aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
159
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 171/643
VIEW ALL
01

OpenAI mulls slashing prices as it competes with Anthropic for users: WSJ

industry
Jun 10, 2026

OpenAI is considering cutting prices on its AI services, particularly the cost of tokens (the units that AI companies charge users for processing text and other content), to compete with rival Anthropic. Both companies are preparing for an IPO (initial public offering, where a company sells shares to the public for the first time) and have been increasing competition as ChatGPT continues to gain users.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
CNBC Technology
02

BBVA puts AI at the core of banking with OpenAI

industry
Jun 10, 2026

BBVA, a global bank founded in 1857, is partnering with OpenAI to integrate AI (artificial intelligence) throughout its entire organization as part of its transformation strategy called 'The Eight.' Over 100,000 BBVA employees now use ChatGPT Enterprise to improve customer experiences, help with decision-making, automate operations, and speed up software development across the bank.

OpenAI Blog
03

OpenAI to acquire Ona

industry
Jun 10, 2026

OpenAI is acquiring Ona, a company that specializes in secure cloud execution and orchestration (technology for running and managing code in cloud environments safely). This acquisition will allow Codex (OpenAI's AI tool used by 5 million people weekly) to work on longer tasks that span hours or days by running in persistent cloud environments instead of being limited to a single device or session. The integration will let organizations deploy AI agents (autonomous programs that perform tasks) securely within their own cloud infrastructure while maintaining control over security, data access, and activity logging.

OpenAI Blog
04

Supporting Europe’s work in ensuring a trustworthy AI ecosystem

policysafety
Jun 10, 2026

OpenAI is supporting the European Commission's Code of Practice on Transparency of AI-Generated Content to help people understand where online content comes from and whether it was created or edited by AI. The company is implementing provenance standards (technical methods for tracking content origin and history) by adding C2PA metadata (embedded information that travels with images to show their source and creation details) to its DALL-E 3 image tool, combining this with SynthID watermarks (invisible digital markers), and offering a public verification tool at openai.com/verify so people can check if images contain provenance signals.

Fix: OpenAI's approach includes: (1) adding C2PA Content Credentials metadata to images created and edited by DALL-E 3 in ChatGPT and the OpenAI API; (2) including both C2PA metadata and SynthID watermarks on images generated with ChatGPT, Codex, and the OpenAI API; (3) providing openai.com/verify, a public verification experience where people can check whether supported images contain provenance signals associated with OpenAI-generated images; and (4) contributing to open standards through joining the C2PA Steering Committee to advance interoperable provenance standards across the ecosystem.

OpenAI Blog
05

CISA Rewrites Federal Patching Requirements for AI Threat Era

policysecurity
Jun 10, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated patching requirements for federal agencies to address AI-related security threats. Agencies must now fix the most critical vulnerabilities (flaws in software that attackers can exploit) within three days, while less severe issues can be addressed later.

Dark Reading
06

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

policysecurity
Jun 10, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA) released a new directive requiring federal agencies to patch critical software vulnerabilities (bugs) in as little as three days, driven by concerns that AI models can now discover and exploit security flaws faster than humans can fix them. The directive uses a prioritization system based on four factors, including whether a vulnerability is publicly exposed and can be automatically exploited, to determine how urgently each bug must be addressed.

Fix: CISA's directive requires agencies to use a prioritization rubric based on four assessments: whether a vulnerability is in a publicly exposed system, whether it appears in CISA's Known Exploited Vulnerabilities Catalog, whether an attacker could automate exploitation, and how much access an attacker would gain. When all four criteria apply, the vulnerability must be fixed within three days, and agencies must also execute a 'forensic triage' process to determine if systems have already been compromised.

Wired (Security)
07

CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice

policysecurity
Jun 10, 2026

Organizations are struggling to patch vulnerabilities fast enough, with only 26% of actively exploited vulnerabilities fully fixed while attackers have reduced their exploitation time to hours or days. CISA issued Binding Operational Directive 26-04, which tells federal agencies to prioritize patching based on four factors (public exposure, known exploitation, automatable attacks, and post-exploitation impact) rather than just severity scores (CVSS, a 0-10 rating of how severe a vulnerability is), recognizing that AI is accelerating both vulnerability discovery and exploitation. Vulnerabilities meeting three or more of these risk factors must be patched within three days, while lower-risk ones can follow longer timelines.

Fix: CISA's Binding Operational Directive 26-04 introduces a decision framework considering four key factors: whether the vulnerable system is publicly exposed to the internet, whether the vulnerability is listed in the KEV (Known Exploited Vulnerabilities) catalog, whether an attacker can automate exploitation, and how much control an attacker would gain after exploitation. Vulnerabilities exhibiting three or more of these attributes must be patched within three days, while lower-risk vulnerabilities can be addressed on longer timelines or deferred until the next major system upgrade.

CSO Online
08

Access OpenAI models and Codex through your Oracle cloud commitment

industry
Jun 10, 2026

OpenAI and Oracle are partnering to let Oracle Cloud Infrastructure (OCI, Oracle's cloud computing platform) customers use their existing Oracle Cloud Universal Credits (UCM, pre-purchased cloud service allowances) to pay for access to OpenAI's AI models and Codex (a code-generation AI tool). This partnership simplifies how enterprises can adopt advanced AI by letting them use their established purchasing processes and cloud budgets instead of creating separate purchasing agreements.

OpenAI Blog
09

AI Risk Worries Insurers and Businesses Alike

policyindustry
Jun 10, 2026

Insurance companies are responding differently to the growing use of AI in businesses: some are refusing to cover AI-related risks entirely, while others are developing frameworks to manage those risks. The article raises the question of which AI risks companies can actually handle and control.

Dark Reading
10

GHSA-8q5r-mmjf-575q: Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

security
Jun 10, 2026

A vulnerability in Claude Code Action allowed attackers to run arbitrary code on GitHub Actions runners and steal secrets by creating a pull request with a malicious `.mcp.json` file (a configuration file that tells the system which external tools to enable). The problem occurred because the action automatically checked out the attacker's code, read the malicious configuration file, and unconditionally enabled all project MCP servers (integrations with external tools) without validation.

Fix: Update claude-code-action to the latest version. Users referencing anthropics/claude-code-action@v1, anthropics/claude-code-action@beta, anthropics/claude-code-action@main, or other non-pinned tags will have already received this fix.

GitHub Advisory Database
Prev1...169170171172173...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026