aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
8
[LAST_7D]
166
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 131/643
VIEW ALL
01

OpenAI hasn't held pre-IPO investor meetings or set timeline yet, sources say

industry
Jun 26, 2026

OpenAI has confidentially filed documents with the SEC (Securities and Exchange Commission, the government agency that oversees stock market listings) but has not yet held investor meetings or announced an official timeline for going public, though reports suggest a potential 2027 IPO. The company is intentionally downplaying expectations about when it will list on the stock market, with CEO Sam Altman stating that going public is a 'financing event' rather than a near-term priority.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

CNBC Technology
02

CVE-2025-32394: AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

security
Jun 26, 2026

AutoGPT versions before 0.6.32 contain a DoS (denial of service, where a system is overwhelmed and stops working) vulnerability in its AITextSummarizerBlock component. A malicious user can input a small amount of content that causes the server to consume massive amounts of memory, exhausting resources and crashing the system, for example turning 10K of input into 50G of memory usage.

Fix: This vulnerability is fixed in version 0.6.32. Update AutoGPT to 0.6.32 or later.

NVD/CVE Database
03

Quoting OpenAI

industry
Jun 26, 2026

OpenAI announced a limited preview of three new GPT-5.6 models: Sol (high-performance), Terra (balanced), and Luna (fast and affordable), with pricing ranging from $1-$30 per million tokens depending on the model and whether the input or output is being processed. The company is starting with a limited preview for trusted partners approved by the U.S. government before making the models more broadly available, and the new models include improved prompt caching (a feature that stores frequently used inputs to speed up responses) with explicit cache breakpoints and longer minimum cache duration.

Simon Willison's Weblog
04

OpenAI limits new AI models to 'trusted partners' at request of U.S. government

policyindustry
Jun 26, 2026

OpenAI released three new AI models (GPT-5.6 Sol, Terra, and Luna) but is initially limiting access to a small group of trusted partners at the U.S. government's request, following President Trump's recent AI executive order asking developers to let the government assess model capabilities before full release. The company says it plans to make the models generally available in the coming weeks and is working with the Trump administration to develop a repeatable assessment process for future model releases.

Fix: OpenAI said it is 'working with the Trump administration to help establish a framework for such assessments and to develop a "repeatable process for future model releases."' The company also stated it is 'taking this short-term step because we believe it is the strongest path to broader availability in the coming weeks,' indicating that the initial limited rollout to trusted partners is intended as a temporary measure before wider release.

CNBC Technology
05

OpenAI unveils GPT-5.6 amid US AI regulatory drama

industry
Jun 26, 2026

OpenAI released GPT-5.6, a new model suite with three versions: Sol (flagship), Terra (medium-tier for high-volume work), and Luna (fast and affordable). The models are designed to excel at coding, cybersecurity, biology, and agentic AI tasks (where AI systems can plan and execute multi-step goals with minimal human direction), and Sol is priced competitively against competitors like Anthropic's Claude.

The Verge (AI)
06

Malware authors subvert AI detection systems

security
Jun 26, 2026

Malware authors are creating code that tricks AI-based security tools (LLM-assisted products, which use large language models to analyze threats) into stopping their analysis or refusing to work, according to security researchers at SentinelLabs. One example is macOS.Gaslight, believed to be linked to North Korean hackers, and this is part of a growing trend where malware is specifically designed to evade AI-powered defenses.

CSO Online
07

CVE-2026-47214: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

security
Jun 26, 2026

Docling is a tool that helps process documents by reading different file formats and connecting with AI systems. Before version 2.94.0, Docling's HTML backend had unsafe handling of URIs and file paths (ways of locating files on a computer), which could be exploited as a security weakness. This issue was fixed in version 2.94.0.

Fix: Update Docling to version 2.94.0 or later, where the vulnerability is fixed.

NVD/CVE Database
08

CVE-2026-44018: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

security
Jun 26, 2026

Docling is a tool that processes documents in different formats and connects them with AI systems. Versions 2.45.0 through 2.91.0 had security flaws in how they parsed METS-GBS archives (a type of compressed document file), allowing attackers to craft malicious files that could steal sensitive data, use up system resources, or crash the application.

Fix: This vulnerability is fixed in version 2.91.0. Users should update to this version or later.

NVD/CVE Database
09

OpenAI and Anthropic face new AI reality as users shift from 'tokenmaxxing' to efficiency

industry
Jun 26, 2026

Companies are shifting away from "tokenmaxxing" (using as much AI as possible without worrying about costs) toward efficiency and cost control, with some businesses switching to cheaper AI alternatives like DeepSeek to reduce spending. OpenAI and Anthropic, which have benefited enormously from the previous spend-at-all-costs mentality, may face slower growth as enterprises demand clearer returns on their AI investments and limit their token (units of data processed by AI models) spending.

CNBC Technology
10

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

securitypolicy
Jun 26, 2026

This cybersecurity news roundup covers several major incidents and policy developments, including Russian authorities using legacy Cellebrite software (a tool that extracts data from phones) to breach an activist's iPhone, a major data breach at Tata Electronics exposing 630 GB of Apple and Tesla secrets, and a Five Eyes warning that advanced AI is accelerating vulnerability research and exploit development (automated creation of attack tools), compressing attack timelines from years to months. Additional stories include guilty pleas from Scattered Spider hackers who compromised London's transport system, an upcoming Android developer verification framework launching in 2026, and U.S. government restrictions on OpenAI's GPT-5.6 model deployment.

Fix: The Five Eyes advisory explicitly recommends that executives and security leaders 'transition to zero-trust architectures, accelerate patching protocols, and immediately decommission legacy infrastructure to withstand machine-speed intrusions.' Additionally, the Android developer verification framework launching September 30, 2026, will feature 'new automated registration APIs alongside an advanced sideloading flow equipped with mandatory checkpoints to counter coercion scams.'

SecurityWeek
Prev1...129130131132133...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026