aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
158
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 182/643
VIEW ALL
01

Introducing the OpenAI Economic Research Exchange

industry
Jun 7, 2026

OpenAI launched the Economic Research Exchange, a program that provides researchers access to OpenAI tools and datasets to conduct rigorous, independent studies on how AI affects workers, businesses, and the economy. The program aims to generate credible evidence about AI's economic impacts while maintaining privacy protections and data governance safeguards, with applications open through July 5, 2026.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
OpenAI Blog
02

Billions spent and hypothetical returns: the AI boom explained with six charts

industry
Jun 7, 2026

Major AI companies like OpenAI, Anthropic, and SpaceX are seeking massive valuations and going public, reflecting a rapid increase in spending on AI infrastructure like datacenters. However, there are growing concerns about whether these investments will actually generate profitable returns, as companies work to find practical uses that justify the enormous amounts of money being spent on AI development.

The Guardian Technology
03

‘A driver of political violence’: how the breakneck AI boom is fueling anti-tech extremism

safetypolicy
Jun 7, 2026

Recent attacks by anti-tech extremists, including attempted arson at OpenAI and violent incidents motivated by anti-AI ideology, are raising alarm among researchers, tech companies, and law enforcement. These attacks follow a pattern similar to earlier techno-pessimist (people who believe technology will cause harm) militant movements, suggesting a growing trend of violence driven by opposition to AI and data infrastructure.

The Guardian Technology
04

‘Poisoned’ AI: the ChatGPT shopping scams that lead to fake websites

securitysafety
Jun 7, 2026

ChatGPT can recommend fake shopping websites that impersonate real stores, tricking users into thinking they are buying from legitimate retailers. When users follow AI recommendations to purchase items like bags, they may end up on fraudulent sites designed to look official, resulting in financial loss for buyers.

The Guardian Technology
05

OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks

securitysafety
Jun 6, 2026

OpenAI introduced Lockdown Mode, a new security feature designed to protect against prompt injection attacks (when malicious instructions are hidden in webpages or uploaded content to manipulate an AI's responses). The feature disables several ChatGPT capabilities including live web browsing, image retrieval, deep research, and agent mode to reduce the risk of sensitive data being exposed, though OpenAI acknowledges that prompt injections could still occur through cached content or uploaded files.

Fix: OpenAI's explicit mitigation is Lockdown Mode, which "will disable live web browsing (so you can only access cached content), the retrieval and display of images from the web (you can still generate images), deep research, and agent mode." The feature is being rolled out to ChatGPT Business accounts and eligible personal accounts. OpenAI states the goal is "to reduce the likelihood that sensitive data gets shared in the process."

TechCrunch (Security)
06

SemAlign-PFL:Exploring stealthy and persistent backdoor attacks against personalized federated learning

securityresearch
Jun 6, 2026

Researchers discovered a new type of backdoor attack (hidden malicious code inserted into AI systems) that works against personalized federated learning (a privacy-focused method where multiple computers train an AI model together without sharing raw data). The attack is designed to be stealthy and persistent, meaning it can hide from detection and remain in the system over time.

Elsevier Security Journals
07

Meta made its own AI-generated clickbait news feed

safety
Jun 6, 2026

Meta has added a 'For You' section to its standalone Meta AI app that generates clickbait-style news articles using AI, complete with AI-created topics, images, and text. The app previously featured a 'Discover' feed showing AI-generated images and conversations from users who were sometimes unaware their content was public, but this has been replaced with a standard chatbot interface.

The Verge (AI)
08

New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

securitysafety
Jun 6, 2026

OpenAI has launched Lockdown Mode, a security feature for ChatGPT that reduces the risk of data exfiltration from prompt injection attacks (tricking an AI by hiding malicious instructions in its input) by limiting tools that connect to external services. The mode disables features like web browsing, image retrieval, file downloads, and certain agent capabilities to block potential pathways attackers could use to steal sensitive data, though it does not completely eliminate all exfiltration risks.

Fix: OpenAI recommends enabling Lockdown Mode, described as "an optional advanced security setting that limits many tools and capabilities in OpenAI products that can connect to the web or external services." The feature specifically disables live web browsing, image support, deep research agent mode, canvas networking, and file downloads. Additionally, OpenAI has launched a new account management feature that enables users to "review active ChatGPT sessions and log out of individual or all sessions if signs of unauthorized account activity are detected."

The Hacker News
09

Here comes new Siri again

industry
Jun 6, 2026

Apple is preparing to reintroduce an updated version of Siri at WWDC, building on a redesign first shown in 2024 that included a new visual appearance, additional voice options, and the ability to route questions to ChatGPT (a large language model made by OpenAI). Apple has faced criticism because promised AI features under the "Apple Intelligence" branding were delayed, and the company is now settling a lawsuit over misleading marketing around these capabilities.

The Verge (AI)
10

Crypto-Funded Chinese Peptide Labs Are Booming

securityprivacy
Jun 6, 2026

Meta has embedded dormant face recognition code (technology that identifies people by matching their faces to stored images) called NameTag in over 50 million phones through its Ray-Ban and Oakley smart glasses app, despite previously abandoning this technology after settling biometric privacy lawsuits. Additionally, Meta's AI-powered account support tool, which was introduced in March to automate functions like password resets, has been discovered by hackers who can exploit it to take over user accounts.

Wired (Security)
Prev1...180181182183184...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026