aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 193/643
VIEW ALL
01

Trump revives parts of canceled AI order with cybersecurity-focused directive

policysecurity
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
Jun 2, 2026

President Trump signed an executive order focused on strengthening cybersecurity and establishing voluntary cooperation between the federal government and AI developers, reviving parts of a broader AI initiative he had canceled two weeks earlier. The order directs federal agencies to deploy AI-enhanced cybersecurity tools, create a government-industry system for sharing information about security vulnerabilities (known as a vulnerability-sharing initiative), and evaluate the cyber capabilities of advanced AI models. The order emphasizes that it does not impose mandatory licensing or approval requirements on AI developers, attempting to balance national security concerns with innovation.

Fix: The executive order specifies several explicit actions: Within 30 days, the Committee on National Security Systems must prioritize cyber defense of national security systems (NSS, government systems handling classified information). The Department of Defense is directed to prioritize protection of its own information systems. The Cybersecurity and Infrastructure Security Agency (CISA) must issue directives and guidance to strengthen civilian federal networks and accelerate adoption of AI-enabled defensive technologies.

CSO Online
02

Trump signs executive order to review AI models before they’re released

policy
Jun 2, 2026

President Trump signed an executive order creating a voluntary framework requiring AI companies to share their frontier models (cutting-edge AI systems at the technological frontier) with the federal government before public release, aiming to improve security and protect critical infrastructure. The order balances innovation concerns with security risks by directing federal agencies to develop a system for assessing the advanced cyber capabilities of AI models before they are released.

The Verge (AI)
03

Microsoft’s first advanced reasoning AI is here

industry
Jun 2, 2026

Microsoft announced MAI-Thinking-1, a new in-house AI model designed for advanced reasoning tasks, at its Build 2026 conference. The company claims this medium-sized model performs as well as leading models on software engineering benchmarks and was trained from scratch on clean data without using techniques from other companies' models. This represents Microsoft's growing effort to develop its own AI models instead of relying solely on its partnership with OpenAI.

The Verge (AI)
04

Google’s Phone app will tell you if a scammer is impersonating one of your contacts

safety
Jun 2, 2026

Google is adding a feature to its Phone app that detects when scammers use AI to impersonate calls from people in your contacts list, alerting you so you can hang up. The feature is part of Google's June Android update, which includes several other security and convenience improvements across Android devices.

The Verge (AI)
05

Microsoft Scout is a new AI personal assistant built on OpenClaw

industry
Jun 2, 2026

Microsoft is launching Microsoft Scout, a new AI personal assistant built on OpenClaw (a foundation model technology) that integrates into Microsoft 365 apps like Outlook, OneDrive, and Teams. Unlike the existing Copilot assistant, Scout can see and do more, functioning as a comprehensive personal assistant that helps employees with tasks like organizing calendars, managing expenses, and drafting emails.

The Verge (AI)
06

Microsoft’s Project Solara is an OS for AI agent gadgets

industry
Jun 2, 2026

Microsoft announced Project Solara, a new operating system (OS, the core software that manages a device) built on Android and designed specifically for gadgets that run AI agents (software programs that can autonomously perform tasks). The company demonstrated two prototype devices: a desk gadget similar to Amazon Echo Show with facial recognition, and a wearable badge with a camera and fingerprint scanner, both intended to provide access to AI agents.

The Verge (AI)
07

Trump signs executive order seeking early access to new AI releases

policy
Jun 2, 2026

President Trump signed an executive order requiring tech companies to voluntarily share new AI models with the federal government for review up to 30 days before public release. The framework aims to help identify national security and cybersecurity risks before powerful AI systems reach the public, though companies are not legally required to participate.

The Guardian Technology
08

CVE-2026-47117: OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The pr

security
Jun 2, 2026

OpenMed versions before 1.5.2 have a remote code execution vulnerability (RCE, where attackers can run commands on the affected system) in how it loads privacy-filter models. The vulnerability exists because the software uses overly broad pattern matching on user-supplied model names, allowing attackers to trick it into loading malicious code from external sources. An unauthenticated attacker can exploit this by providing a fake model repository containing harmful code that gets executed with the same permissions as the OpenMed service.

Fix: Update to OpenMed version 1.5.2 or later.

NVD/CVE Database
09

Anthropic expands Mythos to 150 additional organizations in more than 15 countries

securityindustry
Jun 2, 2026

Anthropic is expanding access to Mythos, an AI model designed to find software vulnerabilities, to 150 additional organizations across 15+ countries as part of Project Glasswing. The expansion includes industries like power, water, healthcare, and communications, though new partners must meet security requirements first. Since the initial launch in April with 50 partners, Project Glasswing participants have discovered over 10,000 high or critical-level security flaws.

CNBC Technology
10

Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies

securitypolicy
Jun 2, 2026

Amazon Bedrock AgentCore is a tool that lets Software as a Service (SaaS) providers serve multiple clients, called tenants, with different security needs using the same AI agent. Resource-based policies (rules that control who can access a resource directly) let you grant some tenants cross-account access from their own AWS accounts while restricting others to traffic that stays only within a private virtual network, all without sharing credentials or creating separate user accounts for each tenant.

Fix: Use resource-based policies on AgentCore Runtime and AgentCore Runtime endpoint resources to centralize access control. For cross-account access (like Example Corp), implement both a resource-based policy on your resources and an identity-based policy (access rules tied to a user or role) in the tenant's AWS account. For VPC-restricted scenarios (like AnyCompany), use specific IAM conditions to enforce that requests originate only from an approved virtual private cloud (VPC, a private network in AWS), adding a network-level security boundary on top of identity-based controls.

AWS Security Blog
Prev1...191192193194195...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026