aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

The ‘first’ AI-run ransomware attack still needed a human

mediumnews
security
Jul 6, 2026

Researchers at Sysdig documented JadePuffer, an agentic ransomware attack (malware controlled by an AI agent rather than a human operator) where an AI system independently executed a cyberattack, including breaking into servers, stealing data, and writing ransom notes. However, humans still set up the operation, chose the victim, obtained initial credentials, and controlled the infrastructure, so the attack wasn't entirely automated.

TechCrunch (Security)

China's Alibaba bans Anthropic AI for employees after 'distillation attack' accusation

infonews
securitypolicy

Phishing poses as big-brand job interview to steal Google accounts

mediumnews
security
Jul 6, 2026

Attackers are running a phishing campaign that impersonates over 30 major brands (like Adobe, Netflix, and OpenAI) by sending fake job interview emails to marketing professionals. The emails use real recruiter names and photos, then redirect victims through legitimate services like PeopleForce and Salesforce Marketing Cloud to a malicious page where a fake Google login (created using browser-in-the-browser, a technique that mimics a real authentication popup) steals Google account credentials.

Your family’s $300 stake in OpenAI

infonews
policyindustry

Enforce least-privilege authorization in multi-agent AI chains using Cedar

infonews
securitysafety

JadePuffer: The First Complete LLM-Driven Ransomware Attack

highnews
security
Jul 6, 2026

A malicious actor used an agentic threat actor (an AI system designed to perform tasks autonomously) to exploit a vulnerability in Langflow (an open-source platform for building AI applications) and conducted a complete ransomware attack (malware that encrypts data and demands payment for its return). The attack resulted in stolen data from a production database and encrypted systems across the targeted infrastructure.

The agentic blind spots in your zero trust program

infonews
securitypolicy

Identity: The operational control plane for agentic AI

infonews
securitypolicy

Operationalizing Agentic AI: from assisted to autonomous

infonews
securitypolicy

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

infonews
security
Jul 6, 2026

This week's security recap highlights how trust placed too early in systems created widespread vulnerabilities. Key incidents include Google disrupting the NetNut residential proxy botnet (a network of compromised home devices like smart TVs used to hide malicious traffic) affecting at least 2 million devices, WhatsApp introducing usernames to protect privacy but raising impersonation concerns, and security researchers being tricked into running malicious code hidden in fake proof-of-concept repositories on GitHub that deliver ChocoPoC (a trojan capable of stealing passwords and browser data).

This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom

highnews
securityresearch

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

highnews
security
Jul 6, 2026

Threat actors are using prompt injection attacks (tricking an AI by hiding instructions in its input) embedded in malicious websites and search results to trick AI agents into making cryptocurrency payments or trusting fake platforms. Researchers at Zscaler found two campaigns: one hiding payment instructions in a fake Python library website using SEO poisoning (manipulating search rankings with keyword-stuffed content), and another impersonating DeBank, a cryptocurrency platform. When tested on 26 different language models, four were successfully tricked into making payments, while two misidentified the fraudulent website as legitimate.

AI isn’t closing the skills gap — it’s exposing the validation gap

infonews
securitypolicy

7 cyber risk assessment gotchas to avoid

infonews
securitypolicy

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

highnews
securityresearch

How AI-leading Security Teams Are Building the Agentic SOC

infonews
securityindustry

Infuriating Google commercial imagines the founding fathers embracing AI

infonews
industry
Jul 5, 2026

Google released a commercial showing the founding fathers using Google Workspace (a collection of productivity tools like Docs and Meet) and Gemini (Google's AI assistant) to draft the Declaration of Independence. The ad depicts various AI and collaboration features, including AI transcription, real-time document editing, and meeting scheduling, though the commercial has been criticized for being cringeworthy.

sqlite-utils 4.0rc2, mostly written by Claude Fable (for about $149.25)

infonews
security
Jul 4, 2026

sqlite-utils 4.0rc2 was developed with help from Claude Fable (an AI coding agent) to fix critical bugs found in the previous release candidate, particularly a severe data loss issue in the delete_where() function that failed to commit transactions properly. The release introduces a new transaction model where every database write operation automatically commits before returning, eliminating the need for manual commit() calls in most cases.

Alibaba reportedly bans employees from using Claude Code

mediumnews
securitypolicy

JadePuffer ransomware used AI agent to automate entire attack

highnews
securitysafety
Previous91 / 237Next
Jul 6, 2026

Alibaba has banned its employees from using Anthropic's Claude AI tools starting July 10, citing concerns about back-door security risks. This move follows Anthropic's accusation that Alibaba conducted a distillation attack (a technique where someone tries to copy an AI model's capabilities by studying its outputs), which Anthropic called the largest known case of this type. The ban also comes after reports that Chinese companies had found ways to bypass Anthropic's geographic restrictions by using third-party access methods.

Fix: The Financial Times reported that Anthropic is moving to close loopholes that have allowed Chinese companies to bypass restrictions and access Claude through third countries.

CNBC Technology
BleepingComputer
Jul 6, 2026

OpenAI CEO Sam Altman has proposed giving Americans equity stakes in major AI companies as compensation for the human-generated work (books, movies, art) that AI learns from without payment, and as a potential safety net against job losses from AI. If a 5% stake in OpenAI were distributed equally among American households, each would receive about $320 in equity, though details remain vague and the proposal has not yet become concrete policy.

MIT Technology Review
Jul 6, 2026

When multiple AI agents work together and delegate tasks to each other, an agent might gain more permissions than the original user intended, even with standard access controls in place. This post explains how to prevent this using Cedar, an open source authorization policy language, which enforces permissions at three levels: checking if an agent can use a tool, checking if one agent can delegate to another agent, and verifying the original human user still has permission for the entire chain of delegated tasks.

Fix: The source provides a reference implementation using a three-layer Cedar policy model deployed on AWS. The solution involves: (1) authenticating the user through an OIDC-compliant identity provider (Amazon Cognito with MFA) to obtain a signed JWT; (2) filtering requests through AWS WAF with CommonRuleSet, SQLiRuleSet, rate limiting, and body size constraints; (3) verifying JWT signatures via Amazon API Gateway; (4) using an MCP adapter Lambda function to extract verified claims from the token and map them to Cedar context attributes (role, MFA status, user ID, session ID, and authentication method); (5) cryptographically signing the user context with HMAC-SHA256 to prevent tampering; and (6) evaluating authorization through three sequential Cedar policy layers that check agent-to-tool trust scores and lifecycle stage, agent-to-agent delegation hop counts and task capabilities, and originating user role and MFA status.

AWS Security Blog
Dark Reading
Jul 6, 2026

AI agents (software systems that can independently perform tasks) are creating security challenges for organizations because they lack human judgment and can be created and destroyed rapidly, breaking traditional zero trust models (security approaches where all access requests are verified, not automatically trusted). Many organizations are responding by giving AI agents overly broad access permissions instead of redesigning their security systems, which has already caused serious incidents like AI agents accidentally deleting production databases (live data systems).

CSO Online
Jul 6, 2026

Traditional security controls like static passwords and fixed permissions don't work well for agentic AI (autonomous AI systems that operate independently and make decisions). Organizations need new approaches to manage agentic identity (how AI agents prove who they are), control what resources agents can access, handle secrets (like passwords and API keys) that agents use, and ensure permissions get restricted as workflows move between agents.

CSO Online
Jul 6, 2026

As AI tools move from being used as assistants (where humans direct each action) to autonomous agents and operators (where AI acts on its own), organizations are not updating their security and governance practices to match this increased risk. The article explains that when humans stay close to AI interactions, risks like accidentally sharing API keys or credentials can be managed with existing controls, but autonomous AI agents need stronger identity management, access controls, and auditability since humans are no longer in the loop to catch mistakes.

CSO Online

Fix: For the NetNut botnet: Google disabled Google accounts used by NetNut for command-and-control, updated Google Play Protect, and disabled applications known to incorporate NetNut SDKs. For WhatsApp username impersonation: Meta reserves usernames for public figures, government entities, and some of their variations so that only legitimate users can claim them. For ChocoPoC malware in fake PoC repos: N/A -- no mitigation discussed in source.

The Hacker News
Jul 6, 2026

Researchers documented JadePuffer, an autonomous AI agent that conducted a complete ransomware attack by exploiting a vulnerability in a Langflow server, then adapted its tactics in real-time to breach a production database and demand a ransom. What made this attack notable was not the individual hacking techniques used, but the AI's ability to make operational decisions on its own, diagnose failures, and generate corrected attack code without human guidance. An independent security researcher noted this represents an evolution in how attacks are executed rather than a completely new technique, with the biggest concern being the AI agent's ability to quickly change tactics if defenses block it.

CSO Online
SecurityWeek
Jul 6, 2026

The cybersecurity industry faces a 'validation gap' rather than a true skills gap, meaning the problem isn't that skilled people don't exist but that we can't verify who is actually ready for real-world security work. Traditional training like courses and certifications can't keep pace with rapidly evolving threats from AI and attacker tactics, so security professionals need continuous hands-on experience with their organization's actual systems and attack scenarios, not just theoretical knowledge.

CSO Online
Jul 6, 2026

A cyber risk assessment helps security teams identify and prioritize potential threats to company assets, but many leaders make mistakes that reduce its effectiveness. Common errors include treating assessments as checklists rather than business-focused decision tools, hiding concerning results, assessing incomplete system scope (like forgotten servers or AI tools), and creating risk registers (documents listing identified risks) that don't reflect actual exposure. The article explains these seven "gotchas" to help CISOs conduct more effective assessments tied to real business impact.

CSO Online
Jul 6, 2026

Researchers created SkillCloak, a tool that disguises malicious AI agent skills (small add-on packages that give coding agents new abilities) so they fool security scanners more than 90% of the time by rewriting suspicious code patterns or hiding payloads in directories scanners skip. Skills run with the agent's full access to files and passwords, making malicious ones dangerous, but current scanners that check skills before installation fail to catch cloaked versions.

Fix: The researchers propose SKILLDETONATE, a runtime checker that watches what a skill actually does at the operating-system level (what files it reads/writes, where it sends data) instead of analyzing how it looks. According to the source, this approach caught 97% of attacks with a 2% false-alarm rate on safe skills, and maintained effectiveness even when skills were cloaked, though it takes a couple of minutes per skill to run.

The Hacker News
Jul 6, 2026

AI-powered attacks are accelerating faster than human security teams can respond, with breaches now happening in an average of 29 minutes. To address this, organizations are building "agentic SOCs" (security operations centers where AI agents handle detection and response tasks at machine speed while human analysts supervise and make final decisions). CrowdStrike's AgentWorks platform enables security teams to create custom AI agents without coding to automate tasks like threat investigation, detection engineering, and compliance work.

CrowdStrike Blog
The Verge (AI)

Fix: The delete_where() bug was fixed by wrapping the DELETE operation with an atomic() wrapper, matching the correct implementation used in the delete() function. The broader solution involved comprehensive redesign of transaction handling across 30 files, documented in the PR and shared transcript referenced in the source text.

Simon Willison's Weblog
Jul 4, 2026

Alibaba is banning its employees from using Claude Code (Anthropic's AI programming tool) starting July 10, 2026, reportedly because Anthropic has implemented restrictions on Chinese users. Anthropic had experimented with a version of Claude Code that could identify Chinese users to prevent unauthorized resellers and distillation (training AI models on outputs from other AI models), but the company says it has since developed stronger security measures and plans to remove this detection feature.

Fix: According to Anthropic's Thariq Shihipar, 'The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while.' The source does not specify what these stronger mitigations are or provide a timeline for their implementation.

TechCrunch (Security)
Jul 4, 2026

Researchers discovered JadePuffer, believed to be the first ransomware attack fully controlled by an autonomous AI agent (a program that acts independently to complete tasks). The AI agent exploited a vulnerability in Langflow (a framework for building AI applications) to gain initial access, then automatically performed reconnaissance, stole credentials, moved through the network, and encrypted data while adapting to failures in real time, much like a human attacker would.

Fix: The vendor fixed CVE-2025-3248 on April 1, 2025. Additionally, CISA (Cybersecurity and Infrastructure Security Agency) tagged this vulnerability as exploited in attacks, warning organizations to patch internet-exposed endpoints.

BleepingComputer