats, says Bank of England governor

infonews
policysafety

SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage

highnews
securityprivacy

Book publishers sue Google for copyright infringement over Gemini AI training

infonews
policy
Jul 14, 2026

Major book publishers including Hachette, Cengage, and Elsevier have sued Google in federal court, claiming the company illegally used millions of copyrighted books to train its Gemini AI model (a large language model trained on text data) without permission. The publishers describe this as one of the largest copyright infringements in history.

Apple in talks with startup that shrinks AI models to run on an iPhone

infonews
industry
Jul 14, 2026

Apple is in talks with PrismML, a startup that compresses large AI models (mathematical systems with billions of parameters that process information) so they can run directly on iPhones instead of requiring cloud servers. PrismML shrunk Alibaba's 54 GB Qwen model down to under 4 GB by drastically simplifying how the model stores information, allowing the compressed version to run on iPhone 15 and newer devices while using significantly less memory and energy, though with some loss in accuracy.

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

highnews
security
Jul 14, 2026

Researchers found that any browser extension able to run scripts on claude.ai can trigger Claude for Chrome to access your Gmail, Google Docs, and Calendar by forging a fake click, since the extension doesn't verify that clicks are from real users rather than scripts. The flaw is rated as high or critical severity depending on whether you have the "Act without asking" automation mode enabled, and while a simple one-line fix exists, Anthropic has not yet released it in the current version 1.0.80.

Authenticate legitimate AI agent traffic with AWS WAF Bot Control

infonews
security
Jul 14, 2026

AWS WAF Bot Control now includes Web Bot Authentication (WBA), a security feature that uses cryptographic signatures (mathematical verification codes created with public and private keys) to confirm that automated bot traffic comes from legitimate sources. Traditional methods like IP-based filtering fail in multi-tenant systems (shared environments where many different services use the same IP address) where attackers can easily fake their identity, but WBA solves this by having bot operators sign their requests with cryptographic keys that AWS WAF can verify at the edge.

Sam Altman didn’t need another lawsuit

infonews
security
Jul 14, 2026

Apple filed a lawsuit against OpenAI in federal court, accusing former Apple employees of stealing Apple's trade secrets to benefit OpenAI. The lawsuit focuses on Apple's confidential information related to product development, manufacturing, and technology research. This legal action is one of several lawsuits OpenAI has faced recently.

The UK wants to catch up in the global AI race – but is too wary to go all-in

infonews
policyindustry

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

highnews
security
Jul 14, 2026

Two unpatched security flaws in Claude for Chrome (Anthropic's browser extension that can take actions on a user's behalf) allow a malicious extension to trick Claude into reading Gmail, Google Docs, and calendar data without real user approval. The vulnerabilities bypass the extension's safety checks by faking user clicks and can operate silently if the user has enabled the extension's autonomous mode ('Act without asking'), and researchers say this remains exploitable in the latest version 1.0.80.

The Download: Claude’s inner workings, and the future of world models

infonews
researchsafety

How Pentera Turns AI Security Workflows into Validation Engines

infonews
securityindustry

How to manage AI investments in the agentic era

infonews
industry
Jul 14, 2026

This article discusses how enterprise leaders should manage spending on AI tools as they move from simple chat interfaces to more complex, longer-running workflows. It recommends focusing on the actual value delivered (tasks completed, time saved) rather than just the cost per token (a unit of text the AI processes), and emphasizes the need for better visibility into who is using AI, what they're using it for, and how much it costs.

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

highnews
securityprivacy

AI incidents need a new playbook. Here’s how to build one

infonews
securitypolicy

AI-powered breaches provide wake-up call for incident response

infonews
security
Jul 14, 2026

Attackers are increasingly using AI agents (autonomous AI systems that can perform multiple tasks without human control) to automate all stages of cyberattacks, from initial entry to stealing data and establishing persistence (maintaining long-term unauthorized access). This automation dramatically speeds up attacks compared to traditional manual hacking, and security experts warn that most organizations haven't updated their defenses to handle this threat, especially since these AI attacks often exploit unpatched systems and common weaknesses rather than requiring advanced zero-day vulnerabilities (previously unknown security flaws).

Ed Husic tells Labor to get tougher on AI companies as letting them self-regulate ‘doomed to fail’

infonews
policy
Jul 14, 2026

Labor MP Ed Husic argues that AI companies should not be allowed to regulate themselves and warns that weakening copyright laws (rules controlling who can use creative works) to help AI companies would contradict his party's values. The Media Entertainment & Arts Alliance, a union representing journalists and artists, is calling on the government to create stricter copyright rules to stop AI models from being trained on creative works without permission.

Previous84 / 237Next

Fix: Microsoft is recommending that customers accelerate their patching schedules to more quickly deal with critical flaws.

CSO Online
Dark Reading
The Verge (AI)
Jul 14, 2026

The Bank of England governor called for international cooperation to address AI threats, warning that the US cannot secure itself against cyber dangers without global coordination. He emphasized that no country can isolate itself from the cross-border nature of modern systems, and stressed the need for stronger coordinated testing to ensure frontier AI (advanced AI models at the cutting edge of capability) models are safe before wider use.

The Guardian Technology
Jul 14, 2026

SpaceXAI's Grok Build AI coding tool was uploading users' entire codebases (the complete collection of source code files for a project) to Google Cloud storage without proper controls, including files users wanted to exclude and sensitive credentials (secret authentication data). The company disabled this upload feature after security researchers discovered and reported the issue.

Fix: SpaceXAI's servers now return a "disable_codebase_upload: true" flag, and the codebase upload feature "no longer fires" (does not activate).

The Verge (AI)
The Guardian Technology
CNBC Technology

Fix: The quickest guard is to turn "Act without asking" off and review any extension with permission to read or change data on claude.ai. Researchers also note that "the one-line fix, the researchers say, rejects synthetic clicks at the top of the handler" but confirm this fix "has not shipped" as of July 14.

The Hacker News

Fix: AWS WAF Bot Control implements Web Bot Authentication (WBA) using asymmetric cryptography and HTTP Message Signatures (RFC 9421). The solution works through: (1) Bot registration, where bot operators publish their public keys in a signature directory that AWS WAF regularly polls; (2) Request signing, where each bot request is signed using the operator's private key following IETF standards; (3) Verification, where AWS WAF verifies signatures against known public keys and appends labels (verified, invalid, expired, or unknown_bot) to allow granular control through WAF rules. AWS WAF Bot Control respects WBA verification status by default, automatically allowing verified AI agent traffic.

AWS Security Blog
The Verge (AI)
Jul 14, 2026

The UK faces a dilemma in competing globally with AI technology, caught between wanting to invest heavily in AI and worrying about three simultaneous risks: putting too much money into AI company stocks, companies adopting AI more slowly than expected, and the extremely rapid pace of AI development making it hard to keep up. The article discusses broader concerns about the UK's position in the global AI competition alongside questions about major AI companies' future plans.

The Guardian Technology
SecurityWeek
Jul 14, 2026

Anthropic announced a discovery that provides insight into how Claude (an AI model) reasons internally by examining its 'thoughts' as it works through problems. The article notes this research shows a new window into AI model operations, though the full implications of what this reveals about how AI systems actually work remain unclear.

MIT Technology Review
Jul 14, 2026

AI security systems currently make decisions based on fragmented data from separate tools, which cannot detect real attack paths because attackers chain exposures across multiple systems in ways individual tools don't see. The article argues that AI security workflows need validation (testing whether vulnerabilities can actually be exploited in a real environment) rather than just severity scores, so teams act on proven attack evidence instead of guesswork. Pentera addresses this by using AI to safely emulate real attacker techniques against production environments and generate validated attack paths showing exactly how an attacker could move through the system.

Fix: Pentera introduced an MCP (Model Context Protocol, a standard for connecting AI assistants to external tools) Server that makes validated attack path data from Pentera directly available to MCP-compatible AI assistants, so security teams can access validation evidence within the same AI workflows where they investigate and prioritize findings instead of switching between separate tools.

The Hacker News

Fix: The source explicitly mentions several management tools and approaches: (1) Updated usage analytics and spend controls in the Admin Console help admins see adoption, credit usage, and spend by user, product, and model, track trends over time, and identify emerging patterns. (2) Evaluate models by measuring the full cost of reaching acceptable outcomes, including model and tool usage, attempts, completion rate, latency, and human review, rather than choosing based on token price alone. (3) Use clear instructions, focused tools, reusable context, and explicit stopping conditions to reduce loops and wasted spend. (4) ChatGPT Work provides centralized controls for access, approved context, connected tools, permitted actions, usage, and spend, with spend controls such as workspace defaults to govern advanced workflows before they scale.

OpenAI Blog
Jul 14, 2026

Grok Build, xAI's coding assistant, was uploading entire Git repositories (a version control system that tracks code changes) to cloud storage, not just the files it needed to read. A researcher discovered that a 12 GB repository generated only 192 KB of traffic to the model but 5.10 GB to storage, and even files the AI was instructed not to open were included, along with unredacted credentials like API keys and passwords. Unlike competing tools from Claude and Google, Grok Build was the only one collecting the entire workspace.

Fix: On July 13, xAI disabled the storage uploads server-side by switching a flag (disable_codebase_upload: true and trace_upload_enabled: false), which multiple users confirmed they received. However, xAI has not confirmed whether this change applies to all accounts or is permanent, and no update to the software itself was released—the change was made on the server side while users remained on version 0.2.93.

The Hacker News
Jul 14, 2026

Most organizations have AI systems in production but lack incident response (IR) playbooks specifically designed for AI failures, relying instead on traditional security frameworks that don't address AI-specific problems. AI incidents fall into two categories with very different causes and defenses: model-originated failures (like hallucinations or bias that happen during normal operation) and externally induced failures (like adversarial attacks or data poisoning), plus hybrid cases where AI errors create legal liability. Traditional security frameworks like the CIA triad (confidentiality, integrity, availability) don't detect many AI incidents because they assume deterministic, static failures, but AI systems produce probabilistic outputs that can't be patched like code vulnerabilities.

CSO Online
CSO Online
The Guardian Technology