aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
2
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 199/643
VIEW ALL
01

Nvidia-backed $5 billion AI company tells CNBC it's launching major expansion in London

industry
Jun 1, 2026

Runway, an AI company valued at $5.3 billion that builds world models (AI systems trained on audio, images, video, and real-world data to understand the physical world), is expanding to London with over $200 million in investment by 2028, joining other major U.S. tech companies like OpenAI and Anthropic in establishing European operations. The expansion aims to serve major European clients and tap into London's talent pool for research in world models and video generation tools.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
CNBC Technology
02

Secure Shadow AI at the Control Plane with Falcon for IT

securityindustry
Jun 1, 2026

CrowdStrike is launching AI Discovery and Governance for Falcon for IT to help organizations find and control AI tools across their infrastructure, addressing the risk of shadow AI (unsanctioned AI systems and locally deployed models running without centralized oversight). Shadow AI expands the attack surface because these systems inherit existing permissions and can access data and credentials, but many organizations lack visibility into where AI is running or what it can access. The new capability gives security teams visibility into AI tools, local model runtimes, SDKs (software development kits, code libraries for building applications), and external AI service integrations at the endpoint layer, enabling them to discover, assess, and govern AI use.

Fix: Organizations should use AI Discovery and Governance for Falcon for IT to "identify, assess, and govern AI technologies across enterprise environments" and to "discover AI use, understand associated risk, and take action from the CrowdStrike Falcon platform." The source states that "Falcon for IT enables teams to take direct action at the endpoint and infrastructure layer. They can use it to remove unauthorized software, enforce configurations, remediate system issues, and contain endpoints."

CrowdStrike Blog
03

CVE-2026-10214: A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_wa

security
May 31, 2026

A vulnerability called OS command injection (a flaw that lets attackers run unauthorized system commands) was found in the Bash Tool component of chatgpt-on-wechat software versions up to 2.0.8. The vulnerability exists in the _get_safety_warning function and can be exploited remotely, meaning an attacker doesn't need direct access to the affected system. This weakness has been publicly disclosed and could be actively exploited.

Fix: Upgrading to version 2.0.9 is capable of addressing this issue. The patch is identified as 16d9b449c9aa53ccee44144a762a2737d7ba4fc4.

NVD/CVE Database
04

This model is not a real person: how AI is shaking up fashion – video

industry
May 31, 2026

Fashion companies are increasingly using generative AI (machine learning technology that creates new images) to produce digital models and product imagery instead of hiring human models or photographers. One Australian retailer emphasized that AI-generated images should be clearly labeled and show products accurately, while a fashion designer noted that these tools can help small brands work more efficiently while maintaining quality standards.

The Guardian Technology
05

Our tech overlords are planning for conscious AI to conquer the cosmos. What could go wrong? | Eduardo Porter

policysafety
May 31, 2026

Some wealthy tech leaders, including Sam Altman of OpenAI and Elon Musk, are promoting a 'transhuman' vision where humans and AI merge or AI becomes the dominant species. Altman warns that if humans and AI both compete for dominance, conflict could result, while Musk suggests humanity's main purpose is to create advanced digital intelligence.

The Guardian Technology
06

How we contain Claude across products

securitysafety
May 30, 2026

Anthropic published documentation explaining how they use multiple containment techniques to restrict what Claude can do across their products. They use process sandboxes (isolated execution environments), virtual machines (complete simulated computers), filesystem boundaries (limiting file access), and egress controls (preventing unauthorized data transfer) to prevent AI agents from accessing credentials, exfiltrating data (stealing information), or reaching unintended systems, even if a user, the AI model, or an attacker tries to find workarounds.

Fix: Anthropic implements containment through: gVisor for Claude.ai, Seatbelt (macOS) and Bubblewrap (Linux) for Claude Code, and full VMs using Apple's Virtualization framework (macOS) or HCS (Windows) for Claude Cowork. They also prevent credentials from entering sandboxes in the first place, ensuring they cannot be exfiltrated regardless of how an agent tries to access them.

Simon Willison's Weblog
07

Model X-Ray: Detection of hidden malware in AI model weights using few shot learning

securityresearch
May 30, 2026

Researchers have developed a technique called Model X-Ray that can detect hidden malware embedded in AI model weights (the numerical parameters that make up a trained AI system) using few-shot learning (training a detector with only a small number of examples). This work addresses a security risk where attackers could hide malicious code inside AI models that might go undetected during normal use.

Elsevier Security Journals
08

Anthropic’s alliance with pope on AI harms: all in good faith or ‘Vatican-washing?’

policyindustry
May 30, 2026

Pope Leo XIV released a major teaching warning about AI's harms, including job displacement, accelerated warfare, and environmental exploitation. Anthropic co-founder Chris Olah spoke at the Vatican ceremony, which some experts criticize as potentially creating superficial 'feelgood' messaging rather than substantive critical examination of AI risks.

The Guardian Technology
09

Russia-aligned crime group Greyvibe extensively uses AI in attacks

security
May 29, 2026

Researchers discovered Greyvibe, a Russia-aligned crime group that uses large language models (LLMs, AI systems trained to generate text) extensively throughout its cyberattacks against Ukrainian targets, including government and military organizations. The group has used generative AI to create spear phishing emails (fraudulent messages pretending to come from trusted sources), malicious scripts, and custom malware programs like PhantomRelay and LegionRelay (remote access trojans, or RATs, which are tools that let attackers control compromised computers). Greyvibe has conducted multiple campaigns since August 2025 using various attack methods, from fake websites to ClickFix-style attacks (tricks that convince users to run malicious commands on their computers).

CSO Online
10

GHSA-hvhp-v2gc-268q: PraisonAI has an Arbitrary File Write in Python API

security
May 29, 2026

PraisonAI (a framework for building AI agents) versions 4.6.37 and earlier have a vulnerability where hidden metadata in webpages can trick AI agents into writing files to any location on a system. The bug happens because the `write_file` function skips path validation (checking whether a file path is safe) when the workspace parameter is `None`, which is the default in production environments.

Fix: Set a default workspace directory and validate that file paths stay within it. The fix involves: (1) replacing `None` workspace with the current working directory using `workspace = os.getcwd()`, and (2) checking that the absolute path stays within the workspace using `is_path_within_directory(abs_path, workspace)` before writing, returning an error if the path is outside the workspace.

GitHub Advisory Database
Prev1...197198199200201...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026