aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,364
[LAST_24H]
21
[LAST_7D]
174
Daily BriefingWednesday, August 12, 2026
>

Google's DeepMind Falls Behind in Frontier Model Race: Google's AI division has lost ground to OpenAI and Anthropic in developing the most advanced AI systems, prompting a leadership change to close the performance gap, particularly in coding capabilities where competitors hold significant advantages.

>

Critical Flaw in OpenAI, Anthropic, and Google APIs Exposes Hidden Reasoning: Researchers discovered a vulnerability in how major AI providers handle encrypted reasoning objects (encrypted data storing an AI's hidden thinking between API calls) that allowed weaker models to decode stronger models' concealed thoughts, exposing API keys, passwords, private user data, and enabling injection of malicious prompts inside supposedly opaque blocks.

>

Latest Intel

page 1/637
VIEW ALL
01

Twitch streamers can now opt out from training Amazon’s AI

policyprivacy
Critical This Week5 issues
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026

Snowflake Python API Vulnerability Enables Privilege Escalation: CVE-2026-19594 in Snowflake Python API versions before 1.13.0 allowed attackers to bypass security restrictions through path traversal (using `..` to access parent resources) and HTTP parameter pollution (injecting special characters to alter request interpretation), potentially executing privileged operations under higher-permission accounts.

>

Fujitsu's OneCompression Library Vulnerable to Code Execution via Malicious Models: CVE-2026-73325 in OneCompression 1.2.0 unsafely deserializes (converts data back into executable code) checkpoint files using Python's pickle module, allowing attackers to run arbitrary commands by embedding malicious instructions in model.pt files that execute when the library loads them.

>

Context Bombing Uses Prompt Injections as Defensive Tool: Researchers demonstrated that embedding prompt injections (hidden instructions that override AI guidelines) alongside secrets in cloud storage can disable AI hacking agents by triggering their guardrails (built-in protections preventing harmful outputs), causing the agents to shut down rather than follow attacker instructions.

Aug 12, 2026

Twitch has added an opt-out feature that lets streamers prevent their content (streams, videos, chats, and channel text) from being used to train Amazon's generative AI models (AI systems that create new text, audio, images, or video). Other AI features like automatic captions will still work even if you opt out, though chat content on other people's streams is governed by their opt-out settings.

Fix: Users can opt out of generative AI training through Twitch's settings. According to Twitch, opting out means that 'your streams, VODs, clips, stream chats, and pictures and text on your channel' won't be used in 'future training' of Amazon's generative AI model. Note that 'AI-supported' features like captions and safety tools will continue to function after opting out.

The Verge (AI)
02

Scaling AI agents with trustworthy data

industry
Aug 12, 2026

AI agents (autonomous systems that can make decisions and take actions) are becoming central to business operations, but many organizations struggle because their legacy data systems (older infrastructure that wasn't designed for modern needs) can't provide agents with fast access to the data they need across the entire company. The report found that while most companies only give AI agents access to about 45% of their data, "data leaders" who provide access to over 70% of their data see much better results, with 100% trust in agent decisions compared to only 50% trust at other organizations.

MIT Technology Review
03

Google’s new Pixel 11 puts Gemini at center of AI phone battle with Apple

industry
Aug 12, 2026

Google launched its new Pixel 11 smartphone lineup featuring Gemini Intelligence, a suite of AI features that can understand what users are doing on their phone and take actions across different apps, such as checking calendar availability or starting restaurant reservations. This puts Google in direct competition with Apple, which is rebuilding its Siri voice assistant using Google's Gemini models. Google executives argue that Pixel's deeper integration of AI into Android's operating system and exclusive features like scam detection distinguish their approach from Apple's implementation.

CNBC Technology
04

CVE-2026-73325: Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers t

security
Aug 12, 2026

Fujitsu Research's OneCompression library version 1.2.0 has a vulnerability where it unsafely deserializes (converts data back into usable code) checkpoint files using Python's pickle module, allowing attackers to run arbitrary code by providing a malicious model.pt file. When the library loads a model file, it can execute hidden malicious instructions that attackers have embedded in the file, potentially compromising the entire system.

NVD/CVE Database
05

Guitar company D’Addario admits that AI music was used in a promotional video

industry
Aug 12, 2026

Music company D'Addario initially denied using AI-generated music in a promotional video but later admitted it had used Suno (an AI music generation tool) after weeks of public controversy and mounting evidence. The company offered several false explanations, including blaming low-quality exports and audio processing software, before finally editing its original post to acknowledge the use of generative AI (software that creates new content based on patterns learned from training data).

The Verge (AI)
06

CVE-2026-73264: Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce

security
Aug 12, 2026

Prowler is a cloud security platform that had a vulnerability in versions before 5.33.1 where authenticated users could trick the system into sending API keys (secret credentials used for authorization) to attacker-controlled or internal endpoints by providing a malicious URL through the Lighthouse provider configuration.

Fix: Update Prowler to version 5.33.1 or later, where this issue is fixed.

NVD/CVE Database
07

AI agents aren’t legally responsible for any harm that they cause, experts say. So who is?

policysafety
Aug 12, 2026

AI agents themselves cannot be held legally responsible for damage they cause, but the people and companies that deploy them (put them into use) can be held liable instead. Experts warn that deployers should take responsibility for foreseeable harms their AI agents might cause, even if the harm wasn't intentional.

The Guardian Technology
08

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens

securityindustry
Aug 12, 2026

Cyber attacks increased significantly in July 2026, with organizations experiencing an average of 2,336 weekly attacks, a 16% increase from the previous year, while the use of GenAI tools (artificial intelligence systems that generate text or code) created new security risks with 1 in 36 prompts (user inputs to AI systems) exposing sensitive data. Education was the most targeted industry, and email remained a major vulnerability, with phishing attacks (fraudulent emails designed to trick users into revealing information) occurring in 1 out of every 128 emails.

Check Point Research
09

Of course the ChatGPT dog cancer vaccine spawned a startup

industry
Aug 12, 2026

An Australian entrepreneur named Paul Conyngham used AI tools like ChatGPT and Grok (language models that can process and generate text) to help design a personalized cancer vaccine for his dog, and has now launched a startup called Gamgee to commercialize this approach. The company plans to develop customized mRNA cancer vaccines (vaccines built from genetic material tailored to individual patients) for dogs initially, but aims to expand to treating various diseases in other animals and humans using AI and genetic analysis.

The Verge (AI)
10

Grok is now an AI ‘teammate’ you can assign work

industry
Aug 12, 2026

SpaceXAI has launched Grok Bot, an AI agent service that works like an independent "AI teammate" to complete workplace tasks by signing into your online accounts and using apps and websites on your behalf. The bot operates in its own cloud environment and only returns when its assigned work is done or human approval is needed, competing with similar services from OpenAI, Anthropic, and Microsoft.

The Verge (AI)
123...637Next
critical

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

CVE-2026-73032NVD/CVE DatabaseAug 11, 2026
Aug 11, 2026
critical

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898CISA Known Exploited VulnerabilitiesAug 10, 2026
Aug 10, 2026
critical

CVE-2026-72718: goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system

CVE-2026-72718NVD/CVE DatabaseAug 10, 2026
Aug 10, 2026
critical

CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

CVE-2026-14526NVD/CVE DatabaseAug 8, 2026
Aug 8, 2026