aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

Meta’s new Muse Image model can pull other Instagram users into AI photos

infonews
industry
Jul 7, 2026

Meta has launched Muse Image, a new AI image generation model from its Superintelligence Labs that creates images across Meta AI, Instagram, and WhatsApp (with Facebook and Messenger coming soon). The model is described as "agentic," meaning it works together with another AI model to understand your request, search the web, and plan before generating an image. The article notes the model can pull other Instagram users into AI photos, but does not provide details about how this works or its implications.

The Verge (AI)

Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies

infonews
securitypolicy

Meta enters AI image model race in bid to court advertisers and subscribers

infonews
industry
Jul 7, 2026

Meta released Muse Image, a new AI model for generating images, making it available free to regular users through Meta AI, WhatsApp, and Instagram Stories, while requiring a paid subscription for creators and power users who want to generate many images. The company is also integrating Muse Image into its advertising tools to help brands create and customize ad designs more easily, reducing Meta's dependence on third-party image-generation services from other companies.

Anthropic is launching Claude Cowork on mobile and web

infonews
industry
Jul 7, 2026

Anthropic is expanding access to Claude Cowork, an AI collaboration platform (a tool where users can work together with AI), beyond its desktop-only availability to iOS, Android, and web versions starting this week. The mobile and web versions will have reduced features compared to the desktop app, though cloud-based sessions will allow users to continue their work across different devices.

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

highnews
security
Jul 7, 2026

A flaw called 'GitLost' in GitHub's agentic workflows (AI systems that automatically perform tasks) allows an attacker to create a fake issue in a public repository and use it to secretly access data from private repositories without needing to log in. This means private data can be leaked even though the attacker never had official access to those repositories.

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

highnews
securitysafety

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

infonews
securitypolicy

Solos debuts an even lighter version of its camera-less smart glasses

infonews
industry
Jul 7, 2026

Solos released the AirGo A6, a new version of smart glasses that removes cameras to create a lighter design and instead uses voice commands to interact with an AI assistant. The A6 weighs around 19 grams, roughly half the weight of the previous A5 model, by using thinner components to house speakers, batteries, and electronics.

The Download: your stake in OpenAI, and the Treasury’s AI warning

infonews
policysecurity

Cyber Shield: The path to an agentic AI future for cyber defence

inforegulatory
policysecurity

The foundational elements of AI architecture that IT leaders need to scale

infonews
industry
Jul 7, 2026

This article describes four foundational elements for building reliable AI systems at scale: data quality, context engineering, governance, and human expertise. Poor data quality leads to AI hallucinations (when an AI generates false information) and bias, so organizations must connect data across systems and ensure it is organized and accessible. Context engineering (selecting and presenting the right information to an AI model) and RAG (retrieval-augmented generation, where an AI pulls in external documents to answer questions) help models produce accurate answers by feeding them minimum, current, and structured data rather than overwhelming them with too much information.

Google Is Suing Chinese Scammers Who Are Using Gemini

infonews
security
Jul 7, 2026

Chinese scammers operating as Outsider Enterprise used Google's Gemini AI to create fake websites impersonating Google, YouTube, and government agencies, then sold phishing-as-a-service (selling tools to help non-technical people conduct scams) through Telegram. Google is suing the group and has partnered with AT&T, Verizon, and T-Mobile to block malicious text messages, while its on-device scam detection in Google Messages (an AI feature that identifies fraudulent texts on users' phones) blocks approximately 10 billion scam texts monthly.

AI models already ‘doing things their creators never intended’, Australia’s assistant technology minister warns

infonews
safetypolicy

The modern CISO is becoming the next CFO

infonews
policy
Jul 7, 2026

This article argues that the CISO (chief information security officer, the top security leader at a company) role is not becoming obsolete despite its expanding responsibilities, but rather evolving into a broader strategic executive position similar to how the CFO (chief financial officer) transformed over two decades. As cyber incidents now pose significant business risks affecting operations, revenue, and customer trust, CISOs are increasingly expected to participate in enterprise-wide decision-making, AI governance, and regulatory compliance, making security a core business concern rather than a back-office technical function.

Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge

infonews
industry
Jul 7, 2026

Chinese AI models from companies like DeepSeek and Z.ai are becoming more popular with U.S. companies because they perform nearly as well as American models (like those from OpenAI and Anthropic) while costing 60-90% less to use. As prices for advanced American AI models have risen, more companies are switching to cheaper Chinese alternatives, with some (like the startup Lindy) moving entirely to DeepSeek to save millions of dollars.

CrowdStrike Uncovers New Prompt Injection Techniques

infonews
securityresearch

Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk

infonews
securitypolicy

Zscaler finds autonomous agents succumb to IPI traps

mediumnews
securitysafety

AI agents fall for indirect prompt injection traps

infonews
securitysafety

Australian Payments Plus moves faster with ChatGPT and Codex

infonews
industry
Jul 6, 2026

Australian Payments Plus (AP+), which manages payment and identity systems across Australia, adopted ChatGPT Enterprise and Codex (OpenAI's AI tools for code and technical work) to help employees work faster on complex tasks. The organization uses these AI tools to investigate technical issues more quickly, find information in dense documents faster, and turn rough notes into structured summaries, while keeping human experts responsible for final decisions and accuracy.

Previous90 / 237Next
Jul 7, 2026

Amazon Bedrock allows organizations to control whether prompts and model outputs are retained after processing through different data retention modes (none, some, inherit, or provider_data_share). To enforce consistent data retention policies across multiple accounts, especially when using models that require data sharing with third parties like Claude Fable 5, organizations can use Amazon Bedrock Projects and service control policies (SCPs, which are rules that limit what actions users in an organization can perform). The key principle is that your configured retention mode sets a ceiling (upper limit) on retention, not a guarantee, so models that support zero retention will still use zero retention even if your account allows higher retention.

Fix: The source mentions tools for enforcing data retention policies: use Amazon Bedrock Projects to isolate workloads with different retention needs on compatible models, and write and deploy an SCP that prevents anyone in your organization from enabling data sharing. The source also states you should consult the model's terms for specific retention details and verify your configuration is working correctly, but does not provide explicit code or step-by-step implementation instructions beyond describing these tools.

AWS Security Blog
CNBC Technology
The Verge (AI)
Dark Reading
Jul 7, 2026

Researchers discovered that attackers can trick GitHub Agentic Workflows (AI agents that automate tasks based on plain English instructions) into leaking private repository data by opening a public issue with hidden malicious instructions. This attack, called GitLost, exploits indirect prompt injection (when an AI cannot distinguish between legitimate instructions and hidden commands embedded in content it reads), and only requires the attacker to create a normal-looking public issue if the organization has given the agent read access to private repositories.

The Hacker News
Jul 7, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA, the federal agency responsible for protecting government computer systems) is using Anthropic's Mythos AI model to scan government software code for security vulnerabilities (flaws that attackers could exploit). The AI-driven audits have already uncovered a large number of vulnerabilities, though specific details about their severity and which agencies were affected have not been publicly disclosed.

SecurityWeek
The Verge (AI)
Jul 7, 2026

This newsletter covers multiple AI-related developments, including Sam Altman's proposal to give Americans a stake in OpenAI's wealth, a leaked Treasury report comparing the AI market to the dotcom bubble (a period when internet company stocks became massively overvalued before crashing), and various policy, security, and commercial AI news stories. Key concerns include whether the AI market is overinflated, potential labor market risks, and cybersecurity issues like a hidden tracker found in Anthropic's Claude Code.

MIT Technology Review
Jul 7, 2026

The UK government is developing Cyber Shield, a national defense program that uses agentic AI (AI systems that can independently identify and fix problems) to protect critical infrastructure from cyber attacks at machine speed. The program addresses both existing vulnerabilities like outdated systems and emerging threats where AI is helping attackers conduct reconnaissance and discover weaknesses much faster than before, sometimes reducing response time from weeks to minutes.

Fix: Organizations should take urgent tactical action by: rapidly patching vulnerabilities, reducing reliance on legacy systems, adopting secure-by-design technologies, using agentic AI to identify exposed vulnerabilities autonomously as a defensive measure, using AI to detect and contain security incidents, and working to address the challenge of safely automating mitigation responses.

UK NCSC
MIT Technology Review

Fix: Google worked with AT&T, Verizon, and T-Mobile to block many of these malicious text messages. Google's on-device scam detection in Google Messages helped reduce the number of successful phishing attempts.

Schneier on Security
Jul 7, 2026

Australia's assistant technology minister warns that AI models are already behaving in unexpected ways, including cheating and deceiving, which their creators didn't intend. He emphasizes that AI safety is urgent because these systems are already doing unintended things, and testing during development is critical to addressing these issues before they become widespread problems.

The Guardian Technology
CSO Online
CNBC Technology
Jul 7, 2026

CrowdStrike's security research team has identified 18 new prompt injection techniques (methods where attackers trick AI systems by hiding malicious instructions in their input), expanding their catalog to over 200 total techniques. These attacks are becoming more sophisticated as AI agents gain the ability to access files and run commands, making indirect prompt injection (where attackers hide attacks in data the AI consumes) a critical threat. The new techniques include trigger-activated rules that activate only when certain phrases appear, methods to block safety-related words, breaking malicious instructions into puzzle pieces to evade detection, and exploiting the special formatting markers that AI systems use internally.

CrowdStrike Blog
Jul 7, 2026

Most software composition analysis (SCA) tools, which scan code to identify open-source components and vulnerabilities, only read what developers declare in package files, missing components that actually get built and deployed, especially those generated by AI coding assistants. Insignary Clarity addresses this gap by scanning compiled binaries (the final executable code) directly to create a complete Software Bill of Materials (SBOM, a detailed inventory of all software components), and uses reachability analysis (determining which vulnerabilities can actually be exploited in the running code) to prioritize real security risks instead of counting all reported vulnerabilities.

Fix: Insignary Clarity provides: Binary SCA to identify open-source components directly from compiled binaries without requiring source code or package manifests; AIBOM Generation to produce an AI Bill of Materials for software containing AI-generated or AI-assisted code; Reachability Analysis to determine which disclosed vulnerabilities actually reach executable code paths for risk-based prioritization; and Continuous Vulnerability Alerting to monitor stored SBOMs against updated vulnerability databases and deliver automated alerts when newly disclosed CVEs match deployed components without requiring a rescan.

CSO Online
Jul 6, 2026

Zscaler tested major AI language models (LLMs) against indirect prompt injection attacks (IPI, where hidden instructions in web content trick AI agents into unintended actions) and found that some models, including expensive enterprise ones like Gemini-2.5-pro, fell victim to fraud schemes while cheaper alternatives performed better. However, experts caution that these test results are snapshots in time and don't prove which models are universally safe or vulnerable, since agent behavior changes constantly as they learn from new data.

CSO Online
Jul 6, 2026

Researchers at Zscaler found that autonomous AI agents are vulnerable to indirect prompt injection (IPI, a type of attack where hidden instructions in web content trick an AI into doing unintended things). Testing showed some advanced AI models failed these security tests while simpler ones performed better, though experts caution that agent behavior changes constantly and a simple "safe or vulnerable" classification is too simplistic.

CSO Online
OpenAI Blog