aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
8
[LAST_7D]
163
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 118/643
VIEW ALL
01

Anthropic wants to develop its own drugs

industry
Jul 3, 2026

Anthropic announced Claude Science, a new AI workbench (an integrated software environment where scientists can work) that combines fragmented tools and datasets to help scientists generate figures and visuals for research. The company claims this tool can speed up scientific discovery and drug development, and noted it already has biotech and pharmaceutical customers using Claude, with Anthropic itself planning to develop drugs.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

The Verge (AI)
02

Chinese LLMs Broaden the Gap Between Attackers & Defenders

securityindustry
Jul 3, 2026

New large language models (LLMs, AI systems trained on massive amounts of text) from Chinese companies are becoming competitive with leading US models. The article raises questions about whether cybersecurity defenders should be concerned about this development, though specific security implications are not detailed in the provided content.

Dark Reading
03

A behind-the-scenes look at Midjourney’s medical scanner leaves many questions unanswered

industry
Jul 3, 2026

Midjourney, an AI company known for image generation, has revealed more details about its experimental medical ultrasound scanner (a device that uses sound waves to create images inside the body) designed for spas, but has not yet provided convincing evidence that it actually works. The scanner combines multiple ultrasound probes with standard computers to attempt cheap, radiation-free medical imaging, though the technology remains largely unproven.

The Verge (AI)
04

CVE-2026-13341: A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow

security
Jul 3, 2026

CVE-2026-13341 is a vulnerability in Kong Konnect MCP (Model Context Protocol, a system for standardized communication between AI models and tools) server versions before 1.0.0 that allows remote attackers to perform prompt injection attacks (tricking the AI by hiding malicious instructions in input) and execute unintended API requests (commands to interact with web services).

NVD/CVE Database
05

Agentic AI Used to Conduct Ransomware Attack via Langflow

security
Jul 3, 2026

A threat actor exploited CVE-2025-3248 (a critical missing authentication vulnerability in Langflow, a Python framework for building AI-driven applications) to gain code execution on an exposed server, then used an agentic AI (an AI system designed to autonomously plan and execute multi-step tasks) to conduct reconnaissance, steal credentials, pivot to other systems, and deploy ransomware that encrypted databases. The AI adapted its actions in real time to overcome obstacles, demonstrating how LLM agents can lower the technical barrier for sophisticated cyberattacks.

SecurityWeek
06

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

security
Jul 3, 2026

Two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549, with CVSS score of 9.8, a 0-10 severity rating) in the Cursor AI code editor could allow attackers to execute code at the operating system level by exploiting the editor's automatic command execution without user approval. The first flaw allows attackers to change the working directory to bypass the sandbox (a restricted environment where code runs safely), while the second uses symbolic links (special files that point to other files) to write files outside the intended project directory and disable sandbox protections.

Fix: Patches for both vulnerabilities were included in Cursor 3.0, which was released on April 2.

SecurityWeek
07

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

industry
Jul 2, 2026

Anthropic clarified that Claude Fable 5 (its most powerful AI model) will move from subscription plans to usage-based billing (a pay-per-use system where you pay for each query) after July 7, but this is temporary, not permanent. The company plans to restore Fable 5 as a standard subscription feature once it has enough computing capacity to handle the high demand.

BleepingComputer
08

Claude Fable relaunch disappoints users with nerfed performance

safety
Jul 2, 2026

Claude Fable, a powerful AI model, was relaunched after a government ban was lifted, but users report it performs worse than before due to overly strict safety guardrails (automated rules that prevent certain outputs). The model frequently switches to a weaker alternative (Opus 4.8) even on tasks that don't seem risky, and it blocks requests containing security-related language, making it less useful for many coding tasks.

BleepingComputer
09

CVE-2026-45499: Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

security
Jul 2, 2026

CVE-2026-45499 is a server-side request forgery vulnerability (SSRF, a flaw where an attacker tricks a server into making unwanted network requests) in Azure OpenAI that allows an authorized attacker to gain elevated privileges over a network. The vulnerability has a CVSS score (severity rating from 0-10) that has not yet been assigned by NIST. Microsoft has published information about this vulnerability on their security update page.

NVD/CVE Database
10

CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege

security
Jul 2, 2026

CVE-2026-41106 is an open redirect vulnerability (a flaw where a website redirects you to an untrusted site) in Microsoft 365 Copilot that allows an attacker to gain unauthorized elevated privileges (higher access levels) over a network. The vulnerability has a CVSS score (severity rating) of 4.0. This is an exclusive service issue affecting Microsoft 365 Copilot users.

NVD/CVE Database
Prev1...116117118119120...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026