aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
8
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 129/643
VIEW ALL
01

Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines

securitysafety
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

Jun 29, 2026

Researchers discovered a new attack where hackers can take over developer machines by hiding malicious instructions in seemingly normal code repositories that Claude Code (an AI coding agent) executes. The attack works by triggering an error during setup that Claude Code tries to fix, which causes it to run a shell script that fetches and executes commands from a DNS TXT record (the system that translates website names into IP addresses), giving attackers an interactive shell on the developer's computer and access to their credentials and secrets.

SecurityWeek
02

Straiker Raises $64 Million for AI Security Platform

securityindustry
Jun 29, 2026

Straiker, a cybersecurity startup founded in 2025, raised $64 million to develop a platform that helps organizations find and monitor AI agents (software programs that can act independently) in their systems and identify security risks. The platform uses pre-deployment adversarial testing (controlled attacks before the AI goes live) to find vulnerabilities, runtime protection (active monitoring while the AI is running) to stop threats immediately, and collaboration with AI labs to stay ahead of emerging attacks.

SecurityWeek
03

Agentic AI Has an Identity Problem and Attackers Know It

securitypolicy
Jun 29, 2026

Agentic AI systems (autonomous AI agents that can authenticate, call APIs, write code, and take action in production environments) create new security challenges because they operate with human-like autonomy but at machine speed and scale, yet organizations lack proper identity management for them. Traditional security approaches built for humans and service accounts fall short because AI agents need contextual, intent-based access that changes based on their goals and environment, not just static minimum permissions. The article identifies three critical problems: organizations don't know what AI agents exist or who owns them (visibility problem), agents are often given too many permissions (overprivilege problem), and traditional identity systems weren't designed to handle this level of autonomy and decentralization.

BleepingComputer
04

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

securityresearch
Jun 29, 2026

Russia has developed a sophisticated influence ecosystem that uses information operations (IO, coordinated campaigns to spread narratives and manipulate public opinion) and generative AI (machine learning systems that create text and media) to advance its strategic goals globally, with recent focus on Ukraine but increasingly pivoting back to broader targets like NATO and the EU. The ecosystem blends state-controlled media, covert IO campaigns, and hacking activities into an interconnected network designed to be resilient against limited disruptions. The research warns that Russia views these influence tactics as cost-effective and successful, and will likely continue expanding their use with new AI tools while maintaining military and political objectives.

Google Threat Intelligence
05

OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

policysecurity
Jun 29, 2026

OpenAI and Anthropic are restricting access to their newest AI models following government cybersecurity reviews by the Trump administration. The concern centers on whether these powerful models could be misused to find software vulnerabilities (security flaws in code) that malicious hackers might exploit to attack critical computer systems, and both companies are releasing their models only to small groups of government-approved customers as a temporary measure.

SecurityWeek
06

OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI

securitypolicy
Jun 29, 2026

OpenAI announced GPT-5.6 Sol, a new AI model designed specifically for cybersecurity tasks, which is being released in limited preview to trusted partners while the government evaluates national security risks from advanced AI systems. Sol is built to excel at defensive security work like finding vulnerabilities and creating patches, rather than launching full cyberattacks, and uses multiple safety layers including real-time classifiers (automated systems that flag suspicious inputs) and secondary review processes to prevent misuse.

Fix: OpenAI deployed a multi-layered security architecture for GPT-5.6 that includes: standard training-level refusals, automated real-time classifiers for biology and cybersecurity inputs that pause output generation when anomalies are flagged for secondary review by a reasoning model, account-level evaluations to distinguish legitimate security research from malicious behavior, and over 700,000 A100-equivalent GPU hours of automated red-teaming (adversarial testing to find weaknesses) focused on discovering universal jailbreaks (broad attack methods) rather than single-prompt failures.

SecurityWeek
07

Mapping Europe’s AI Workforce Opportunity

policyindustry
Jun 29, 2026

OpenAI's report applies an AI Jobs Transition Framework to Europe's labor market, categorizing occupations into four groups based on how AI might affect them: about 12% may grow with AI, 14% face higher automation potential (meaning AI could replace workers), 27% will likely reorganize with AI changing workflows, and 47% will see less immediate change. The report notes that AI's impact on jobs varies significantly by country due to differences in occupational structures, and recommends that policymakers and employers plan for these changes in detail rather than relying on aggregate employment statistics.

Fix: The report suggests that policymakers strengthen monitoring capabilities to track labor market change and establish national readiness plans to tailor interventions. It also recommends connecting Europe's existing occupation, training, vacancy, wage, and statistical systems to measures of AI capability and workplace adoption to identify where transition pressure and opportunity are emerging before effects appear in headline labor-market data.

OpenAI Blog
08

China’s Z.ai claims it can match Mythos on cybersecurity

industry
Jun 28, 2026

China's Zhipu AI released GLM-5.2, an open-weight model (a publicly available AI that can be freely used and modified) that some researchers say performs as well as Mythos in cybersecurity tasks like finding bugs. While GLM still lags behind US models in general capabilities, this development shows China has significantly narrowed the gap with American AI systems, which concerns the US government that has tried to limit China's access to advanced models and the computing hardware needed to train them.

The Verge (AI)
09

HP Inc. launches Frontier strategic partnership with OpenAI

industry
Jun 28, 2026

HP Inc. announced a strategic partnership with OpenAI to scale deployment of Frontier (OpenAI's unified platform for managing AI agents and workflows) across the company after successful pilot tests. Early pilots showed significant gains, such as one engineer processing 122 pull requests in weeks and a security team fixing bugs in a day that normally would take a month, demonstrating how AI can compress time and reduce friction in software development, customer support, and device management workflows.

OpenAI Blog
10

Prosecutors used ChatGPT logs as evidence in the Palisades fire trial

securitypolicy
Jun 28, 2026

In a criminal trial for arson related to the Palisades fire, prosecutors used ChatGPT conversation logs as evidence against the defendant, pointing to interactions where he asked the AI to generate images of fire and made statements about anger and wealth inequality. This case illustrates how records of conversations with AI systems can be retrieved and used in legal proceedings, raising questions about the privacy and persistence of data users share with AI chatbots.

The Verge (AI)
Prev1...127128129130131...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026