aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,423
[LAST_24H]
10
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

Critical RCE in Cortex MCP Server: CVE-2026-49986 affects the Cortex MCP server (a tool enabling AI assistants like Claude to access persistent memory across projects) before version 3.17.1, allowing arbitrary Python code execution when an attacker plants malicious files in a repository and the `open_visualization` tool is invoked. The vulnerability stems from inadequate validation of project directories set by Claude Code, enabling attackers to run commands with user privileges.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera's acquisition of Oasis Security combines data security and identity management into a unified control system for AI agents (autonomous software programs), shifting from fixed permission roles to context-aware access based on business needs.

Latest Intel

page 109/643
VIEW ALL
01

Cybersecurity and the Gap Between Skill and Ability

securitysafety
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
>

OpenAI Faces Executive Exodus Ahead of IPO: OpenAI is experiencing significant departures of senior leadership, including Chief Revenue Officer Denise Dresser and Operating Chief Brad Lightcap, as the company prepares for its initial public offering. Industry observers view the exits as a potential warning sign that could undermine investor confidence amid intensifying competition from Google and Anthropic.

>

Google Enables Watermark Removal for Gemini-Generated Media: Google now allows users to disable visible watermarks on AI-generated images, videos, and music in Gemini and Flow, though invisible SynthID watermarks and C2PA metadata (hidden markers tracking AI-generated content) remain embedded in all outputs.

Jul 8, 2026

National security agencies from the Five Eyes (the English-speaking allies: US, UK, Canada, Australia, New Zealand) warned that AI models can now autonomously hack into systems and networks, expanding what untrained people can do with minimal skill. The core problem is that AI has decoupled skill from ability: whereas hacking once required deep technical knowledge, AI tools now let anyone with little expertise cause major damage through attacks like data theft, ransomware (malicious software that locks files until payment is made), and system destruction. The text suggests that defending against this will require using AI itself for protection, but notes that open-source models (AI code anyone can download and run locally) lack safety guardrails and will spread like earlier hacker tools.

Schneier on Security
02

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

security
Jul 8, 2026

A critical vulnerability called GitLost affects GitHub Agentic Workflows (AI agents that automate repository interactions by reading natural language instructions in markdown files). Attackers can exploit prompt injection (tricking an AI by hiding instructions in its input) in public GitHub Issues to make the AI agent leak private repository data, even without credentials or coding skills. GitHub's security protections failed against variations of the attack, such as adding the keyword "additionally" to bypass safeguards.

Fix: The source mentions recommendations from Noma Labs but does not describe an explicit fix or patch from GitHub. The recommendations include: treat all user-controlled content as untrusted, restrict agent permissions to the minimum required, restrict what agents can post publicly, and sanitize user input before it is passed to the AI agents. However, these are suggested best practices, not a confirmed mitigation or update from GitHub.

SecurityWeek
03

Helping K–12 educators build practical AI skills

industry
Jul 8, 2026

OpenAI Academy is hosting in-person workshops called the AI Skills Jam for K–12 Educators across eight U.S. cities to help teachers and school administrators learn practical ways to use AI tools in their work. Research shows teachers who use AI weekly save an average of 5.9 hours per week, which they reinvest in activities like better student feedback and lesson planning. During the Jam, educators will work with OpenAI mentors on real classroom tasks and gain access to OpenAI Academy, a free online platform with ongoing resources for responsible AI use in education.

OpenAI Blog
04

CISA orders feds to prioritize patching Langflow auth bypass flaw

security
Jul 8, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch an actively exploited vulnerability in Langflow, a popular tool for building AI agents with a drag-and-drop interface. The flaw, tracked as CVE-2026-55255, is an IDOR (insecure direct object reference, where an attacker can access data they shouldn't by manipulating request parameters) that lets authenticated attackers view other users' workflows and steal sensitive data or computing resources. Attackers are already using this vulnerability to gain code execution and deploy malware to compromise servers and steal credentials.

Fix: CISA ordered federal agencies to patch the vulnerability by Friday, as required by Binding Operational Directive (BOD) 26-04. The source states that 'stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines,' but does not provide specific patch version numbers or technical patching instructions.

BleepingComputer
05

OpenAI secures U.S. regulatory green light for GPT-5.6 rollout, Axios report says

policy
Jul 8, 2026

The U.S. Department of Commerce has approved OpenAI to release its GPT-5.6 model widely, with the rollout expected to begin this week after additional testing and government meetings. This decision reflects the Trump administration's hands-on approach to AI regulation (government oversight of AI system capabilities before release), which has also affected competitors like Anthropic whose Claude models faced temporary suspension.

CNBC Technology
06

China warns about AI risks with Anthropic's Claude Code

security
Jul 8, 2026

China's government reported that Anthropic's Claude Code, an AI tool for automated coding, contains a back-door vulnerability (a hidden security flaw that lets attackers access a system they shouldn't be able to reach) that can secretly send sensitive user information like location and identity to a remote server. This warning intensifies tensions in the U.S.-China tech competition, as Chinese companies and individuals have been using this American AI tool despite it not being officially available in China.

Fix: According to China's cybersecurity platform, users should uninstall or upgrade from the affected Claude Code versions 2.1.91 to 2.1.196 (released from April 2 to June 29). The latest version as of the report date is 2.1.204.

CNBC Technology
07

State IDs for AI Agents: Will Estonia Set a Precedent?

policy
Jul 8, 2026

Estonia is exploring the creation of state-issued digital identities for AI agents (autonomous programs that can perform tasks without direct human control), which would allow these agents to interact with government services. This initiative positions Estonia as a potential leader in establishing rules and standards for how AI agents can be officially recognized and used in government contexts.

Dark Reading
08

Lawmakers probe growing use of Chinese AI models in U.S. companies

policyindustry
Jul 8, 2026

U.S. lawmakers are investigating why American companies are adopting Chinese AI models, which are becoming competitive with American alternatives while costing less. Concerns focus on whether these models could advance China's political interests or pose cybersecurity risks, though using Chinese AI models is not currently banned for U.S. companies (unlike some government departments).

CNBC Technology
09

Introducing GPT-Live

industry
Jul 7, 2026

OpenAI has launched GPT-Live, a new voice AI model that uses full-duplex architecture (the ability to listen and speak simultaneously) to make conversations feel more natural and human-like. Unlike earlier voice systems that processed speech in separate steps or waited for users to finish speaking, GPT-Live can continuously process audio, respond expressively, and delegate complex tasks to more powerful backend models while maintaining conversation flow.

OpenAI Blog
10

CVE-2026-59706: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f

security
Jul 7, 2026

mem0 (a software tool) has a critical security flaw where API endpoints lack authentication (verification of user identity), allowing attackers to steal LLM API keys (credentials used to access AI services) stored in plaintext, and exploit SSRF attacks (server-side request forgery, where an attacker tricks a server into making requests to unintended internal systems) by controlling the ollama_base_url parameter. The vulnerability has a CVSS score of 9.2, indicating it is extremely severe.

NVD/CVE Database
Prev1...107108109110111...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026