aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,425
[LAST_24H]
7
[LAST_7D]
162
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 141/643
VIEW ALL
01

CVE-2026-54319: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

security
Jun 23, 2026

Daytona is a platform that runs code generated by AI in a controlled environment (sandbox, which is an isolated space). Before version 0.186, it had a path-traversal vulnerability (a weakness where an attacker can use special character sequences like '../' to access files outside intended directories) that could let someone access files outside the intended storage volume directory by manipulating the volume reference sent to the runner.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

Fix: This vulnerability is fixed in version 0.186. Users should upgrade to this version or later.

NVD/CVE Database
02

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

security
Jun 23, 2026

A vulnerability called 'Cordyceps' exploits weaknesses in CI/CD workflows (automated systems that test and deploy code changes) to inject malicious pull requests (code change proposals) into popular developer tools like Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black. Attackers can use this method to compromise the software supply chain, potentially affecting many developers who use these tools.

Dark Reading
03

CVE-2026-54324: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

security
Jun 23, 2026

Daytona is a platform that runs code generated by AI safely and efficiently. Before version 0.185.0, it had a cross-tenant authorization flaw (a security problem where access controls between separate organizations failed), which let any logged-in user listen to another organization's real-time notifications and see their events without permission.

Fix: This vulnerability is fixed in version 0.185.0.

NVD/CVE Database
04

CVE-2026-54323: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

security
Jun 23, 2026

Daytona, a tool for running AI-generated code safely, had a security flaw before version 0.185.0 where it didn't verify TLS certificates (the security credentials that prove a website is authentic) when cloning Git repositories (copying code from remote servers). This meant an attacker intercepting the connection could steal Git credentials (login information) and replace the real code with fake, harmful code.

Fix: This vulnerability is fixed in version 0.185.0.

NVD/CVE Database
05

CVE-2026-54021: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, sever

security
Jun 23, 2026

Open WebUI, a self-hosted AI platform that runs offline, had a vulnerability before version 0.9.6 where authenticated users could bypass access controls by manipulating a url_idx parameter (a number used to select which backend server to use). This allowed them to reach Ollama backends (the AI model servers) they shouldn't have access to, including internal or admin-disabled ones, because the system only checked if they could use a model but not which backend server they were routed to.

Fix: This vulnerability is fixed in 0.9.6.

NVD/CVE Database
06

CVE-2026-54019: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open

security
Jun 23, 2026

Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.6 where access controls (ACL, rules that restrict who can access what) could be bypassed when a database feature called Milvus multitenancy mode was enabled. An attacker could exploit this by using a specially crafted collection name that wasn't properly cleaned before being used in a database query, allowing them to access data they shouldn't be able to reach.

Fix: Update Open WebUI to version 0.9.6 or later, where this vulnerability is fixed.

NVD/CVE Database
07

How GPT-5 helped immunologist Derya Unutmaz solve a 3-year-old mystery

industry
Jun 23, 2026

Immunologist Derya Unutmaz used GPT-5 Pro in late 2025 to solve a three-year-old mystery about how glucose affects T cell development (immune cells that fight disease). His lab had run an experiment in 2022 showing that deoxyglucose (a glucose-like molecule that disrupts a cell's energy production) caused T cells to become inflammatory-response cells at much higher rates than low glucose alone, but they couldn't explain why. GPT-5 Pro analyzed the data and suggested that deoxyglucose interfered with IL-2 protein construction, which normally prevents T cells from becoming inflammatory cells, thereby explaining the unexpected results.

OpenAI Blog
08

Something’s off with Midjourney’s pivot to body scanners

industry
Jun 23, 2026

Midjourney, an AI company known for its image generator, announced a new medical imaging product: an experimental ultrasound scanner that would immerse users in water to produce detailed body images similar to MRI (magnetic resonance imaging, a medical scanning technique). Medical imaging experts expressed skepticism about the technology, saying Midjourney has not yet shown sufficient public evidence to support its claims that the system could match or exceed MRI capabilities.

The Verge (AI)
09

AI PACs pour $20 million into New York Democratic primary in AI regulation battle

policyindustry
Jun 23, 2026

AI companies are spending over $20 million in a New York congressional race between AI safety advocate Alex Bores and two other candidates, with competing super PACs (political action committees, groups that raise unlimited money for political causes) backing different approaches to AI regulation. Leading the Future, backed by companies like OpenAI and Andreessen Horowitz, opposes Bores and favors lighter regulation, while Public First Action, funded by Anthropic, supports Bores and advocates for stricter safety requirements built into AI models from the start. This race has become a proxy battle over whether the U.S. government should heavily regulate the AI industry or allow it to develop with fewer restrictions.

CNBC Technology
10

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

securitysafety
Jun 23, 2026

A security firm created a fake AI agent skill (a bundle of instructions that agents load and follow) that bypassed all security scanners and reached approximately 26,000 agents by exploiting a structural weakness: scanners only check the skill's initial package, but attackers can change the external webpage the skill points to after it passes review. The fake skill appeared legitimate through inherited GitHub credibility and targeted ads, demonstrating that current trust signals and scanning tools fail to catch sophisticated attacks.

Fix: Treat skills as software, not text, by vetting what a skill points to externally, not just what ships inside it. Route new skills through a single source you control and re-check them when anything changes since a clean result at install does not stay clean if the skill connects to a link someone else can edit. Additionally, pin versions, hold agents to the least privilege (minimum access needed to function), and assume any external instruction an agent fetches runs with the agent's full access level.

The Hacker News
Prev1...139140141142143...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026