aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchive
Stay Informed
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletterData SourcesAPIRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

[TOTAL_TRACKED]
1,998
[LAST_24H]
8
[LAST_7D]
171
Daily BriefingSaturday, March 7, 2026
>

OpenAI Launches Codex Security AI Agent for Vulnerability Detection: OpenAI deployed Codex Security, an AI-powered agent that scans code repositories for vulnerabilities; during beta testing it identified 792 critical and 10,561 high-severity issues across 1.2 million commits with false positive rates dropping over 50%.

>

Critical SSRF Vulnerability in PinchTab Browser Control Server: CVE-2026-30834 is a high-severity Server-Side Request Forgery flaw in PinchTab (pre-0.7.7), an HTTP server that gives AI agents Chrome browser control; the /download endpoint allowed arbitrary requests to internal network services and potential exfiltration of sensitive data.

>

Latest Intel

page 1/200
VIEW ALL
01

OpenAI robotics lead Caitlin Kalinowski quits in response to Pentagon deal

policyindustry

Anthropic and Pentagon at Odds Over AI Weaponization Safeguards: Anthropic refused to remove safety restrictions on Claude AI for military use, specifically blocking domestic mass surveillance and autonomous weapons capabilities; the Pentagon designated Anthropic a supply chain risk in response, while Anthropic vowed legal challenge, raising critical questions about AI governance in defense applications.

>

Anthropic's Claude Model Discovers 22 Firefox Security Flaws: Anthropic identified 22 previously unknown vulnerabilities in Firefox (14 high-severity) using Claude Opus 4.6 during a two-week security partnership with Mozilla, demonstrating AI agents' effectiveness at discovering complex security issues in mature codebases.

Mar 7, 2026

OpenAI robotics lead Caitlin Kalinowski resigned in protest of the company's Pentagon agreement, citing concerns about rushed governance and insufficient safeguards against domestic surveillance and autonomous weapons. OpenAI responded by stating its agreement includes red lines against domestic surveillance and autonomous weapons, supported by both contract language and technical safeguards, while committing to continued engagement with stakeholders on these issues.

TechCrunch
02

OpenAI delays ChatGPT’s ‘adult mode’ again

industry
Mar 7, 2026

OpenAI has delayed the launch of its 'adult mode' feature for ChatGPT, which was designed to give verified adult users access to adult content including erotica. The delay, the second postponement from the originally announced December launch, is attributed to the company prioritizing work on core features like intelligence, personality, and proactive functionality.

TechCrunch
03

OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

securityindustry
Mar 7, 2026

OpenAI has rolled out Codex Security, an AI-powered security agent that scans code repositories to identify and propose fixes for vulnerabilities. During beta testing, Codex Security scanned over 1.2 million commits and found 792 critical and 10,561 high-severity vulnerabilities across open-source projects, with false positive rates declining by over 50%.

The Hacker News
04

CVE-2026-30834: PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7,

security
Mar 7, 2026

CVE-2026-30834 is a Server-Side Request Forgery (SSRF) vulnerability in PinchTab, an HTTP server that provides AI agents with Chrome browser control. Prior to version 0.7.7, the /download endpoint allowed users with API access to make arbitrary requests to internal network services and local files, potentially exfiltrating sensitive response content.

Fix: This issue has been patched in version 0.7.7.

NVD/CVE Database
05

What does the US military’s feud with Anthropic mean for AI used in war?

policysafety
Mar 7, 2026

Anthropic is in a dispute with the U.S. Department of Defense over safety restrictions on its Claude AI model, specifically refusing to allow its use for domestic mass surveillance or autonomous weapons systems. The Pentagon has declared Anthropic a supply chain risk due to this refusal, while Anthropic has vowed to challenge the designation in court, raising questions about how AI will be regulated in military applications.

The Guardian Technology
06

The OpenClaw superfan meetup serves optimism and lobster

industry
Mar 7, 2026

OpenClaw, an open-source AI assistant platform created by Peter Steinberger in November 2025, held a fan convention called ClawCon in Manhattan that attracted hundreds of attendees. The event celebrated the platform's popularity in the tech industry, featuring interactive elements like sponsor stations and a demo stage.

The Verge (AI)
07

Pentagon’s Chief Tech Officer Says He Clashed With AI Company Anthropic Over Autonomous Warfare

policysafety
Mar 7, 2026

Pentagon CTO Emil Michael reported disagreements with AI company Anthropic regarding autonomous warfare capabilities. The military is developing procedures to enable varying levels of autonomy in warfare based on assessed risk levels.

SecurityWeek
08

Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model

securityresearch
Mar 7, 2026

Anthropic discovered 22 new security vulnerabilities in Firefox (14 high-severity, 7 moderate, 1 low) using its Claude Opus 4.6 AI model during a two-week security partnership with Mozilla in January 2026. Most of these vulnerabilities have been addressed in Firefox 148, released in late February 2026, with the remainder scheduled for upcoming releases.

Fix: Most issues have been fixed in Firefox 148, with the remainder to be fixed in upcoming releases.

The Hacker News
09

Trump’s cyber strategy emphasizes offensive operations, deregulation, AI

policyindustry
Mar 6, 2026

President Trump's cybersecurity strategy emphasizes offensive cyber operations as a central pillar of US policy, alongside deregulation of industry and accelerated AI adoption. The seven-page blueprint outlines six pillars including disrupting adversaries, promoting deregulation, modernizing federal networks with zero-trust architecture and AI-powered defenses, securing critical infrastructure, and maintaining technological superiority. The strategy represents a significant shift from past approaches by prioritizing offensive operations and AI integration while addressing federal system defense and critical infrastructure protection.

CSO Online
10

GHSA-8w32-6mrw-q5wv: WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool

security
Mar 6, 2026

WeKnora contains a critical Remote Code Execution vulnerability in its SQL validation framework where the validateNode() function in Phase 5 fails to recursively inspect PostgreSQL ArrayExpr and RowExpr node types, allowing attackers to smuggle dangerous functions like pg_read_file() inside array expressions and bypass all SQL injection protections. An unauthenticated attacker can chain these functions with large object operations to achieve arbitrary code execution on the database server.

GitHub Advisory Database
123...200Next