aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
7,866
[LAST_24H]
6
[LAST_7D]
232
Daily BriefingSunday, September 27, 2026
>

Comprehensive Survey Maps AI Auditing Landscape: A new academic survey consolidates existing frameworks, principles, and methodologies used to audit AI systems for safety, fairness, and reliability, providing practitioners with a structured overview of current evaluation approaches.

Latest Intel

page 13/787
VIEW ALL
01

Gemini 3.8 TTS Playground

industry
Sep 23, 2026

Google released two new text-to-speech models (gemini-3.8-flash-tts and gemini-3.8-flash-lite-tts) that can convert written text into spoken audio using over 2,000 voices or custom voices created from a 30-second audio sample. A developer created an interactive playground tool where users can write multi-character conversations, preview the generated speech, and share their creations through shareable URLs.

Critical This Week5 issues
critical

CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm

CVE-2026-84462NVD/CVE DatabaseSep 25, 2026
Sep 25, 2026
Simon Willison's Weblog
02

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

securitysafety
Sep 23, 2026

Threat actors are using three open-source AI agent frameworks (Strix for scanning, Cairn for exploitation, and Hermes for coordination) to automatically attack hundreds of online retailers, stealing over 600,000 credit card records and injecting skimmer malware (code that secretly captures payment card data) onto 119+ websites since at least July. The attacker gives the AI agents high-level instructions and lets them execute attacks autonomously at scale, with an average cost of only $25 per target and success rates varying across at least 27 compromised companies including major retailers and airlines.

BleepingComputer
03

CVE-2026-18875: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook

security
Sep 23, 2026

IBM Financial Transaction Manager for RedHat OpenShift has a security flaw where unauthenticated attackers can inject malicious content into the AI agent's runbook database without needing a password or login credentials, allowing them to manipulate the AI into making unauthorized payments or stealing payment information through RAG poisoning (corrupting the external documents that an AI uses to answer questions).

NVD/CVE Database
04

Two years of OpenAI Academy

industry
Sep 23, 2026

OpenAI Academy is a training program launched in September 2024 that has reached over 4 million people with practical AI skills through workshops, online courses, and events called AI Skills Jams. The program is expanding through a new Community Trainer Program that prepares people in local organizations to teach AI training in their own communities, so more people have access to AI education and support where they live and work.

OpenAI Blog
05

Reimagining the SOC for the agentic era in Microsoft Defender

securityindustry
Sep 23, 2026

Microsoft is announcing an Integrated Security Operations Center (ISOC) in Microsoft Defender that combines SIEM (security information and event management, which collects and analyzes security data from across a network) and threat protection into one unified system. This design addresses the challenge that cyberattackers now use AI agents to automate attacks at massive scale, requiring defenders to operate faster by eliminating delays caused by separate, disconnected security tools. ISOC enables both human security teams and AI agents to work together using shared signals, context, and controls to detect threats, predict attacks, and respond in real-time.

Microsoft Security Blog
06

Gemini 3.8 text-to-speech says hello

industry
Sep 23, 2026

Google has released Gemini 3.8 Flash TTS and Gemini 3.8 Flash-Lite TTS, two new text-to-speech models (AI systems that convert written text into spoken audio) that allow creators and developers to generate highly expressive custom voices with detailed control over performance, tone, and character. These models support over 100 languages, offer 2,000+ pre-made voices, enable voice replication from short audio samples, and allow line-by-line direction of how dialogue is delivered in applications like gaming, podcasts, and interactive media.

DeepMind Safety Research
07

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

securitysafety
Sep 23, 2026

Attackers are planting fake content and malicious links across the internet, then using SEO (search engine optimization, techniques to make content rank higher in search results) to make sure AI chatbots like ChatGPT and Gemini pull this poisoned information when answering user questions. This allows them to spread disinformation and phishing attacks (scams designed to steal personal information) at scale through AI systems.

Dark Reading
08

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

security
Sep 23, 2026

CLOSEDQUORUM is a Windows malware that uses a voting system from up to four AI models (DeepSeek, Qwen, Mistral, and Google Gemini) to decide what malicious actions to perform, such as stealing passwords and crypto wallet data, instead of taking orders from a traditional command-and-control server. The malware sends information about the victim's computer to the AI models and executes whatever action receives the most votes, with results posted to Discord. While Talos researchers discovered this malware and the public version does not currently work due to missing API keys and placeholder values, it represents an early example of attackers delegating attack decisions to AI services.

The Hacker News
09

Workforce AI Security Policy Management Is Now ConversationalĀ 

securityindustry
Sep 23, 2026

Check Point has released a new Workforce AI MCP (Model Context Protocol, a standard for connecting AI systems to external tools), which allows security managers to query and manage employee AI usage policies using natural conversation instead of navigating complex menus and settings. Instead of manually checking individual rules, users can now ask simple questions in plain language, like which security rule applies to a specific employee, and can create or update policies through conversational requests.

Check Point Research
10

OpenAI extends cyber access to Ukraine for civilian defense

securitypolicy
Sep 23, 2026

OpenAI announced it will give Ukraine's government access to its Daybreak program, an AI tool that helps cyber defenders find and fix software vulnerabilities (weaknesses in code that attackers can exploit) more quickly. Ukraine faces thousands of cyber attacks yearly targeting hospitals, energy systems, and communications, so this tool aims to help protect critical infrastructure that citizens depend on.

OpenAI Blog
Prev1...1112131415...787Next
critical

GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

CVE-2026-61742GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

CVE-2026-61732GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security BulletinsSep 24, 2026
Sep 24, 2026
critical

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker NewsSep 22, 2026
Sep 22, 2026