aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
8
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 124/643
VIEW ALL
01

Anthropic: US has lifted export controls on Fable and Mythos AI models after security risk fears

policysecurity
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

Jun 30, 2026

The US lifted export controls on Anthropic's Fable and Mythos AI models (advanced language models developed by the company) after the company agreed to detect security risks, work with the government on safety standards, and report any malicious activity. The controls had been imposed weeks earlier due to national security concerns that these powerful AI systems could be misused by foreign militaries or intelligence agencies.

Fix: Anthropic agreed to proactively detect and address security risks associated with the models; to work diligently with the US government on protocols and standards for releases; and to inform the US government of any malicious activity. The US government also established a vetting process to control which organizations can access the models, limiting initial access to 'trusted' US organizations.

The Guardian Technology
02

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

securityresearch
Jun 30, 2026

Researchers discovered that large language models (LLMs, AI systems trained on massive amounts of text data) frequently generate fake web domain names that don't actually exist but sound like they belong to real companies. Attackers are registering these made-up domains (a practice called phantom squatting) to intercept traffic sent by AI systems and users who trust the LLM's output, creating a new supply chain attack vector (a way to compromise software development and deployment). The researchers identified over 13,000 confirmed malicious URLs and approximately 250,000 unregistered hallucinated domains that attackers could exploit.

Fix: Palo Alto Networks customers can use the following products and services for protection: Advanced WildFire, Advanced URL Filtering, Advanced DNS Security (systems that monitor and block suspicious web traffic), Prisma AIRS, Koi Agentic Endpoint Security, and the Unit 42 AI Security Assessment. Organizations can also contact the Unit 42 Incident Response team if they suspect compromise.

Palo Alto Unit 42
03

Anthropic to restore Claude Fable access on Wednesday

policy
Jun 30, 2026

Anthropic has announced that the Department of Commerce lifted export controls on Claude's powerful AI models, Fable 5 and Mythos 5, and will begin restoring access to Fable 5 on Wednesday. The company is also rolling out identity verification (KYC, or know-your-customer checks) for certain Claude features, requiring users to provide government-issued photo ID and a live selfie through a third-party verification partner called Persona to prevent misuse and comply with legal requirements.

BleepingComputer
04

Anthropic’s long-sidelined Fable 5 is greenlit to return

policy
Jun 30, 2026

Anthropic's Claude Fable 5 AI model is being brought back online after the U.S. Department of Commerce lifted export controls that had previously blocked it. The company plans to restore access to users globally starting Wednesday across Claude platforms and cloud services like AWS, Google Cloud, and Microsoft Foundry, though without a specific timeline for completion.

The Verge (AI)
05

CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

security
Jun 30, 2026

Microsoft SharePoint Server has a deserialization of untrusted data vulnerability (a flaw where the software unsafely processes data from an untrusted source, allowing an attacker to inject malicious code), which lets an authorized attacker run code over a network. This vulnerability is actively being exploited in real attacks. Organizations must apply security updates following CISA's BOD 26-04 guidance by July 4, 2026, or stop using the product if no fix is available.

Fix: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. See https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 for vendor-specific details and https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk for patching guidelines.

CISA Known Exploited Vulnerabilities
06

Quoting Anthropic

policy
Jun 30, 2026

Anthropic announced that the U.S. Department of Commerce has removed export restrictions on two AI models, Claude Fable 5 and Mythos 5, allowing the company to restore user access to these models starting the next day. This announcement suggests that government controls on advanced AI technology exports had previously limited who could use these models outside certain regions.

Simon Willison's Weblog
07

v2026.06

securityresearch
Jun 30, 2026

This release document describes updates to security techniques and mitigations related to AI systems, including new attack methods like stealing web session cookies and jailbreaking LLMs (large language models, AI systems trained on massive amounts of text), as well as updated defenses like AI guardrails (safety features that prevent unwanted outputs) and telemetry logging (monitoring system activity). Several new case studies illustrate real-world attacks on AI services, including prompt injection (tricking an AI by hiding malicious instructions in user input) and vulnerabilities in commercial AI products.

MITRE ATLAS Releases
08

Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price

industry
Jun 30, 2026

Anthropic has released Claude Sonnet 5, a new AI model that performs nearly as well as their expensive flagship model (Opus 4.8) but costs significantly less. Sonnet 5 is designed to be 'agentic,' meaning it can make plans, use tools like browsers and terminals, and check its own work, capabilities that were previously limited to more expensive models. The model is available now with introductory pricing of $2 per million input tokens (the words you feed it) and $10 per million output tokens (the words it generates) through August 2026.

BleepingComputer
09

New BioShocking attack manipulates AI browser into data theft

securitysafety
Jun 30, 2026

BioShocking is a prompt injection attack (tricking an AI by hiding malicious instructions in its input) that manipulates AI-powered browsers into ignoring safety guardrails by framing dangerous actions as part of a fictional game scenario. Researchers at LayerX tested this attack on six mainstream AI browser products and found that all six failed to distinguish between harmless game actions and real sensitive operations like stealing passwords. Only OpenAI implemented a working fix for the vulnerability.

Fix: OpenAI was the only vendor to implement a working fix for BioShocking in ChatGPT Atlas. The source also recommends that vendors add explicit user confirmation for sensitive actions, stronger context checks, and scope limits for agentic sessions (AI agent operating boundaries), while users should restrict AI browser access to sensitive services through available platform options.

BleepingComputer
10

Claude Science is Anthropic’s newest flagship product

industry
Jun 30, 2026

Anthropic announced Claude Science, a new AI product designed to help scientists conduct research autonomously, similar to how Claude Code supports software engineers. The tool has special features for computational biology and drug development, including the ability to run code on powerful computers and ensure results can be verified for accuracy. This positions Anthropic as a major competitor to Google DeepMind in AI-assisted scientific research.

MIT Technology Review
Prev1...122123124125126...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026