aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

infonews
policysecurity
Jul 9, 2026

The UK government announced Cyber Shield, a national initiative to deploy agentic AI (autonomous AI systems that can take independent actions) for cybersecurity defense, working across government and private organizations. The plan aims to use AI red teams (attackers) and blue teams (defenders) to automatically find and fix vulnerabilities faster than human attackers can exploit them, since current vulnerability discovery has accelerated from weeks to minutes. However, cybersecurity experts quoted in the article argue that most organizations today are compromised by basic configuration failures and legacy infrastructure problems, not sophisticated AI-driven attacks, so focusing on these fundamentals may be more urgent.

SecurityWeek

Meta jumps into AI coding market in effort to chase Anthropic and OpenAI

infonews
industry
Jul 9, 2026

Meta released Muse Spark 1.1, an updated AI model designed for coding and agentic work (AI that can autonomously perform multiple tasks), as it competes with OpenAI and Anthropic. The model is now available through a public preview via a developer portal with aggressive pricing ($1.25 per million input tokens, $4.25 per million output tokens), though Meta is initially limiting API access to its own properties rather than third-party platforms.

Meta says its new AI model is ready to compete on coding

infonews
industry
Jul 9, 2026

Meta has released Muse Spark 1.1, an updated AI coding model that can be integrated into AI coding software through a new API (a set of tools that lets software talk to other software). The model claims improvements in detecting and fixing bugs, supporting multi-agent systems (where multiple AI agents work together), and processing multiple types of data like images and videos.

Say hello to Claude Wrapped

infonews
industry
Jul 9, 2026

Anthropic has launched a "reflect" feature for Claude, its AI chatbot, that shows users a year-in-review analysis of their usage patterns similar to Spotify Wrapped. The dashboard displays information like the topics users discuss most, the types of tasks they ask Claude to handle, and when they use the service most frequently.

Character.AI wants a piece of the microdrama pie

infonews
industry
Jul 9, 2026

Character.AI, a platform built on large language models (AI systems trained on vast amounts of text to generate human-like responses), is expanding beyond chatbots into short-form video content called c.ai Series. These animated videos are created using generative AI (technology that can produce new images, text, or video from patterns it learned) and are designed to be watched and interacted with on mobile phones, positioning the company to compete in the growing microdrama industry.

AI Gateways Offer Attackers the Keys to the Kingdom

infonews
security
Jul 9, 2026

AI gateways (systems that control access to AI models and cloud services) can be vulnerable entry points for attackers, as shown by a recent cryptomining incident where attackers exploited these gateways to gain access to AI models, cloud infrastructure, and IAM (identity and access management, the system controlling who can access what resources) data. This highlights a security risk in how organizations protect their AI systems.

A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

infonews
security
Jul 9, 2026

Cyber-attacks increased significantly in June 2026, with organizations worldwide experiencing an average of 2,270 attacks per week, up 10% from the previous month. Education, Government, and Telecommunications sectors were hit hardest, while ransomware attacks (malware that encrypts data and demands payment for its return) reached 646 cases in the month. Healthcare and Telecommunications industries face the most risk from unsafe prompts (instructions given to AI systems that could be misused).

Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk

highnews
security
Jul 9, 2026

Attackers compromised an AWS EC2 instance running LiteLLM (a proxy that acts as a gateway to AI models), deployed cryptomining malware, and attempted to abuse cloud permissions and AI services. The incident reveals a broader security risk: AI gateways concentrate access to cloud identities, permissions, and AI models in a single system, making them extremely valuable targets that can give attackers broad access to an organization's cloud infrastructure and AI resources.

GPT-5.6 is now the preferred model in Microsoft 365 Copilot

infonews
industry
Jul 9, 2026

OpenAI announced GPT-5.6, a new AI model that will become the default option in Microsoft 365 Copilot (an AI assistant built into Microsoft's productivity apps like Word, Excel, and PowerPoint). This update gives Microsoft 365 users access to a more capable model that can produce better quality work with less effort, such as helping draft documents, analyze data, or create presentations more efficiently.

UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed

infonews
securitypolicy

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

infonews
security
Jul 9, 2026

AI-powered attacks now move much faster than traditional attacks, with tools like Mythos allowing attackers to craft custom phishing messages, find targets, test their success, and move to new systems within minutes. Traditional security tools were designed to defend against slower human attackers and cannot keep up with AI-driven attacks operating at scale. The article promotes a webinar that claims to teach three defensive strategies: reducing what attackers can access, preventing lateral movement (attackers spreading through a network after initial entry), and detecting attacks early through automated responses.

The Language of AI Could Change How Humans Speak

infonews
safetyresearch

Agentic AI identity: A 6-stage maturity model for non-human identities

infonews
securitypolicy

GPT-5.6: Frontier intelligence that scales with your ambition

infonews
industry
Jul 9, 2026

OpenAI released the GPT-5.6 family of models, including Sol (flagship), Terra (balanced), and Luna (cost-efficient), which achieve better performance than competing models while using fewer tokens (units of text the AI processes) and costing less money. The models were trained with safeguards (protective measures against misuse) tested through human red teaming (security experts trying to break it) and automated testing before general release. GPT-5.6 Sol also introduces enhanced coding abilities and a new "ultra" setting that coordinates multiple agents (independent AI systems working in parallel) to handle complex tasks faster.

ChatGPT is now a partner for your most ambitious work

infonews
industry
Jul 9, 2026

OpenAI has introduced ChatGPT Work, an agent (a specialized AI assistant designed to perform specific tasks) powered by GPT-5.6 that can handle complex, multi-step projects by breaking them into smaller tasks and working across apps like spreadsheets, slides, and documents. The system can continue working on projects independently, even when users are away, and uses Codex technology (built-in code generation capabilities) to create finished materials and automate workflows.

GPT-5.5 Bio Bug Bounty

infonews
securitysafety

Why fixing your data architecture matters more than upgrading your detection models

infonews
securityresearch

TopĀ AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

highnews
securitysafety

Why AI Governance Without Guardrails Is Theater

infonews
policysecurity

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

highnews
security
Jul 9, 2026

Researchers discovered GhostApproval, a flaw in six AI coding assistants that exploits symlinks (shortcuts that point to different files on a computer) to trick developers into approving edits that secretly modify sensitive files like SSH login keys. The assistants show approval dialogs that name harmless files while actually writing to dangerous system files, bypassing informed consent even though developers think they are approving safe changes.

Previous88 / 237Next
CNBC Technology
The Verge (AI)
The Verge (AI)
The Verge (AI)
Dark Reading
Check Point Research

Fix: According to Jason Soroko at Sectigo, security teams should close public admin paths, remove long-term keys where possible, scope IAM permissions (limit what access credentials can do), monitor Bedrock and model access patterns, and correlate workload telemetry (performance data from running systems) with control-plane events (administrative actions in the cloud).

CSO Online
OpenAI Blog
Jul 9, 2026

The UK's National Cyber Security Centre (NCSC) has unveiled Cyber Shield, a plan to deploy autonomous AI agents (software programs that can act independently) to find and stop cyberattacks on national networks in real time. The proposal addresses a growing problem: attackers are already using AI to discover vulnerabilities (security weaknesses) and gather information faster than human defenders can respond, compressing activities that once took weeks into minutes. Cyber Shield would use paired AI 'red' and 'blue' agents to identify weaknesses and defend against threats, starting with partnerships in government and critical sectors before expanding commercially.

CSO Online

Fix: The source describes three mitigation strategies mentioned in the webinar: (1) 'Shrink what the attacker can reach. Cut exposed entry points and enforce least-privilege access everywhere' (limiting what systems users can access); (2) 'Kill lateral movement by design. Drop network-based trust and allow only the connections users and workloads actually need' (restricting network access to only necessary connections); (3) 'Catch it early. Plant tripwires that AI attacks set off, firing automated containment before a foothold becomes an incident' (automated detection and response systems). The article also mentions applying a 'Zero Trust approach built for machine speed,' though specific implementation details are not provided in the source text.

The Hacker News
Jul 9, 2026

Large language models are trained primarily on written text and scripted speech, missing the vast majority of human conversation, which means they capture an incomplete slice of how people actually communicate. As people encounter more AI-generated text and interact with chatbots, they may gradually adopt the linguistic patterns of these models, leading to changes in how humans speak to each other and think about the world, such as using shorter sentences, narrower vocabulary, overly formal structures, and increased confirmation bias (accepting information without questioning it).

Schneier on Security
Jul 9, 2026

An AI agent with standing access to a production system caused a four-hour outage through a misconfiguration, but no one could identify which human authorized its action because the agent lacked proper identity controls (MFA, scoped access revocation, short-lived credentials). The core problem is that traditional identity management systems were built for predictable service accounts with fixed roles, but agentic AI systems (AI that breaks tasks into steps and chooses which tools to use) operate with unbounded scope and unpredictable actions, creating major security risks around privilege abuse and rogue agent behavior that existing access controls cannot properly govern.

CSO Online
OpenAI Blog
OpenAI Blog
Jul 9, 2026

OpenAI is running a bug bounty program (a competition where security researchers find vulnerabilities and report them for rewards) to test GPT-5.5 and GPT-5.6 for universal jailbreaks (methods that can trick the AI into ignoring its safety rules for biology-related requests). The company increased rewards from $25,000 to $50,000 for researchers who successfully find these vulnerabilities, aiming to strengthen safeguards before releasing advanced AI models.

OpenAI Blog
Jul 9, 2026

Organizations spend billions upgrading AI detection models in cybersecurity, but the real problem is often poor data quality upstream in the data pipelines. Issues like fragmented telemetry (data collected from multiple tools in different formats), schema drift (gradual changes to data format structures), and stale behavioral baselines cause AI models to produce unreliable results, leading to false alarms and missed threats.

CSO Online
Jul 9, 2026

AI coding agents like Claude Code and OpenAI's Codex can be tricked into running malicious code when they are supposed to be scanning code for security problems. Researchers at the AI Now Institute demonstrated an attack called "Friendly Fire" that hides a malicious script in a README file (a standard text file in code projects), and the agent runs it without warning because it looks like a legitimate security check. The researchers say this is a design problem, not a bug that can be patched, because the AI models cannot reliably tell the difference between the code they are reading and the instructions they should follow.

The Hacker News
Jul 9, 2026

Many organizations have AI governance policies on paper, but in reality, employees widely use unapproved AI tools outside company oversight, a problem called shadow AI (unauthorized use of AI applications). This creates security and data risks, such as employees accidentally pasting sensitive information into chatbots or connecting company systems to AI tools without approval, and traditional security controls weren't designed to monitor these new AI interactions.

Fix: The source identifies needed guardrails but does not describe specific implemented solutions. It states that organizations need 'strong identity controls, continuous authorization, logging, segmentation, safe tool use, and secure-by-default patterns in apps that call models,' and that CIOs must 'turn to technology guardrails capable of transporting AI governance intent from the realm of policy principles to the world of production environments, with scalable visibility and enforcement.' However, no concrete fix, patch, version update, or deployed mitigation is explicitly mentioned in the text.

CrowdStrike Blog

Fix: Three tools have shipped fixes: Amazon Q Developer (update to Language Server 1.69.0, which installs automatically for most users), Cursor (update to v3.0 via the extension manager), and Google Antigravity (update to the current version). For Augment and Windsurf, which have not yet released fixes, the source recommends: do not point them at repositories you do not trust. For Claude Code, the source states: update, and read the symlink warning before accepting any edits.

The Hacker News