aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 191/643
VIEW ALL
01

OpenAI public policy agenda

policy
Jun 3, 2026

OpenAI has published its public policy agenda centered on ensuring that artificial general intelligence (AGI, highly capable AI systems that can perform many tasks) benefits all of humanity through five core principles: democratization, empowerment, universal prosperity, resilience, and adaptability. The document outlines OpenAI's policy priorities, including a focus on frontier AI safety (protecting against risks from the most advanced AI models, particularly regarding CBRN weapons like cyber or biological threats) and support for state and federal frameworks that emphasize transparency, safety incident reporting, and developer accountability.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Fix: OpenAI supports state-level legislative efforts such as California SB 53, the New York RAISE Act, and Illinois SB 315, which emphasize transparency, public reporting around catastrophic-risk evaluations and safety incidents, whistleblower protections, and enforceable accountability for developers. OpenAI also supports Congressional action to establish a comprehensive federal framework that leverages state frontier safety laws, strengthens the Center for AI Standards and Innovation (CAISI) as the primary federal institution for frontier AI safety, and mobilizes a broader resilience plan across government to address national security and public safety challenges.

OpenAI Blog
02

A blueprint for democratic governance of frontier AI

policy
Jun 3, 2026

This document proposes a strategy for the U.S. government to create lasting institutions that oversee frontier AI (the most advanced AI systems being developed). The plan has three main parts: build a national framework based on state laws already in place, strengthen CAISI (the federal organization responsible for frontier AI safety) as the main federal institution, and develop a broader government-wide plan to address national security and public safety risks from advanced AI.

OpenAI Blog
03

Google adds Android protection against AI deepfake scam calls

safetysecurity
Jun 3, 2026

Google is rolling out a new Android security feature called 'fake call detection' that protects users from AI deepfake scam calls where scammers impersonate someone's contacts. The feature works by having a user's device send an encrypted confirmation signal when receiving a call, and if that signal is missing, it pings the actual contact's phone to verify the call is real, warning the user to hang up if the contact's device confirms they're not calling.

Fix: Google's mitigation is built into the new 'fake call detection' feature, which is rolling out globally this month to Android 12 and later devices (starting with Pixel devices) and enabled by default. The feature requires Phone by Google, Contacts, and Google Messages (with RCS, or Rich Communication Services, enabled) to be installed. Google also stated: 'If your device uses a different app, you can install Phone by Google from the Play Store and set it as your default phone app to help protect yourself from fake calls.'

BleepingComputer
04

Google must let publishers opt out of AI Search features, rules UK

policy
Jun 3, 2026

The UK's Competition and Markets Authority has ruled that Google must allow website publishers to opt out of AI Search features, including AI Overviews (summaries generated by AI) and prevent their content from being used to train Google's AI models. This new rule gives publishers, especially news organizations, more control over how their content is used by AI systems.

The Verge (AI)
05

Debapt: Ontology-driven multi-agent debate for APT adversary profile construction from cyber threat intelligence

researchsecurity
Jun 3, 2026

Debapt is a system that uses multiple AI agents (independent AI programs that work together) debating with each other to build profiles of APT (advanced persistent threat, a sophisticated type of cyberattack) adversaries by analyzing cyber threat intelligence (information about security threats). The system uses an ontology (a formal structure that defines how concepts relate to each other) to organize this debate process. This research proposes a new way to understand and track advanced attackers by having AI agents discuss and reason through threat data together.

Elsevier Security Journals
06

Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure

securityindustry
Jun 2, 2026

Anthropic expanded its Project Glasswing (an AI-based vulnerability hunting initiative that finds security bugs in software) to 150 more companies, especially those in critical infrastructure like power and healthcare. However, security experts warn this creates a bottleneck problem: if AI finds vulnerabilities 10 or more times faster than before, companies may not be able to validate, prioritize, patch, and deploy fixes quickly enough, potentially overwhelming security teams rather than actually improving defense.

CSO Online
07

Deepfake detection with dual-mode swin transformer: Multi-scale feature learning and local ambiguity mitigation

researchsafety
Jun 2, 2026

This research paper presents a method for detecting deepfakes (synthetic videos or images created by AI to look realistic) using a dual-mode Swin Transformer, which is a type of neural network architecture. The approach uses multi-scale feature learning (analyzing visual details at different zoom levels) and local ambiguity mitigation (reducing confusion in uncertain areas) to improve detection accuracy. This is a technical contribution to security research, not a response to an existing vulnerability or security incident.

Elsevier Security Journals
08

Palo Alto CEO says customer meeting requests have surged amid AI security concerns

securityindustry
Jun 2, 2026

Palo Alto Networks CEO Nikesh Arora reported a surge in customer meetings, with the company fielding roughly 1,200 inquiries in recent weeks from organizations seeking guidance on AI security risks. The article notes that AI-powered attacks are becoming more sophisticated, making cybersecurity more important for companies, and that earlier investor concerns about AI disrupting cybersecurity companies appear to have been overblown.

CNBC Technology
09

CVE-2026-44654: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha

security
Jun 2, 2026

LibreChat (a ChatGPT-like tool that connects to multiple AI providers) has a security flaw in versions up to 0.8.3 where someone with editing access to a shared agent can delete files globally, breaking the owner's separate private agents that use the same files. This is a cross-agent integrity violation, meaning one agent's access should not affect another agent's files.

Fix: Version 0.8.4 contains a patch.

NVD/CVE Database
10

CVE-2026-44653: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users

security
Jun 2, 2026

LibreChat, a ChatGPT-like application supporting multiple AI providers, has a vulnerability in versions up to 0.8.3 where users with limited VIEW access can retrieve encrypted admin passwords and API keys through specific API endpoints, exposing credentials that should remain secret. This happens because the API returns plaintext sensitive values instead of hiding them from non-admin users.

Fix: Version 0.8.4 contains a patch. The source also recommends these additional approaches: never return decrypted admin-managed secrets to non-owners; redact apiKey.key and oauth.client_secret from all API responses; consider returning only boolean presence indicators for secrets (true/false flags showing whether a secret exists, similar to the auth-values route pattern); and if owners need to edit configs without re-entering secrets, preserve secrets server-side and return placeholders instead of plaintext values.

NVD/CVE Database
Prev1...189190191192193...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026