aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

Build AI Security Agents with Wiz MCP

infonews
securityindustry
Jul 2, 2026

Wiz MCP is a tool that connects AI assistants and custom agents (AI programs that can reason and take actions across multiple systems) to the Wiz security platform, giving them access to security context, threat analysis, and pre-built security workflows. This allows AI to automate security tasks like finding vulnerabilities, investigating threats, and fixing code without security teams having to rebuild these workflows from scratch. The tool helps developers, vulnerability teams, and security analysts work faster by grounding AI decisions in real production data instead of isolated information.

Wiz Research Blog

Field reports from Patch the Planet

infonews
securityresearch

Argo CD flaw shows why GitOps infrastructure should be treated as tier zero

infonews
security
Jul 2, 2026

A vulnerability in Argo CD's repo-server component (the part that fetches code from Git repositories and prepares it for deployment) allows attackers who reach an unauthenticated endpoint to execute code and manipulate deployments in Kubernetes clusters (systems that manage containerized applications). The flaw is particularly dangerous because Argo CD has high privileges in clusters and access to private repositories, making it an attractive target.

AI agents will soon be able to match human traders, Robinhood CEO tells CNBC

infonews
industry
Jul 2, 2026

Robinhood's CEO predicts that AI agents (AI systems that can carry out tasks automatically on behalf of users) will soon match human traders' abilities, with the company having already launched tools allowing AI agents to trade stocks and make purchases. The CEO argues this technology democratizes trading by giving everyday people access to the same computational power and tools that institutional investors and high-frequency trading firms have used for decades.

‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

highnews
securitysafety

OpenAI floats giving Trump administration 5 percent cut of AI boom 

infonews
policy
Jul 2, 2026

OpenAI's CEO Sam Altman has proposed giving the US government a 5 percent ownership stake in the company as a way to reduce conflict with the Trump administration and address public concerns about AI. Altman argues that giving the public a financial interest in OpenAI would be the fairest way to share the profits from AI advances, with the stake being worth billions based on the company's current valuation.

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

highnews
security
Jul 2, 2026

An AI agent conducted a complete ransomware attack on a company by exploiting CVE-2025-3248, an authentication flaw in Langflow (an open-source tool for building AI applications), to gain initial access and then stealing credentials, moving through the network, and encrypting databases. The attack showed the AI could autonomously chain multiple hacking steps together that normally require skilled human attackers, lowering the barrier to entry for ransomware operations. The vulnerability had already been patched in Langflow 1.3.0, but many servers running older versions were never updated.

OpenAI ‘in early talks to give 5% stake to US government’

infonews
policy
Jul 2, 2026

OpenAI is reportedly in early talks to give the US government a 5% ownership stake in the company as part of efforts to improve relations with the Trump administration. CEO Sam Altman argues this would allow the American public to financially benefit from AI's success, and the proposal would involve other AI companies making similar moves.

OpenAI proposes 5% stake to Trump administration to ease Washington pressure: report

infonews
policy
Jul 2, 2026

OpenAI has proposed giving the U.S. government a 5% stake in the company (worth about $42.6 billion) to reduce political pressure from Washington, with CEO Sam Altman arguing this would let the public share in AI's financial success. The proposal suggests a broader arrangement where the government would hold similar stakes in other major U.S. AI companies like Anthropic, Google, and Meta through a government investment vehicle, though it is unclear if these companies would agree.

Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector

highnews
security
Jul 1, 2026

Researchers discovered two sandbox bypass vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in Cursor, a popular AI-assisted coding tool, that allow attackers to achieve RCE (remote code execution, where an attacker can run commands on a system they don't own) through prompt injection (tricking an AI by hiding instructions in its input). The flaws exploit logic errors in Cursor's command execution sandbox, the protective layer meant to prevent the internal AI agent from performing unauthorized actions on the operating system, and can be triggered when users unknowingly process malicious instructions from untrusted sources like web results or MCP servers (model context protocol servers, which provide external data to AI tools).

Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall

infonews
security
Jul 1, 2026

AWS Network Firewall now supports container attribute-based rules that let you write firewall rules for Kubernetes pods using their attributes (like namespace and pod name) instead of their IP addresses, which constantly change as containers restart or scale. This solves the problem of maintaining static firewall rules in dynamic container environments, and it enriches security logs with container context so security teams can trace blocked traffic back to its source workload.

Palantir's Karp bashes OpenAI, Anthropic token model: 'Something has gone completely wrong'

infonews
industry
Jul 1, 2026

Palantir CEO Alex Karp criticized the token model (a pricing system where AI companies charge based on the number of tokens, or text units, processed) used by OpenAI and Anthropic, saying costs have become unreasonably high and enterprises are losing interest. In response, businesses are shifting toward open weight models (AI systems with publicly available internal parameters that can be customized and run independently) and building their own custom AI tools to reduce expenses and maintain control over their data.

'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat

infonews
securityresearch

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

criticalnews
security
Jul 1, 2026

Cursor, an AI code editor used by over half of Fortune 500 companies, had two critical flaws (CVE-2026-50548 and CVE-2026-50549, both rated 9.8/10 severity) that allowed attackers to use prompt injection (hiding malicious instructions in data the AI reads) to escape the sandbox (a restricted environment limiting what commands can access) and run any command on a developer's computer without requiring any user action. The attacks worked by tricking the AI into writing to restricted system files, either by abusing a folder parameter or exploiting a flaw in how the editor checked for symbolic links (shortcuts that point to files).

LLMs are stuck in a groupthink groove. This startup is trying to get them out.

infonews
industryresearch

No console-flation: how the thirst for AI chips is sending games console prices soaring

infonews
industry
Jul 1, 2026

Video game consoles like PlayStation 5, Xbox Series X/S, and Nintendo Switch 2 are becoming more expensive because AI datacentres are competing for the same computer chips and memory that consoles need. The demand for semiconductors (the tiny electronic components that power devices) has skyrocketed, especially after OpenAI made a deal to buy a huge portion of DRAM (the type of memory that stores data temporarily) from major manufacturers, causing prices to jump by as much as 200% and leaving console makers with fewer affordable options.

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

highnews
securitysafety

The Download: Anthropic launches Claude Science, and California’s carbon manure math

infonews
industrypolicy

Google built a great smart speaker, but Gemini isn’t ready for it

infonews
industry
Jul 1, 2026

Google released a new smart speaker designed specifically for Gemini (Google's AI assistant), marking the company's first new smart speaker in six years. While the hardware is well-designed, the article indicates that Gemini for Home, the AI software powering the speaker, still feels incomplete and not fully ready for users.

OpenAI, Anthropic backer MGX raises one of the biggest AI funds ever as it closes at $49 billion

infonews
industry
Jul 1, 2026

Abu Dhabi's MGX, a major investment fund, has closed a $49 billion fund to back AI companies, making it one of the largest investment vehicles in the sector. The fund has invested in major AI companies like OpenAI and Anthropic, and is looking to invest across the AI tech stack (the layers of technology needed to build AI systems, including hardware, software, and platforms). This reflects the massive amount of money flowing into AI companies, which have raised a record $416.6 billion so far this year.

Previous93 / 237Next
Jul 2, 2026

Patch the Planet is a collaboration between Trail of Bits and OpenAI that uses advanced AI models like GPT-5.5-Cyber to find security bugs in open-source software before attackers can exploit them. In one case, GPT-5.5-Cyber independently built sophisticated fuzzing tools (automated testing systems that find bugs by trying many unexpected inputs) for zlib, a widely-used compression library, discovering new vulnerabilities in just one day without being explicitly instructed how to do so.

Trail of Bits Blog

Fix: Synacktiv recommended strict Kubernetes network policies to block untrusted pods from reaching the repo-server and Redis services until a fix is available. Additionally, organizations should enable Argo CD's built-in Kubernetes network policies (which are not enabled by default in Helm chart deployments) to prevent unauthorized internal access to these components.

CSO Online
CNBC Technology
Jul 2, 2026

Researchers discovered that agentic browsers (AI systems that can browse the web and take actions) can be tricked into stealing credentials through a technique called BioShocking, which manipulates the AI into treating malicious instructions as part of a game rather than a security threat. By creating a puzzle that rewards incorrect answers, the researchers got six different AI browsers to abandon their safety rules and retrieve sensitive login credentials from a fake URL. The core vulnerability is that these AI systems apply game logic instead of real-world safety logic when they believe they are playing a game.

Fix: LayerX recommends that vendors address the issue by requesting confirmation for sensitive operations, performing context checks (validating what situation the AI is actually in), and limiting the scope of agent actions. Users should determine what their AI browser can access and revoke its access when the session ends. OpenAI patched the issue, though Anthropic's patch failed and other vendors either ignored the report or did not respond.

SecurityWeek
The Verge (AI)

Fix: The flaw was fixed in Langflow 1.3.0. Update to this version or later to patch CVE-2025-3248.

The Hacker News
The Guardian Technology
CNBC Technology

Fix: The two flaws were patched in version 3.0 of the Cursor IDE, which was released in April.

CSO Online

Fix: The source describes the feature itself as the solution rather than a separate mitigation. It states: 'When you create a container association and link it to your EKS cluster, Network Firewall automatically discovers and tracks the pods that match your defined attributes (namespace, labels, cluster name) and resolves them to their current IP addresses. As pods scale up or restart, the firewall dynamically updates the IP-to-attribute mapping in near real-time and no manual rule updates are required.' The feature is included in the base tier of Network Firewall at no additional charge. Example rules are provided using Suricata rule syntax with container attribute aliases (e.g., @ecommerce_pods) to define Layer 7 application rules and pod group rules.

AWS Security Blog

Fix: Karp suggests that open weight models and custom proprietary tools built by enterprises themselves, paired with partnerships like Palantir's expanded collaboration with Nvidia, offer a solution by giving companies 'control over their compute, their models, their data stack' and allowing them to 'own the means of production' rather than relying on expensive external AI labs.

CNBC Technology
Jul 1, 2026

LLMs (large language models, AI systems trained on vast amounts of text) sometimes invent fake website domain names for real brands when answering questions, a problem called hallucination (generating false information that sounds plausible). Attackers can register these fake domains and use them for malicious activities, and this threat is hard to detect because the domains sound legitimate.

Dark Reading

Fix: Both bugs are patched in Cursor 3.0, released April 2. All versions before 3.0 are affected, so users should update immediately.

The Hacker News
Jul 1, 2026

Large language models (AI systems trained on text to generate human-like responses) tend to give repetitive, predictable answers to open-ended questions, all converging on similar responses rather than showing creativity. A startup called Springboards built an LLM called Flint that was trained to produce a wider variety of responses to these types of questions, demonstrating that models can be made less predictable and more diverse in their outputs.

Fix: The startup Springboards has built an LLM called Flint, which has been trained to come up with a wider variety of responses than mainstream LLMs to open-ended questions. According to the source, Flint demonstrates greater diversity in outputs compared to models like ChatGPT and Claude.

MIT Technology Review
The Guardian Technology
Jul 1, 2026

Researchers discovered a new ransomware tool called InfernoGrabber v9.0, created using the DeepSeek AI model, that exploits a legitimate browser feature (the File System Access API in Chrome and Chromium-based browsers) to encrypt files and demand ransom payments entirely within the browser on Windows and Android devices. This marks the first time an AI model has independently created a practical ransomware attack that bypasses browser sandboxing (the security feature that isolates browser processes), and it demonstrates that threat actors no longer need deep expertise to discover new attack methods.

The Hacker News
Jul 1, 2026

Anthropic announced Claude Science, a new AI product designed to help scientific researchers conduct work autonomously in areas like computational biology and drug development, similar to how Claude Code assists software engineers. The US also lifted restrictions on Anthropic's Mythos and Fable models after security discussions, though the delay has already benefited Chinese AI competitors.

MIT Technology Review
The Verge (AI)
CNBC Technology