aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
4
[LAST_7D]
161
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges 14x Ahead of Planned IPO: The company behind Claude reported second quarter revenue of $11.5 billion, representing over 14 times year-over-year growth as it prepares to go public and competes directly with OpenAI for enterprise customers.

>

AI Firms Suspected of Covert Data Acquisition Through Bulk Book Purchases: Secondhand booksellers across the UK and Ireland are reporting unexplained bulk orders believed to be AI companies acquiring physical books for text extraction and model training, following reports that Anthropic has spent millions on similar acquisitions.

Latest Intel

page 165/643
VIEW ALL
01

Anthropic to disable its most advanced AI models after US order limiting foreign access

policysecurity
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
Jun 13, 2026

Anthropic will disable its most advanced AI models (Fable 5 and Mythos 5) for all users after the US government ordered the company to stop letting foreign nationals access them, citing national security concerns. The US government believes the safeguards protecting these models can be bypassed and the models could be used to identify software vulnerabilities, though Anthropic was not given specific details about the security concern.

The Guardian Technology
02

The future of Hollywood isn’t feeding prompts into vanilla gen AI models 

industry
Jun 13, 2026

Despite excitement about generative AI transforming filmmaking, current AI video models can only produce short clips with inconsistent visuals, and several major Hollywood-AI partnerships have ended, suggesting studios cannot yet depend on this technology for professional entertainment products.

The Verge (AI)
03

US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos

securitypolicy
Jun 13, 2026

The US government issued an export control directive requiring Anthropic to block access to its two most advanced AI models, Fable 5 and Mythos 5, for all foreign nationals worldwide, citing national security concerns. Anthropic complied by suspending these models for all users globally, though the company disputes the government's reasoning, which appears related to a reported jailbreak (a method to bypass the model's safety restrictions) that Anthropic says it reviewed and found to be minor and not unique to their system.

Fix: Anthropic states in its developer notice that 'new sessions would fall back to a user's default model or Opus 4.8, existing Fable 5 sessions would end with an error, and Platform requests to Fable 5 would also fail' and told integrators to 'migrate to other models.' The company also says it is 'working to restore access' to these models and promised 'more details within 24 hours,' though no specific technical fix or timeline for restoration is provided in the source text.

BleepingComputer
04

Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

policy
Jun 13, 2026

Anthropic took its latest AI models, Fable 5 and Mythos 5, offline after receiving a directive from the U.S. government to comply with new export controls (restrictions on who can access advanced technology) that prevent foreign nationals from using them. The company disagreed with how the government handled the order, saying it lacked transparency and technical justification, and expressed hope to restore access soon.

SecurityWeek
05

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

safetypolicy
Jun 13, 2026

The U.S. government ordered Anthropic to suspend access to its advanced AI models Claude Fable 5 and Mythos 5 for all foreign nationals due to national security concerns, citing a discovered method of bypassing (jailbreaking, or tricking the AI's safety rules) these models. Anthropic disputed the order, arguing that the vulnerabilities identified are minor and already known, that its safety systems are robust, and that perfect jailbreak resistance is impossible for any AI company.

The Hacker News
06

Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive

policy
Jun 12, 2026

Anthropic disabled access to its Fable 5 and Mythos 5 AI models after receiving a U.S. government order citing national security concerns and export control restrictions, preventing foreign nationals from using them whether inside or outside the United States. The company immediately suspended the models for all customers to ensure compliance, though other Anthropic models remain available. Anthropic stated the government did not provide specific details about the security concern and said the action did not follow transparent or fair procedures.

CNBC Technology
07

OpenAI says it's engaging 'constructively' with state AGs about concerns

policysafety
Jun 12, 2026

OpenAI says it will work constructively with state attorneys general who are investigating the company over concerns about advertising, data handling, and potential harms to minors and seniors. The investigation comes amid multiple lawsuits against OpenAI, including cases where families allege ChatGPT (a conversational AI chatbot) was misused to cause harm, and as the company prepares for a public stock offering.

Fix: OpenAI stated that 'Today's ChatGPT includes a more protective experience for minors and people experiencing difficult situations, with safeguards that direct them to real-world resources and trusted human contacts.' No specific version numbers or technical implementation details are provided in the source.

CNBC Technology
08

OpenAI WebRTC Audio Session, now with document context

industry
Jun 12, 2026

OpenAI released a new model called GPT-Realtime-2 for their WebRTC API (a protocol for real-time audio communication in web browsers), which offers improved reasoning capabilities with knowledge through September 2024. A developer updated their audio conversation tool to support this new model and added the ability to paste document context, allowing users to have voice conversations in their browser about custom information.

Simon Willison's Weblog
09

CVE-2026-50287: AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a

security
Jun 12, 2026

AgenticMail, a tool that allows AI agents to access email and phone services, has a security flaw in versions before 0.9.27 where the /mcp endpoint (a communication interface) accepts requests without requiring authentication (verification of identity) when started in HTTP mode. This means a remote attacker could connect to the service and use its tools directly to access real email addresses and phone numbers.

Fix: This issue has been patched in version 0.9.27.

NVD/CVE Database
10

CVE-2026-47138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

security
Jun 12, 2026

Parse Server, an open source backend framework that runs on Node.js, has a vulnerability where attackers can send specially crafted HTTP requests that cause the server to spend seconds or minutes processing a single request before checking user permissions or rate limits. An attacker only needs to know the application's public ID and can overload the server by sending a few concurrent requests or one large request, making it slow or unresponsive for legitimate users.

Fix: Update Parse Server to version 8.6.77 or 9.9.1-alpha.1 or later, as this issue has been patched in these versions.

NVD/CVE Database
Prev1...163164165166167...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026