aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,426
[LAST_24H]
5
[LAST_7D]
160
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 152/643
VIEW ALL
01

Embedding Forbidden Text in Spyware to Discourage AI Analysis

securitysafety
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

Jun 18, 2026

A malware developer is embedding forbidden text about nuclear and biological weapons in JavaScript spyware to prevent AI analysis. The malware hides real code after a large comment block containing policy-triggering content, which tricks AI systems into refusing to analyze the file or getting confused before they can identify the actual malicious code.

Schneier on Security
02

Improving health intelligence in ChatGPT

safetyresearch
Jun 18, 2026

ChatGPT has improved its ability to help with health questions through a new model called GPT-5.5 Instant, which better recognizes when urgent care is needed, explains uncertainty honestly, and provides clearer information. The improvements were measured using physician-led evaluations (HealthBench, a set of tests that assess health response quality) and real-world usage data, showing a 71% reduction in factuality issues over two months. GPT-5.5 Instant is available free to all ChatGPT users and performs similarly to OpenAI's most advanced models on health-related tasks.

OpenAI Blog
03

5 new security operations roles the AI-SOC will create

industry
Jun 18, 2026

AI-powered security operations centers (SOCs, where cybersecurity teams monitor and respond to threats) are automating many traditional analyst tasks, starting with alert triage and investigation. This shift will create new job roles such as security data engineers, AI security agent orchestrators, and AI model trainers, where humans will focus on preparing data, managing AI agent systems, and continuously updating AI models rather than doing routine alert monitoring.

CSO Online
04

Cybersecurity was built for predictable systems. AI changes the rules

securitysafety
Jun 18, 2026

AI systems challenge traditional cybersecurity because they behave unpredictably, unlike the deterministic (consistent and predictable) systems that security programs were designed around. Traditional security approaches focused on preventing attacks before systems go live, but AI agents make dynamic decisions and interact with external tools in ways developers can't fully predict, meaning security risks emerge at runtime (while systems are actively running) rather than being preventable beforehand. Additionally, AI-assisted development tools are accelerating code production, compressing the time security teams have to review and understand what enters production.

CSO Online
05

Using AI to help physicians diagnose rare genetic diseases affecting children

research
Jun 18, 2026

Researchers used OpenAI o3 Deep Research, an AI reasoning model, to re-analyze 376 previously unsolved rare genetic disease cases by connecting clinical data, genetic variants, and scientific literature into evidence-based explanations for human experts to review. After specialist evaluation and clinical confirmation, the AI-assisted workflow helped establish new diagnoses in 18 cases (4.8% additional diagnostic yield), with the model generating hypotheses rather than making medical decisions itself. This demonstrates how periodic AI-assisted reanalysis could help scale the process of solving rare disease cases as medical knowledge evolves.

OpenAI Blog
06

Google Gemini co-lead Noam Shazeer leaves for OpenAI

industry
Jun 17, 2026

Noam Shazeer, a senior Google engineer and co-lead of the Gemini AI models (Google's large language model system), has left the company to join OpenAI (the company behind ChatGPT). This departure highlights the competitive battle between tech companies to recruit top AI researchers and engineers.

CNBC Technology
07

Midjourney goes from generating cat images to full-body ultrasound scans

industry
Jun 17, 2026

Midjourney, known for its AI image generator, has unveiled The Midjourney Scanner, a hardware product that uses ultrasound technology (sound waves to create images of the body's interior) with a ring of sensors to capture full-body scans showing muscle, fat, bone, and organs. The company plans to build a spa in San Francisco where users could get these scans, which the CEO claims could match MRI (magnetic resonance imaging, a medical scanning technique) quality.

The Verge (AI)
08

Leak confirms OpenAI is testing a ChatGPT for Science subscription

industry
Jun 17, 2026

OpenAI is testing a new subscription service called 'ChatGPT for Science' that would provide specialized AI capabilities for scientific research, similar to how it previously created GPT-Rosalind (a specialized model built on GPT-5.5 architecture for life sciences research). The service would likely be restricted to verified research institutions and universities rather than being available to all users, and it is expected to be announced within the coming weeks.

BleepingComputer
09

CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability

security
Jun 17, 2026

Splunk Enterprise has a critical security flaw where a PostgreSQL sidecar service endpoint (a supporting service that handles database connections) doesn't require authentication (proof of identity), allowing an attacker without credentials to create or delete arbitrary files. This vulnerability is currently being exploited in real attacks in the wild.

CISA Known Exploited Vulnerabilities
10

GLM-5.2 is probably the most powerful text-only open weights LLM

industry
Jun 17, 2026

Z.ai released GLM-5.2, a 753-billion parameter text-only open weights LLM (large language model, a type of AI trained on text) under an MIT license on June 16th, 2026. It features a 1-million token context window (the amount of text it can consider at once) and ranks as the top open weights model on independent benchmarks, though it uses significantly more output tokens per task than competing models. The model performs well on web development coding tasks but has shown mixed results in creative image generation tasks compared to its predecessor.

Simon Willison's Weblog
Prev1...150151152153154...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026