aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
4
[LAST_7D]
161
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges 14x Ahead of Planned IPO: The company behind Claude reported second quarter revenue of $11.5 billion, representing over 14 times year-over-year growth as it prepares to go public and competes directly with OpenAI for enterprise customers.

>

AI Firms Suspected of Covert Data Acquisition Through Bulk Book Purchases: Secondhand booksellers across the UK and Ireland are reporting unexplained bulk orders believed to be AI companies acquiring physical books for text extraction and model training, following reports that Anthropic has spent millions on similar acquisitions.

Latest Intel

page 164/643
VIEW ALL
01

CVE-2026-12203: A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown par

security
Jun 14, 2026

A vulnerability in HKUDS AI-Trader allowed attackers to access sensitive information through the research export feature by manipulating the /api/research/agents.csv file, and this flaw could be exploited remotely without needing physical access to the system. The vulnerability affects versions up to commit 74caf996f78dcc0c657df8365c8544678a16e215, and the exploit details have been made publicly available.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Fix: Apply patch 91a31aac1b0f4dbc6b8bef9f6eff0b7912e0bc65. The vendor confirms the fix requires authentication (proof of identity) and the research_exports capability (a specific permission) to access research export endpoints.

NVD/CVE Database
02

China may have accessed Mythos

securitypolicy
Jun 14, 2026

According to a report, the White House may have restricted exports of Anthropic's Mythos AI model because it feared a group linked to China had accessed it, which would pose serious national security risks. One concern is that the Chinese government could use distillation (training a simpler AI on a more advanced one to copy its behavior) to reverse engineer the model.

The Verge (AI)
03

Introducing the OpenAI Partner Network

industry
Jun 14, 2026

OpenAI announced a new Partner Network program to help organizations adopt AI by connecting them with consulting and technology partners who can identify use cases, integrate AI into existing systems, and manage organizational change. The program invests $150 million to support partners across systems integration, consulting, and technology, with plans to train 300,000 certified consultants by the end of 2026, recognizing that enterprise AI success depends on strategy and implementation support, not just model capabilities.

OpenAI Blog
04

A year after Meta tapped Alexandr Wang to build a new AI model, Zuckerberg has to sell it

industry
Jun 14, 2026

Meta spent $14.3 billion to hire Alexandr Wang and his team to build proprietary AI models, resulting in the Muse Spark model released in April 2024, a shift away from Meta's previous open-source approach. However, Meta still struggles to compete with OpenAI and Google, and faces challenges convincing developers and investors that it can monetize AI products beyond its core advertising business, which currently accounts for 98% of revenue. The company's earlier open-source Llama models failed to attract developers, damaging its reputation in the AI community.

CNBC Technology
05

Rethinking ransomware defense in the age of generative AI

securityresearch
Jun 14, 2026

This article examines how ransomware (malicious software that locks files and demands payment to unlock them) defense strategies need to change as generative AI (AI systems that create new content like text or code) becomes more common. The piece suggests that traditional security approaches may be less effective in an environment where AI is widely used.

Elsevier Security Journals
06

A Survey of Neural Network Robustness Assessment in Image Recognition

researchsafety
Jun 14, 2026

This academic survey paper reviews methods for testing how well neural networks (AI systems trained to recognize patterns in data) perform when faced with unexpected or manipulated images. The paper examines various approaches researchers use to assess whether image recognition systems remain accurate and reliable under challenging conditions.

ACM Digital Library (TOPS, DTRAP, CSUR)
07

Amazon security research reportedly led to the White House’s Anthropic Fable ban

securitypolicy
Jun 13, 2026

Amazon's security research found that Anthropic's Fable 5 AI model could be manipulated through prompt injection (tricking an AI by hiding instructions in its input) to reveal information usable for cyberattacks. After Amazon CEO Andy Jassy shared these findings with the White House, Anthropic restricted access to Fable 5 and Mythos 5 to prevent foreign nationals from using the models.

The Verge (AI)
08

Amazon CEO reportedly raised Anthropic model concerns before government crackdown

securitypolicy
Jun 13, 2026

Amazon CEO Andy Jassy reportedly told U.S. government officials that researchers discovered security vulnerabilities in Anthropic's Claude models that could be exploited for cyberattacks, leading the government to ban exports of two models (Fable 5 and Mythos 5). Anthropic subsequently cut off worldwide access to these models, though the company stated that the concerning capabilities were already available in other public models.

TechCrunch (Security)
09

My yard is dying, so I made an app for that

industry
Jun 13, 2026

A user prompted Google's Gemini AI to build a functional app in a single request, and the AI generated working code in a preview window. However, Gemini encountered a bug (a race condition, which is when the order of operations in code causes unexpected behavior) and reported a broken channel, though it provided a button to fix the issue, which succeeded after 233 seconds.

The Verge (AI)
10

Anthropic cuts off Fable 5 and Mythos 5 access following government order

securitypolicy
Jun 13, 2026

The U.S. government ordered Anthropic to block access to two AI models called Fable 5 and Mythos 5 due to unspecified national security concerns, and the company complied by cutting off access for all users worldwide, including its own employees. Anthropic stated that the government did not provide detailed information about the security threat and only mentioned potential jailbreak (tricks to make the AI ignore its safety instructions) vulnerabilities verbally, which the company claims were minor.

The Verge (AI)
Prev1...162163164165166...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026