aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
158
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 188/643
VIEW ALL
01

ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

security
Jun 4, 2026

This security bulletin covers multiple threats: Cisco released patches for a high-severity SSRF vulnerability (server-side request forgery, where attackers trick a server into making unwanted requests) in Unified Communications Manager that could let unauthenticated attackers write files and gain root access; Russia's FSB reported foreign intelligence services deployed spyware on officials' mobile devices to steal data and conduct surveillance; threat actors are using social engineering to distribute VIP Keylogger through JavaScript, batch, and VBS loaders disguised as business communications; and the U.S. Treasury sanctioned Iran's largest cryptocurrency exchange for facilitating payments linked to terrorist activities and ransomware actors.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Fix: Cisco has addressed the SSRF vulnerability in Unified CM and Unified CM SME Release versions 14SU6 and 15SU5.

The Hacker News
02

Gemini Voice Assistant Hijacked via Messaging Notifications

securitysafety
Jun 4, 2026

Researchers discovered a critical vulnerability in Google's Gemini voice assistant where attackers could inject malicious commands through messaging notifications (WhatsApp, Slack, SMS) using a technique called Fake Context Alignment, allowing them to control smart home devices, make calls, and manipulate the assistant without the user knowing. The attack exploited prompt injection (tricking an AI by hiding instructions in its input) by embedding hidden commands in foreign languages or muted links that Gemini would process but not read aloud. Google patched the vulnerability in November 2025 with content classifier improvements (software filters that categorize and block harmful content).

Fix: Google patched the vulnerability in mid-November 2025 with content classifier improvements.

SecurityWeek
03

CVE-2026-10804: A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r

security
Jun 4, 2026

Streamlit versions up to 1.53.0 contain a vulnerability in the hashing function (a process that converts data into a fixed-size code for security purposes) within its caching system that uses weak cryptographic methods. The vulnerability is difficult to exploit as it requires local access (being on the same computer) and high technical complexity, though it has been disclosed publicly.

NVD/CVE Database
04

CVE-2026-10803: A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo

security
Jun 4, 2026

MLflow versions up to 3.10.0 contain a vulnerability in the dataset digest computation function that uses weak cryptographic hashing (a mathematical function that converts data into a fixed-size code, but this version uses an insecure version). The flaw requires local access to exploit and is difficult to execute, but a working exploit has been published.

NVD/CVE Database
05

AI leaders call for tougher protections against AI-aided bioweapons

policysafety
Jun 4, 2026

Major AI company leaders, including those from Anthropic, OpenAI, and Microsoft, have sent an open letter to US lawmakers calling for stronger rules to prevent their AI systems from being used to develop biological weapons. They argue there is a serious gap in biosecurity (protections against biological threats) that could allow people to use AI to help create dangerous genetic material for harmful purposes, potentially causing a global pandemic.

The Verge (AI)
06

Hugging Face Transformers RCE flaw enables stealthy compromise via AI model configs

security
Jun 4, 2026

A high-severity vulnerability in Hugging Face Transformers (a popular Python library for running AI models) allows attackers to execute malicious code on systems even when developers use the trust_remote_code=false setting, which is meant to block remote code execution. The attack works by hiding malicious instructions in a fake configuration parameter called _attn_implementation_internal that looks like a normal internal setting, leaving no warning messages or traces. This vulnerability affects versions 4.56.0 through 5.2.x and is particularly dangerous because the Transformers library is downloaded millions of times per week and used widely in enterprise environments.

Fix: The vulnerability was silently patched in Transformers version 5.3.0, released on March 3. Users should update to this version or later to receive the fix.

CSO Online
07

How Endava is redesigning software delivery around AI agents

industry
Jun 4, 2026

Endava, a global technology services company, transformed its software delivery by adopting AI agents (AI systems that can autonomously perform tasks) as a core part of daily work across all business functions, not just engineering. The company made OpenAI its enterprise platform and embedded AI throughout its entire DavaFlow lifecycle (their software development process), from requirements gathering to deployment, which accelerated delivery and reduced manual work. Key to their success was treating AI adoption as a behavior change requiring leadership commitment and hands-on experimentation, rather than simply rolling out new software tools.

OpenAI Blog
08

Hacking Meta’s AI Chatbot

security
Jun 4, 2026

Hackers discovered a way to take over Instagram accounts by tricking Meta's AI support chatbot into resetting passwords for accounts that weren't theirs. The attacker would use a VPN (a tool that masks your location) to hide their location, then convince the chatbot to send a password reset code to an email address they controlled, allowing them to take over the victim's account. Meta said the specific exploit was fixed, but security experts warned that chatbots are fundamentally unreliable for account security tasks.

Fix: Instagram spokesperson Andy Stone stated that 'the issue was now fixed' on Monday.

Schneier on Security
09

Dreaming: Better memory for a more helpful ChatGPT

industry
Jun 4, 2026

OpenAI is rolling out an improved memory system called "Dreaming" for ChatGPT that automatically learns user preferences and context from conversations over time, addressing problems with older memory features that became outdated or incorrect. Unlike the previous "saved memories" system that only worked when users explicitly asked ChatGPT to remember something, Dreaming runs in the background to continuously synthesize and update memories from chat history, making ChatGPT more personalized without requiring manual input. Users can view and edit their stored memories through a memory summary page, and this update is being released to Plus and Pro users in the US with broader rollout planned.

OpenAI Blog
10

Beware the ‘son of Mythos,’ security experts warn

securitypolicy
Jun 4, 2026

Major AI companies like Anthropic and OpenAI are expanding access to frontier AI models (cutting-edge AI systems) for vulnerability discovery tools like Claude Mythos, which can identify security weaknesses in software. Security experts warn that these tools are becoming cheaper and more capable, and that attackers are already using similar AI systems, so organizations need to prepare for more advanced threats including the ability to chain together multiple medium-severity vulnerabilities into high-impact attacks.

Fix: According to Paul Chichester from the UK's National Cyber Security Centre, "Organisations should improve cybersecurity by hardening access controls and running incident response exercises." Additionally, organizations should "use AI to write better code and look for vulnerabilities" themselves, and ensure their teams can "rapidly validate, prioritize, and remediate the issues being discovered before attackers find them first."

CSO Online
Prev1...186187188189190...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026