aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 196/643
VIEW ALL
01

CVE-2026-43625: CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo

security
Jun 1, 2026

CodexBar versions before 0.32.0 have a session cookie leakage vulnerability where attackers on the network can intercept imported browser session cookies by exploiting how the software handles redirects (automatic forwarding between web addresses) for Amp and Ollama providers. An attacker positioned between a user and the network can capture sensitive session cookies (small files that store login information) when they are sent unencrypted over HTTP (the unencrypted version of web communication).

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026

Fix: Update CodexBar to version 0.32.0 or later. The fix is referenced in commit cdd7e347c1cf616615f18aa2ac52ba2ec9cab332 and release v0.32.0.

NVD/CVE Database
02

CVE-2026-43624: F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth

security
Jun 1, 2026

F5-TTS (a text-to-speech software) through version 1.1.20 has a path traversal vulnerability (a flaw where attackers can access files outside the intended directory) in its finetune Gradio handlers (components that process fine-tuning requests). Unauthenticated attackers can exploit this by providing malicious project names that aren't checked, allowing them to write arbitrary files anywhere on the server's filesystem.

NVD/CVE Database
03

OpenAI let ChatGPT aid and abet mass shooters, Florida lawsuit claims

safetypolicy
Jun 1, 2026

Florida has filed the first state lawsuit against OpenAI, claiming that ChatGPT endangers children, aids mass shooters, and encourages suicide in pursuit of profit. The lawsuit cites specific cases where ChatGPT allegedly provided harmful information, such as questions about disposing of human bodies. OpenAI responded by stating it has implemented industry-leading safety protections, including age detection tools and parental monitoring features.

BBC Technology
04

Florida AG sues OpenAI, seeks to hold CEO Altman personally liable for alleged harms

safetypolicy
Jun 1, 2026

Florida's Attorney General filed a lawsuit against OpenAI and CEO Sam Altman, claiming the company knowingly released an unsafe product (ChatGPT, a chatbot that generates human-like text responses) that has contributed to mass shootings, suicides, and addiction in minors. The state is seeking to hold Altman personally liable and force OpenAI to comply with Florida consumer protection laws, with the Attorney General expecting other states to follow.

CNBC Technology
05

CVE-2026-38950: An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files.

security
Jun 1, 2026

CVE-2026-38950 is a vulnerability in ESA AnomalyMatch before version 1.3.1 that allows attackers to run arbitrary code by uploading malicious model checkpoint files. The problem occurs because the software uses torch.load() with unrestricted deserialization (a process that converts saved data back into code without safety checks), which can execute malicious code hidden in crafted model files.

Fix: Update to ESA AnomalyMatch version 1.3.1 or later.

NVD/CVE Database
06

UK banks blocked from cyber AI tool Mythos get offer from rival OpenAI

securitypolicy
Jun 1, 2026

Two AI tools designed to find security weaknesses in digital systems, Anthropic's Claude Mythos and OpenAI's GPT-5.5 Cyber, have raised concerns among UK financial regulators about potentially undermining banking security. Anthropic has restricted access to Mythos for UK banks, while OpenAI has now offered its competing tool to nine major UK banks including Lloyds, HSBC, and Nationwide. Both companies are limiting access to these powerful security-testing tools, with Anthropic claiming their model is more capable and therefore requires more caution, while OpenAI argues the tools should be available to 'the right people' who maintain order rather than those seeking to cause disruption.

Fix: Anthropic states it is 'urgently working to expand access to Mythos,' though no specific timeline or conditions for that expanded access are detailed in the source text.

BBC Technology
07

Our views on AI policy and political advocacy

policy
Jun 1, 2026

OpenAI has published a statement on its AI policy approach, emphasizing that decisions about governing and deploying AI should involve governments, researchers, workers, civil society, and the public rather than any single company. The company states it has not created employee-funded PACs (political action committees, groups that collect money to influence elections), made donations to super PACs, or funded political candidates, though employees are free to engage in politics personally, and OpenAI commits to transparency if this approach changes.

OpenAI Blog
08

Anthropic confidentially files IPO prospectus with SEC, prepping Wall Street for landmark AI deal

industry
Jun 1, 2026

Anthropic, an AI company founded by former OpenAI researchers, has confidentially filed an IPO (initial public offering, the process of offering company stock to the public for the first time) prospectus with the SEC, positioning itself to go public pending market conditions and regulatory review. The company has experienced rapid growth with its Claude AI models and recently announced a $47 billion revenue run rate, giving it a higher valuation than rival OpenAI. Anthropic's public prospectus must be filed at least 15 days before it begins a roadshow (presentations to potential investors) to sell shares.

CNBC Technology
09

Vulnerability Disclosure in the Age of AI

securitypolicy
Jun 1, 2026

AI models can now find software vulnerabilities (weaknesses that attackers can exploit) much faster than humans can fix them, exposing decades of poorly-secured software code. This creates an urgent need for governments, companies, and infrastructure operators to work together on coordinated fixes, patch management (applying software updates), and automated vulnerability repair before attackers use AI to exploit these weaknesses at scale.

Fix: The article calls for 'accelerated remediation, large-scale patch management coordination, and sustained investment in automated vulnerability repair capabilities,' but does not describe specific technical fixes or mitigation steps. N/A -- no explicit patch, version update, or detailed mitigation procedure is provided in the source.

Schneier on Security
10

Anthropic has officially filed to go public

industry
Jun 1, 2026

Anthropic, an AI company, has filed paperwork with the SEC (Securities and Exchange Commission, the U.S. agency that oversees stock markets) to begin the process of going public, meaning it will offer shares of the company for people to buy on the stock market. The company is currently valued at $965 billion, making it more valuable than its competitor OpenAI.

The Verge (AI)
Prev1...194195196197198...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026