aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
9
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 117/643
VIEW ALL
01

CVE-2026-14535: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls A

security
Jul 4, 2026

In fickling (a security tool for analyzing pickle files), versions up to 0.1.11 have a bug where the UnsafeImportsML analysis pass marks all imports as already-checked in a shared list, causing the MLAllowlist pass (which is supposed to block imports from unsafe libraries) to skip its checks entirely. This means dangerous imports from standard library modules that aren't explicitly blocked can be deserialized and executed when fickling's security check returns LIKELY_SAFE.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

NVD/CVE Database
02

OpenAI’s apparent failure to visit key site raises questions over UK investment

industrypolicy
Jul 4, 2026

OpenAI paused its Stargate UK project, a planned multibillion-pound datacentre investment in Britain, citing regulatory concerns and high energy costs in April. An investigation revealed that OpenAI apparently never visited the key site in North Tyneside, and £20 billion of the £30 billion in investment that the UK government promoted appears to have been speculative rather than confirmed, raising questions about whether the project was primarily a publicity announcement rather than a genuine development plan.

The Guardian Technology
03

The fanfiction community is at war with AI — and itself

safety
Jul 4, 2026

Fanfiction communities are attempting to identify and remove works created using generative AI (large language models like Claude and ChatGPT that can create text automatically). However, the detection methods being used are unreliable and risk falsely accusing human writers of using AI.

The Verge (AI)
04

Could the next great novel be written by AI (and would you even be able to tell)?

industry
Jul 4, 2026

The article explores whether AI language models (LLMs, which are trained systems that predict and generate text) can write fiction indistinguishable from human authors, amid growing concerns about AI use in publishing and media. It examines what linguistic features actually differentiate human writing from machine-generated text, drawing on perspectives from linguists and established novelists like Jennifer Egan and Jeanette Winterson.

The Guardian Technology
05

CVE-2025-71372: Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all

security
Jul 3, 2026

Picklescan (a security tool that checks pickle files, which are Python files that serialize and deserialize objects) before version 0.0.33 fails to detect a specific dangerous code gadget called numpy.f2py.crackfortran.getlincoef that can hide in pickle __reduce__ methods (special functions that control how objects are reconstructed). This allows attackers to create malicious pickle files that execute arbitrary code when opened, potentially compromising shared model files in supply chains.

NVD/CVE Database
06

CVE-2025-71342: picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A

security
Jul 3, 2026

picklescan (a tool for detecting malicious code in pickle files, which are Python serialized objects) before version 0.0.30 has a vulnerability that allows attackers to hide malicious code in pickle files using a specific method (idlelib.run.Executive.runcode in reduce methods). When these files are loaded using pickle.load, the hidden code executes automatically, enabling RCE (remote code execution) and potential supply chain attacks on systems using PyTorch models.

NVD/CVE Database
07

A Layered Needs-Affordances-Features Approach to Advancing Artificial Intelligence Fairness in Hiring Systems

researchsafety
Jul 3, 2026

This research proposes a framework for making AI hiring systems more fair by addressing algorithmic bias (when AI systems make systematically unfair decisions against certain groups). The study analyzes real applicant data and finds that language differences in interviews and how interview questions are structured can cause unfair outcomes, but these problems can be reduced by modifying linguistic features (the words and language patterns used) and making interview questions more consistent across all applicants.

Fix: The source identifies two interventions demonstrated to reduce unfairness: (1) modifying linguistic features in interview responses, and (2) increasing interview structure (making questions more standardized). The study notes that 'the strongest fairness improvements observed when these interventions are jointly applied,' meaning combining both approaches together is most effective.

AIS eLibrary (Journal of AIS, CAIS, etc.)
08

CVE-2026-12481: A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser

security
Jul 3, 2026

A vulnerability in Keras (a machine learning library) version 3.14.0 allows attackers to run arbitrary code by exploiting how the Lambda layer deserializes data (converts stored data back into usable form). The bug occurs because the safety check treats an unset value the same as a deliberately disabled one, allowing malicious bytecode (low-level machine instructions) to execute when functions like `keras.layers.deserialize()` are called without proper safety protections.

NVD/CVE Database
09

AI prey: why watchdogs are telling parents to protect children from nudification apps

safetysecurity
Jul 3, 2026

Online predators are using nudification apps (AI tools that digitally remove clothing from images) to create fake sexual content of children from innocent photos posted online. The Report Remove service helps victims report and remove these explicit images from social media, but the widespread availability of these AI tools means children can be targeted without directly contacting criminals.

The Guardian Technology
10

NSW government ‘absolutely thrilled’ to welcome OpenAI ... until someone mentioned the Terminator films

industry
Jul 3, 2026

NSW government officials initially expressed enthusiasm about OpenAI opening a Sydney office, but removed language saying they were "absolutely thrilled" after staff members joked about dystopian AI scenarios similar to the Terminator films' Skynet (a fictional AI system that becomes hostile to humanity). The incident reflects some caution in how government communicates about AI expansion, even as it publicly encourages the technology.

The Guardian Technology
Prev1...115116117118119...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026