aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
8
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 123/643
VIEW ALL
01

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

securitysafety
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

Jul 1, 2026

Researchers discovered a new ransomware tool called InfernoGrabber v9.0, created using the DeepSeek AI model, that exploits a legitimate browser feature (the File System Access API in Chrome and Chromium-based browsers) to encrypt files and demand ransom payments entirely within the browser on Windows and Android devices. This marks the first time an AI model has independently created a practical ransomware attack that bypasses browser sandboxing (the security feature that isolates browser processes), and it demonstrates that threat actors no longer need deep expertise to discover new attack methods.

The Hacker News
02

The Download: Anthropic launches Claude Science, and California’s carbon manure math

industrypolicy
Jul 1, 2026

Anthropic announced Claude Science, a new AI product designed to help scientific researchers conduct work autonomously in areas like computational biology and drug development, similar to how Claude Code assists software engineers. The US also lifted restrictions on Anthropic's Mythos and Fable models after security discussions, though the delay has already benefited Chinese AI competitors.

MIT Technology Review
03

SemAder: Evading LLM-Based Binary Code Analysis via Structure-Semantics Joint Induction

securityresearch
Jul 1, 2026

Researchers discovered that SemAder, a technique that manipulates both the structure and meaning of binary code (compiled programs), can fool LLM-based binary code analysis tools into missing security problems. The study shows that by carefully modifying how code is organized and what it semantically does, attackers can evade detection systems that use large language models to analyze compiled programs for vulnerabilities.

ACM Digital Library (TOPS, DTRAP, CSUR)
04

Google built a great smart speaker, but Gemini isn’t ready for it

industry
Jul 1, 2026

Google released a new smart speaker designed specifically for Gemini (Google's AI assistant), marking the company's first new smart speaker in six years. While the hardware is well-designed, the article indicates that Gemini for Home, the AI software powering the speaker, still feels incomplete and not fully ready for users.

The Verge (AI)
05

OpenAI, Anthropic backer MGX raises one of the biggest AI funds ever as it closes at $49 billion

industry
Jul 1, 2026

Abu Dhabi's MGX, a major investment fund, has closed a $49 billion fund to back AI companies, making it one of the largest investment vehicles in the sector. The fund has invested in major AI companies like OpenAI and Anthropic, and is looking to invest across the AI tech stack (the layers of technology needed to build AI systems, including hardware, software, and platforms). This reflects the massive amount of money flowing into AI companies, which have raised a record $416.6 billion so far this year.

CNBC Technology
06

When AI Invents the Attack: Browser-Native Ransomware

securitysafety
Jul 1, 2026

Check Point Research discovered a Python Flask web application where an AI model independently combined a browser vulnerability with a working ransomware technique to create malware that operates entirely within a web page, requiring no exploit kit, software installation, or technical skill from the attacker. This represents a shift in AI-assisted threats, as the AI connected theoretical security risks to practical attack methods on its own.

Check Point Research
07

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

security
Jul 1, 2026

Security researcher Ian Carroll used Claude Opus (an AI assistant) to discover a vulnerability in Front Gate Tickets' website that allowed him to gain super-administrator access (high-level control over a system) and issue free tickets to music festivals across the US. Carroll reported the bug responsibly rather than exploiting it, and Front Gate patched the vulnerability within 24 hours, demonstrating how AI tools can help identify serious security flaws in web systems.

Fix: Front Gate Tickets patched the vulnerability. According to the company's statement: 'This was resolved within 24 hours, and we can confirm there is no evidence of exploitation, ticket impact, or compromise of customer information.' Anthropic also noted that if Carroll had not been part of its Cyber Verification Program (an approved security research program), his use of Claude to hack the system would have been detected and blocked.

Wired (Security)
08

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

securitysafety
Jul 1, 2026

Large language models frequently invent web addresses that don't exist, and attackers are now registering these fake domains before anyone else can, then hosting phishing pages on them to catch people following AI-generated links. Palo Alto Networks' research found that when two AI models answered 685,339 questions about major brands, they generated 2.1 million links, including roughly 250,000 made-up domains with no owner yet and 13,229 known-malicious addresses. This attack, called phantom squatting (a technique where criminals register fake domains that AI systems invented), works because brand-new domains have no reputation history for security filters to flag them, so victims reach the phishing site before defenses catch up.

The Hacker News
09

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

securitypolicy
Jul 1, 2026

Anthropic restored access to Claude Fable 5 worldwide after the U.S. lifted export controls (restrictions on who can use a technology) that had been imposed for two and a half weeks following the discovery of a jailbreak (a prompt that tricks an AI into bypassing its safety rules). To address the security concern, Anthropic trained a new safety filter called a classifier that blocks the specific jailbreak technique in over 99% of attempts, while automatically routing blocked requests to a weaker model and notifying users.

Fix: Anthropic trained a new safety filter called a classifier that watches for the exact jailbreak technique and blocks it. The company says it now stops that technique in more than 99% of tries as of the June 30 write-up. Blocked requests get handed to the weaker Opus 4.8 model instead, and the user is told.

The Hacker News
10

Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5

policy
Jul 1, 2026

Anthropic's Claude Fable 5 and Mythos 5 AI models, which the U.S. government had restricted from being shared with foreign nationals due to national security concerns, have been cleared for release again following negotiations with the Trump administration. Fable 5 will be available globally starting Wednesday through Claude's platforms, while Mythos 5 access has been restored for some U.S. organizations with plans to expand through Anthropic's Glasswing program (a cybersecurity initiative providing selected organizations access to advanced AI models for defensive security testing).

Fix: The U.S. Department of Commerce lifted the export controls on both models. According to Commerce Secretary Howard Lutnick's letter to Anthropic (viewed by CNBC), he determined that 'appropriate safeguards' were in place to permit certain 'trusted partners' to access the model. Fable 5 will be available to global users on the Claude platform, Claude.AI, and Claude Code starting Wednesday, and will also be re-enabled on Amazon Web Services, Google Cloud, and Microsoft Foundry as soon as possible.

CNBC Technology
Prev1...121122123124125...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026