Definition
- 2026-07: Copilot Word ai-worm expands prompt-injection to self-propagating document carriers (2026-08-01-microsoft-copilot-word-prompt-injection-worm)
AI Security encompasses securing AI systems, AI-powered threat detection, and vulnerabilities introduced by AI coding agents and autonomous tools.
July 2026: GhostApproval
wiz disclosed ghostapproval — symlink attack affecting six AI coding assistants (Claude Code, Cursor, Amazon Q, Google Antigravity, Augment, Windsurf). Malicious repos bypass sandbox and human-in-the-loop confirmation via path deception (2026-07-09-ghostapproval-wiz-primary).
Distinct from hallusquatting (hallucinated package names).
July 2026: Defender tooling & AIDR inference
- cisco-antares open-weight vuln-localization SLMs (2026-07-23-cisco-antares-open-weight-vuln-localization)
- crowdstrike × cerebras for falcon-aidr inference (2026-07-23-crowdstrike-cerebras-primary-pr)
July 2026: Open Secure AI Alliance
nvidia-led open-secure-ai-alliance launches open defense stack (nooa, MDASH, Lightwell, Safetensors, Grok Build) after hugging-face-ai-agent-security-incident. Position: open weights/harnesses as defender assets (2026-07-27-nvidia-open-secure-ai-alliance-blog). See open-secure-ai-defense.
Key Concepts
- Trust boundary gaps in AI coding agents
- Adversarial attacks on machine learning models
- AI-powered threat detection and response
- Securing AI training pipelines from poisoning
- Supply chain attacks via malicious repositories