aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
4
[LAST_7D]
161
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges 14x Ahead of Planned IPO: The company behind Claude reported second quarter revenue of $11.5 billion, representing over 14 times year-over-year growth as it prepares to go public and competes directly with OpenAI for enterprise customers.

>

AI Firms Suspected of Covert Data Acquisition Through Bulk Book Purchases: Secondhand booksellers across the UK and Ireland are reporting unexplained bulk orders believed to be AI companies acquiring physical books for text extraction and model training, following reports that Anthropic has spent millions on similar acquisitions.

Latest Intel

page 162/643
VIEW ALL
01

All the news about Anthropic’s new AI fight with the White House

securitypolicy
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
Jun 15, 2026

The White House ordered Anthropic to block foreign access to its newly released AI models, Fable 5 and Mythos 5, after researchers discovered potential jailbreaks (methods to make the AI ignore its safety guidelines) that could be exploited for cyberattacks. Anthropic complied by shutting off access to both models for all users, though the company disagreed with the decision, arguing that a narrow security flaw shouldn't justify recalling models used by hundreds of millions of people.

Fix: Anthropic removed access to Fable 5 and Mythos 5 for all users in response to the government's legal directive.

The Verge (AI)
02

CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE

security
Jun 15, 2026

Kiro IDE, an AI-powered development tool, had a security flaw in versions before 0.11.133 where authentication token cache files (files storing login credentials) were saved with world-readable permissions on macOS and Linux, meaning any user or process on the same computer could read them instead of just the owner.

Fix: Update Kiro IDE to version 0.11.133 or later.

AWS Security Bulletins
03

Trump’s Anthropic shutdown just made the case for non-American AI

policy
Jun 15, 2026

The Trump administration ordered Anthropic to take its newest AI models offline and block access for all foreign nationals, including the company's own international employees. This incident highlights how the US government can control access to advanced AI technology, even for American companies, raising concerns about global AI development being dominated by American political decisions.

The Verge (AI)
04

Anthropic to meet with Trump administration over Mythos dispute

policysecurity
Jun 15, 2026

The U.S. government ordered AI company Anthropic to disable access to its latest AI models, Fable 5 and Mythos 5, citing national security concerns about a potential jailbreak (a method to bypass safety restrictions). Anthropic complied by shutting down access for all users, and senior staff are meeting with Trump administration officials to resolve the dispute, which follows earlier government actions restricting defense contractors from using Anthropic's technology.

CNBC Technology
05

Anthropic to meet with White House over AI tool suspension

safetypolicy
Jun 15, 2026

Anthropic, an AI company, is meeting with US government officials after releasing Fable 5 and Mythos 5, new versions of its Claude Mythos AI model, which the government suspended due to national security concerns. The government discovered a potential jailbreak (a method to make an AI tool do something unintended) in the publicly available version shortly after release, and Anthropic reported receiving only verbal evidence of the vulnerability so far.

BBC Technology
06

Big Tech’s desperate last push at AI regulation

policy
Jun 15, 2026

Tech company lobbyists in Washington have been pushing for preemption, a comprehensive federal law that would create one set of AI rules across the entire country instead of having different regulations in each state. Their efforts have faced political obstacles and public backlash, and they worry that after upcoming elections, Congress may have more Democrats who are unwilling to support their proposals.

The Verge (AI)
07

Salesforce to buy AI customer service platform Fin for $3.6 billion to boost agentic offerings

industry
Jun 15, 2026

Salesforce is acquiring Fin (formerly Intercom), an AI customer service platform, for $3.6 billion to strengthen its agentic AI (autonomous artificial intelligence agents that can independently handle tasks) offerings. Fin's main product is an AI agent powered by a proprietary model called Apex that can resolve customer inquiries across multiple channels including chat, email, WhatsApp, and Slack. This acquisition reflects how software companies are competing to invest in more autonomous AI technologies as businesses increasingly demand agentic solutions.

CNBC Technology
08

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

security
Jun 15, 2026

LiteLLM, a widely-used open-source AI gateway (a system that routes AI requests to multiple providers), has a critical vulnerability chain (CVSS score of 9.9, meaning extremely severe) that lets low-privilege users gain full admin control and run code on the server. The three bugs work together: an authorization bypass (CVE-2026-47101) that lets users create keys with unlimited access, a privilege escalation (CVE-2026-47102) that promotes users to admin, and a sandbox escape (CVE-2026-40217) that executes arbitrary code. This compromise exposes all provider API keys, encrypted credentials, and all prompts and responses passing through the gateway, plus allows attackers to alter AI responses in transit.

Fix: Upgrade to LiteLLM v1.83.14-stable or later. This release, published May 2, includes the complete fix set for all three CVEs in the vulnerability chain.

The Hacker News
09

Cybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful models

policysecurity
Jun 15, 2026

The U.S. government ordered Anthropic to restrict exports of its Fable and Mythos AI models (advanced models designed to find security vulnerabilities), citing national security concerns, which prompted Anthropic to suspend worldwide access to these models. Dozens of prominent cybersecurity experts published an open letter arguing this ban is dangerous because it removes powerful security tools from defenders while adversaries continue advancing, and they claim the vulnerability that justified the ban can be replicated in other widely available AI models like OpenAI's GPT-5.5 and Claude Opus 4.8.

TechCrunch (Security)
10

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

security
Jun 15, 2026

A critical flaw in Microsoft 365 Copilot Enterprise Search could let attackers steal emails, calendar details, and multi-factor authentication codes with a single click on a malicious link. Researchers discovered that three chained bugs, including parameter-to-prompt injection (tricking the AI by hiding instructions in a URL parameter), a timing flaw in how responses are filtered, and a Content Security Policy allowlist for Bing, allowed attackers to extract sensitive data without the user entering any passwords or clicking again.

Fix: Microsoft mitigated the flaw on its backend, so customers have nothing to worry about. No customer action was required.

The Hacker News
Prev1...160161162163164...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026