aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,426
[LAST_24H]
5
[LAST_7D]
160
Daily BriefingFriday, August 14, 2026
>

OpenAI's Enterprise Revenue Surpasses Consumer Business: OpenAI's CFO disclosed that enterprise sales now exceed consumer revenue, crossing 50% of the company's $40 billion annualized run rate earlier than anticipated. The shift reflects enterprises moving from untracked employee AI usage toward measuring cost per unit of intelligence delivered.

>

Cyera Acquires Oasis Security for $1 Billion to Unify AI Agent Controls: Cyera purchased Oasis to merge data security and identity management into a single control plane for AI agents (autonomous software programs that act on behalf of users), enabling context-based access decisions rather than static permission roles.

>

Latest Intel

page 155/643
VIEW ALL
01

1Password Acquires Apono in Reported $250M-$300M Deal

industry
Jun 17, 2026

1Password has acquired Apono, an Israeli company specializing in just-in-time access governance (a system that grants temporary, narrowly scoped permissions that are automatically removed after a task completes), for an estimated $250 million to $300 million. Apono's technology allows organizations to manage access for humans, machines, and AI agents by evaluating each permission request against policy before granting it, and for AI agents specifically, it monitors behavioral drift (unexpected changes in how the AI is acting) to detect misuse. This acquisition helps 1Password extend its identity security platform to provide more comprehensive access control across enterprise tools and cloud services.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Critical RCE in Cortex MCP Server Enables Code Execution via Malicious Repositories: CVE-2026-49986 affects Cortex MCP server (a tool providing persistent memory to AI assistants like Claude) versions before 3.17.1, where insufficient validation of project directories allows attackers to execute arbitrary Python code by placing malicious files in a repository that trigger when the visualization tool is invoked. The vulnerability carries critical severity and runs with user privileges.

>

Anthropic Deploying Invisible Text Watermarks in Claude for EU Compliance: Anthropic is embedding undetectable watermarks in Claude's output by subtly biasing word selection during generation using a secret key, creating verifiable patterns without degrading text quality. The implementation addresses EU regulatory requirements mandating identification of AI-generated content.

SecurityWeek
02

Anthropic asked for regulation. Washington went much further

policyindustry
Jun 17, 2026

Anthropic, an AI company that has publicly advocated for government regulation of AI safety, received an export control directive from the Trump administration ordering it to suspend access to its latest Claude models (Fable 5 and Mythos 5) to foreign nationals, citing national security concerns. The directive was reportedly prompted by concerns that Amazon researchers had used prompts to get Fable 5 to generate information that could help with cyberattacks, and Anthropic disagreed with the suspension, calling it a 'misunderstanding' and characterizing it as not adhering to transparent, fair processes.

CNBC Technology
03

Tenet Security Emerges From Stealth With $6 Million Seed Funding

securityindustry
Jun 17, 2026

Tenet Security is a new startup that detects and stops dangerous behavior from AI agents (autonomous software systems that can make decisions and take actions on their own) in real time. The company uses a patent-pending technology with a lightweight runtime sensor that monitors operating system behavior, network calls, and the agent's reasoning, then predicts and blocks harmful actions before they happen. Tenet addresses a growing security gap where traditional tools cannot detect when malicious actors manipulate AI agents (a threat called 'agentjacking') or when agents malfunction on their own.

SecurityWeek
04

Google’s Vertex AI SDK could allow RCE through bucket squatting

security
Jun 17, 2026

Google's Vertex AI SDK for Python had a design flaw that could allow attackers to hijack and poison AI models through bucket squatting (creating cloud storage buckets with names matching those expected by other projects). An attacker who knew a victim's project ID and region could create a bucket with the same name, trick the SDK into uploading models there, replace the model with malicious code, and achieve RCE (remote code execution, where an attacker runs commands on a system they don't control) when the poisoned model was loaded using Python's pickle deserialization (a process that can execute hidden code in specially formatted data).

Fix: Google modified the affected workflow so that staging buckets are now validated before use, preventing attackers from registering bucket names that could be mistaken for resources belonging to other projects. The fixes were deployed in SDK versions 1.144.0 and 1.148.0, and users must upgrade to either of the patched versions.

CSO Online
05

AI Red Teaming Makes the Unknowns Known

securitysafety
Jun 17, 2026

AI systems are now widely used in business for tasks like writing, coding, and automating workflows, but existing safety review processes weren't designed for this real-world deployment. An AI system can pass tests in controlled environments yet still fail or behave unpredictably when used in actual production (real work scenarios with actual data and users).

Check Point Research
06

AI Use by the US Government

policysafety
Jun 17, 2026

The US government disclosed 3,611 active or planned uses of AI across federal agencies, a 70% increase from the previous administration, including controversial applications like using AI to assess prisoner misconduct risk before violations occur and monitoring veterans' crisis calls to predict suicide risk. While some AI uses in government could theoretically be implemented responsibly, the disclosure provides minimal details about how these systems actually work, and public consultation is largely absent, making it difficult for citizens to understand or scrutinize these programs.

Schneier on Security
07

Will it take a ‘Chernobyl-scale disaster’ for us to regulate cyber weapons of mass destruction? | Stuart Russell

safetypolicy
Jun 17, 2026

Stuart Russell, a leading AI safety researcher, warns that unrestricted development of unsafe AI systems poses serious risks to society. He highlights concerns about recursive self-improvement (RSI, where an AI system teaches itself to become smarter, creating a cycle of increasing capability), which Anthropic recently reported observing in early development stages.

The Guardian Technology
08

A near-autonomous AI chemist improves a challenging reaction in medicinal chemistry

researchindustry
Jun 17, 2026

OpenAI's GPT-5.4 AI system, connected to Maria (an autonomous chemistry lab), successfully improved a difficult chemical reaction called Chan-Lam coupling used in drug discovery. The AI independently designed and ran experiments, analyzed results, and proposed improvements that increased reaction yields from 16.6% to 25.2%, a finding that human chemists confirmed in the lab.

OpenAI Blog
09

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

securityprivacy
Jun 17, 2026

Cybersecurity researchers discovered 15 malicious plugins on the JetBrains Marketplace (a platform where developers download tools for their coding environment) that pretend to be AI coding assistants but secretly steal API keys (authentication credentials that allow access to paid AI services like OpenAI and DeepSeek). The stolen keys are sent to an attacker's server, and some keys are resold to other criminals in what appears to be an illegal monetization scheme. Additionally, two malicious Chrome extensions disguised as ad blockers are capturing users' conversations with various AI chatbots.

The Hacker News
10

5 AI risk management frameworks for shoring up key gaps

policyindustry
Jun 17, 2026

Organizations are finding that traditional risk management frameworks don't work well for AI systems because AI has unique failure modes and ethical complexities. A new generation of AI-specific frameworks, like ISO/IEC 42001 and NIST AI Risk Management Framework, has emerged to help organizations identify where AI can fail, implement safeguards, and demonstrate responsible AI use to regulators and customers. These frameworks are complementary tools that focus on different areas, such as governance, security controls, and regulatory compliance, so organizations should choose based on their specific gaps.

CSO Online
Prev1...153154155156157...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026