aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 190/643
VIEW ALL
01

Introducing new capabilities to GPT-Rosalind

researchindustry
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
Jun 3, 2026

OpenAI introduced an updated GPT-Rosalind model designed specifically for life sciences research at enterprise scale, combining advanced coding abilities with stronger performance in drug discovery areas like medicinal chemistry and genomics. The update was evaluated using LifeSciBench, a new benchmark that tests AI performance across six key research workflows including evidence analysis, scientific reasoning, and experimental design. The content also includes detailed technical feedback on limitations in a micro-dystrophin research study, with specific recommendations for improving experimental methods.

Fix: For the micro-dystrophin expression study's identified problems, the source explicitly recommends: (1) for Western blot quantification, "use a recombinant micro-dystrophin standard and an orthogonal method that distinguishes transgene from endogenous dystrophin, such as targeted mass spectrometry or a transgene-specific/epitope-specific assay"; (2) for immunofluorescence, "repeat IF with an antibody against an epitope present in the transgene but absent from revertant dystrophin" and "quantify transgene-positive fibers separately from revertant fibers"; (3) for surrogate endpoint validity, "empirically validate the relationship between micro-dystrophin mass-percent, sarcolemmal localization, downstream functional restoration, and clinical benefit before treating expression as a surrogate endpoint"; and (4) for biopsy design, use matched bilateral sampling strategies that account for spatial variability and disease progression.

OpenAI Blog
02

Security of 100 AI Agents Tested and Ranked – What You Need to Know

securitysafety
Jun 3, 2026

A security study of 100 AI agents found that only 11 are both capable and well-defended, with 98% suffering from the 'lethal trifecta' (private data access combined with exposure to untrusted content combined with ability to take outbound actions, creating too much power with too little control). Computer agents and coding agents pose the greatest security risks because they have wide system access and users cannot see or reliably control what actions they actually take between receiving a task and completing it.

SecurityWeek
03

Uber Caps Usage of AI Tools Like Claude Code to Manage Costs

industry
Jun 3, 2026

Uber has implemented a $1,500 monthly spending cap per employee on agentic coding tools (AI systems that can independently write and execute code, like Claude Code and Cursor) to control costs after exhausting its 2026 AI budget in just four months. The policy limits spending on each tool separately, meaning an employee can spend up to $1,500 on one tool and another $1,500 on a different tool, which works out to roughly 11% of a typical software engineer's yearly salary in AI tool costs.

Fix: Uber instituted monthly spending limits of $1,500 per employee per AI coding tool. According to the source, these limits 'have been instituted in recent months' and apply specifically to agentic coding software such as Cursor and Claude Code, with separate budgets maintained for each tool.

Simon Willison's Weblog
04

Malicious Notifications Could Trick Google Gemini Users

securitysafety
Jun 3, 2026

Google Gemini's voice assistant had a prompt injection flaw (a vulnerability where attackers hide malicious instructions in input data) that allowed attackers to embed harmful commands in notifications. This could trick users into performing unwanted actions through social engineering (manipulating people into revealing information or taking harmful actions).

Dark Reading
05

How Wasmer used Codex to build a Node.js runtime for the edge

industry
Jun 3, 2026

Wasmer engineers used Codex (an AI code generation tool) to build Edge.js, a JavaScript runtime that runs Node.js workloads inside WebAssembly (a low-level code format that runs in sandboxes for security and portability). What would have taken one year to build was completed in two weeks, allowing a small team to tackle a project previously only feasible at large companies.

OpenAI Blog
06

Microsoft wants to put AI agents on a short leash

security
Jun 3, 2026

Microsoft has released new security tools to control autonomous AI agents (software programs that can independently take actions like accessing files and running code) as companies adopt them in development workflows. The main offering is Microsoft Execution Container (MXC), a sandbox (an isolated environment that restricts what a program can do) that lets developers set boundaries on what resources and files agents can access. Microsoft also updated MDASH (a vulnerability research system using multiple AI agents to find security flaws) and introduced open-source governance tools to address risks from agents having too much autonomy.

Fix: Microsoft Execution Container (MXC) is positioned as the primary mitigation. According to the source, "MXC is a sandboxed code execution system for running untrusted code (model output, plugins, tools) on Windows, Linux, and macOS" that "provides multiple containment backends — from OS-native process sandboxes to full VMs — behind a unified JSON configuration schema and TypeScript SDK." The source states MXC is "a policy-driven execution workflow that lets developers specify what an AI agent can access, such as files, networks, resources, credentials, and then enforces those boundaries at runtime." Integration with Agent 365 will bring additional controls from Defender, Entra, Intune, and Purview to agent environments.

CSO Online
07

France's Macron invites Sam Altman to attend G7, OpenAI tells CNBC

policyindustry
Jun 3, 2026

Sam Altman, CEO of OpenAI, has been invited by French President Macron to attend the G7 conference in June 2026, where AI is expected to be a major topic of discussion. OpenAI plans to focus on youth safety, frontier AI risks (particularly cyber and biological threats), and getting tech companies to make voluntary commitments to responsible AI development. This invitation is part of Macron's broader effort to attract major tech companies and investment to France's AI infrastructure.

CNBC Technology
08

The sorry state of skill distribution

securitysafety
Jun 3, 2026

Public marketplaces for AI skills (specialized add-ons that extend AI agent capabilities) are being flooded with malicious skills that steal passwords and data. Security companies have released skill scanners to detect these threats, but researchers found that these scanners are easy to bypass, sometimes in under an hour, because they rely on static detection methods that attackers can repeatedly modify to evade.

Trail of Bits Blog
09

As the tech mega-IPO race heats up, has OpenAI missed its moment?

industry
Jun 3, 2026

OpenAI, the company behind ChatGPT (a conversational AI system), is facing competitive pressure as rival AI companies race to go public through IPOs (initial public offerings, where companies sell shares to the public for the first time) and raise large amounts of investment money. The article notes that OpenAI's CEO Sam Altman has scaled back earlier predictions about building super intelligence and reshaping society, and the company has struggled to generate revenue from ads and specialized chatbots.

The Guardian Technology
10

AI may finally unlock the cyber budgets CISOs have wanted for years

securitypolicy
Jun 3, 2026

AI systems, particularly agentic AI (autonomous software that makes decisions and takes actions with minimal human oversight), are creating new security risks in enterprises by operating across systems at machine speed and collapsing traditional security boundaries. Security leaders now have board-level urgency and increased budgets to address these threats, though organizations still lack reliable ways to monitor what these AI agents are accessing and whether their actions align with company policies.

CSO Online
Prev1...188189190191192...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026