aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Industry News

New tools, products, platforms, funding rounds, and company developments in AI security.

to
Export CSV
4740 items

New macOS malware embeds fake errors to confuse AI analysis tools

mediumnews
securitysafety
Jun 25, 2026

A macOS malware called "Gaslight" uses prompt injection (tricking an AI by hiding instructions in its input) to confuse AI-powered malware analysis tools by embedding fake error messages, crash reports, and debugging data within the executable file. The malware contains 38 fabricated system messages designed to make LLM (large language model)-assisted analysis tools question their own sessions or stop analyzing the malware, rather than trying to evade detection in sandboxes (isolated test environments). Researchers attribute the malware to a North Korean-linked threat actor, and while it hasn't been shown to successfully bypass current AI analysis platforms, it suggests attackers are developing new anti-analysis techniques targeting AI-based security tools.

BleepingComputer

Computer-Use and TOCTOU: What You Click Is Not What You Get!

mediumnews
securityresearch

Ford had to hire back former engineers to fix mistakes made by its automated systems

infonews
industry
Jun 25, 2026

Ford's automated systems and AI models made production and design errors that required the company to hire experienced technicians, sometimes rehiring former employees, to fix the mistakes. Ford acknowledged that while AI is powerful, it is prone to errors that depend heavily on the quality of training data (the information used to teach AI models how to work).

Interesting Paper Exploring Prompt Injection

infonews
researchsafety

Rethinking the balance between AI oversight and innovation

infonews
policyindustry

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

highnews
securitysafety

Anthropic's latest hiring spree reveals where it's building AI data centers next

infonews
industry
Jun 25, 2026

Anthropic, a major AI company, is rapidly expanding its data center operations in Asia-Pacific by hiring 13 people, with eight positions in Australia and Japan, to handle increasing demand for its AI products. The company is building infrastructure in these regions because they offer advantages like renewable energy, political stability, and security benefits, though Australia's copyright laws present a potential obstacle to large-scale expansion.

How agents are transforming work

infonews
industry
Jun 24, 2026

Agentic AI (AI systems that can work independently on tasks for extended periods, rather than just answering single questions) is transforming how people work by handling longer, more complex tasks instead of short interactions. At OpenAI, a tool called Codex shifted from being used mainly by engineers to becoming the primary AI tool across all departments, including non-technical ones like Legal and Recruiting, with usage growing dramatically over the past year. Users increasingly delegate tasks that would take humans hours or even days to complete, with some users running dozens of hours of parallel agent tasks in a single day.

Congresswoman denies staff used AI to write defense funding amendment

infonews
policyindustry

v0.14.23

infonews
security
Jun 24, 2026

LlamaIndex v0.14.23 is a maintenance release that updates dependencies (uv and pip, which are Python package managers) across multiple directories and fixes various bugs in the core library. Key fixes include handling empty input sequences, preserving video and document blocks in memory, resolving recursion errors in text splitting, and preventing state mutation issues in workflows.

From Prompt Testing to AI Red Teaming at Enterprise Scale

infonews
security
Jun 24, 2026

The article explains that while casual prompt testing (trying unusual inputs to see if an AI refuses them) is accessible to anyone, it is insufficient for enterprise AI systems. Enterprise AI is more complex because it includes policies, retrieval pipelines (systems that fetch information from databases), APIs (interfaces allowing programs to communicate), tools, permissions, workflows, and data sources, requiring more rigorous testing approaches.

Broadcom stock needs a win. The new OpenAI co-designed Jalapeno chip might do the trick

infonews
industry
Jun 24, 2026

This article discusses Broadcom's stock performance and mentions a new AI chip called Jalapeno that was co-designed with OpenAI. The article suggests this chip development could be a significant business opportunity for Broadcom.

When Information Becomes the Attack Surface – Understanding AI Agent Traps

infonews
securityresearch

Scattered Spider duo convicted over $38M Transport for London attack

infonews
security
Jun 24, 2026

Two members of Scattered Spider, a cybercrime collective, were convicted for attacking Transport for London's network in September 2024, which disrupted services, exposed personal data of 10 million people, and caused £29 million in damages. Thalha Jubair and Owen Flowers used social engineering and help-desk impersonation tactics to compromise TfL systems. The group is known for targeting IT support providers to bypass multi-factor authentication (security that requires multiple verification methods) and gain unauthorized access to networks.

The $27 million Al proxy war over Alex Bores ends in a draw

infonews
policy
Jun 24, 2026

A $27 million political campaign between AI companies Anthropic and OpenAI, fought through a super PAC (a political organization that can raise unlimited funds), ended without a clear winner when Alex Bores, a New York politician who had authored AI safety legislation, narrowly lost a Democratic primary election. Bores had previously passed the RAISE Act, which added safety requirements for advanced AI companies, but this legislation upset the pro-AI super PAC that opposed him.

More Malicious OpenClaw Skills Threaten AI Supply Chain

highnews
security
Jun 24, 2026

OpenClaw, an AI skills marketplace called ClawHub, discovered and removed five malicious packages that had bypassed security checks despite containing infostealers (malware that steals information like passwords and data). This incident demonstrates that threats can slip through marketplace defenses and compromise the AI supply chain (the network of tools and components used to build AI systems).

Introducing computer use in Gemini 3.5 Flash

infonews
safetysecurity

Figma now has AI motion graphics and shader tools

infonews
industry
Jun 24, 2026

Figma announced new AI-powered design features at its Config conference, including AI-generated motion graphics (animations created by describing them to an AI chatbot) and coding layers that let developers edit code without leaving the design canvas. These updates aim to help creative teams automate repetitive tasks and work more efficiently in one integrated workspace.

OpenAI unveils first chip as part of Broadcom deal in effort to 'build the full stack'

infonews
industry
Jun 24, 2026

OpenAI and Broadcom unveiled Jalapeño, OpenAI's first custom AI chip designed for inference (the process of running trained AI models to generate responses for users). The chip is an ASIC (application-specific integrated circuit, a processor built for one particular job rather than general computing), which is cheaper and more efficient than standard graphics processors but less flexible, and OpenAI designed it in nine months with help from its own AI models to address extreme demand for computing power.

OpenAI reveals its first AI processor: Jalapeño

infonews
industry
Jun 24, 2026

OpenAI has announced a new chip called Jalapeño, an ASIC (application-specific integrated circuit, a processor designed for one particular job) built with Broadcom to power AI servers. The chip is specifically designed for AI inference (the process where a trained AI model processes user requests and generates responses), rather than AI training (where models learn from large amounts of data).

Previous98 / 237Next
Jun 25, 2026

A TOCTOU attack (time-of-check to time-of-use, a type of race condition where a system checks something and then uses it, but the situation changes in between) can trick AI agents that control computers by changing what's on the screen while the AI is thinking. For example, an attacker can swap out a button with a different one, or overlay a fake button on top of a real one, so the AI clicks something it didn't intend to, like sending an email or visiting a malicious site.

Fix: "Ensure that the UI hasn't changed before taking an action." Anthropic addressed this in Claude Computer-Use by implementing a check to "ensure that pixels haven't changed before action," according to Felix Rieseberg's announcement when the feature shipped.

Embrace The Red
The Verge (AI)
Jun 25, 2026

A research paper shows that large language models (LLMs) are vulnerable to prompt injection attacks (tricks where attackers hide malicious instructions in text input) because they rely on role tags (formatting markers that separate different instruction blocks) as their main security mechanism, but these tags don't actually reflect how the model processes information internally. The researchers conclude that unless LLMs develop a genuine ability to understand and maintain role boundaries, prompt injection attacks will remain difficult to prevent permanently.

Schneier on Security
Jun 25, 2026

CIOs face pressure to rapidly adopt AI across their organizations to prove business value, but must balance this speed with managing new security and governance risks. AI introduces unique challenges because its behavior is indeterminate (unpredictable and hard to verify like traditional technology) and employees are eager to use it without oversight, creating what's called shadow use (unauthorized use of tools that bypasses IT controls). Organizations should clarify their specific business goals and conduct a risk assessment before implementing AI rather than adopting it out of fear of falling behind.

CSO Online
Jun 25, 2026

A new malware called Gaslight, created by North Korea-aligned hackers, targets macOS systems and uses prompt injection (tricking an AI by hiding instructions in its input) to disrupt AI tools that analyze malware. The malware embeds fake system-failure messages designed to confuse AI-assisted analysis tools, while also stealing sensitive data like browser histories and passwords through a command-and-control (C2, a server that lets attackers remotely control infected computers) channel powered by Telegram.

The Hacker News
CNBC Technology
OpenAI Blog
Jun 24, 2026

A U.S. Congresswoman claimed her staff used AI only for "spellcheck" when writing a summary of a defense bill amendment, not for drafting the actual legislation. Screenshots shared online showed what appeared to be Claude (an AI assistant) being used to generate the amendment summary, prompting the congresswoman to deny that AI was used to write any actual laws.

The Verge (AI)
LlamaIndex Security Releases
Check Point Research
CNBC Technology
Jun 24, 2026

AI agents that can autonomously access websites, emails, and files are vulnerable to 'traps' - maliciously designed information that tricks them into wrong actions. These traps include content injection (hiding malicious instructions in webpage code or metadata), semantic manipulation (using repetition and emotional language to guide decisions), and cognitive state attacks (poisoning databases that agents rely on for memory), with research showing such attacks succeed 57-90% of the time depending on the type.

SecurityWeek
CSO Online
The Verge (AI)
Dark Reading
Jun 24, 2026

Google has added computer use, a capability that allows AI agents to see and interact with computer screens to perform tasks, directly into Gemini 3.5 Flash (an AI model). This feature enables developers to build agents that can automate work across browsers, phones, and desktops, such as testing software or handling business tasks.

Fix: To mitigate prompt injection risks (attacks where malicious instructions are hidden in user inputs), Google uses targeted adversarial training for computer use in Gemini 3.5 Flash. The company also released two optional enterprise safeguard systems: one that requires explicit user confirmation for sensitive or irreversible actions, and another that automatically stops tasks if an indirect prompt injection is identified. The source recommends combining these features with secure sandboxing, human-in-the-loop verification (having humans review AI decisions), and strict access controls.

DeepMind Safety Research
The Verge (AI)
CNBC Technology
The Verge (AI)