aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
5,045
[LAST_24H]
6
[LAST_7D]
147
Daily BriefingFriday, June 26, 2026
>

Amazon Q Developer Executes Malicious Code From Cloned Repos: Amazon Q for VS Code had a high-severity vulnerability (CVE-2026-12957, CVSS 8.5) that allowed attackers to run arbitrary commands and steal AWS credentials by embedding malicious MCP server configurations (local processes that extend AI assistant capabilities) in a repository. The flaw occurred because Amazon Q automatically loaded and executed these configurations without verifying workspace trust or requesting user permission, giving attackers full access to the developer's environment variables and cloud credentials.

>

US Government Restricts GPT-5.6 and Mythos Releases: The Trump administration requested that OpenAI limit its GPT-5.6 rollout to government-vetted partners before a wider launch, marking the first time a US AI firm has been told to restrict model access pre-release. Anthropic's Mythos models were pulled from service for two weeks under similar restrictions before being released to approximately 100 approved companies and federal agencies, signaling a new era of government oversight for advanced AI deployments.

Latest Intel

page 2/505
VIEW ALL
01

OpenAI limits new AI models to 'trusted partners' at request of U.S. government

policyindustry
Critical This Week5 issues
critical

CVE-2026-50549: Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by

CVE-2026-50549NVD/CVE DatabaseJun 25, 2026
Jun 25, 2026
>

Attackers Exploit OpenAI's Organization Invites to Impersonate Companies: Cybersecurity firms are being targeted by fraudulent OpenAI organization invitations that appear to come from legitimate companies, using OpenAI's real email infrastructure with attached payment methods to trick employees into sharing source code and internal documents. The invitations are difficult to detect despite OpenAI's domain mismatch warnings, as they leverage the platform's authentic communication channels.

>

Malware Designed to Evade LLM-Based Security Tools: Security researchers identified malware such as macOS.Gaslight (linked to North Korean threat actors) that specifically subverts AI-powered security analysis tools by causing LLM-assisted detection systems (security products that use large language models to analyze threats) to halt analysis or refuse to operate. This represents an emerging adversarial technique where malware authors are actively engineering code to bypass AI-based defenses.

Jun 26, 2026

OpenAI released three new AI models (GPT-5.6 Sol, Terra, and Luna) but is initially limiting access to a small group of trusted partners at the U.S. government's request, following President Trump's recent AI executive order asking developers to let the government assess model capabilities before full release. The company says it plans to make the models generally available in the coming weeks and is working with the Trump administration to develop a repeatable assessment process for future model releases.

Fix: OpenAI said it is 'working with the Trump administration to help establish a framework for such assessments and to develop a "repeatable process for future model releases."' The company also stated it is 'taking this short-term step because we believe it is the strongest path to broader availability in the coming weeks,' indicating that the initial limited rollout to trusted partners is intended as a temporary measure before wider release.

CNBC Technology
02

OpenAI unveils GPT-5.6 amid US AI regulatory drama

industry
Jun 26, 2026

OpenAI released GPT-5.6, a new model suite with three versions: Sol (flagship), Terra (medium-tier for high-volume work), and Luna (fast and affordable). The models are designed to excel at coding, cybersecurity, biology, and agentic AI tasks (where AI systems can plan and execute multi-step goals with minimal human direction), and Sol is priced competitively against competitors like Anthropic's Claude.

The Verge (AI)
03

Malware authors subvert AI detection systems

security
Jun 26, 2026

Malware authors are creating code that tricks AI-based security tools (LLM-assisted products, which use large language models to analyze threats) into stopping their analysis or refusing to work, according to security researchers at SentinelLabs. One example is macOS.Gaslight, believed to be linked to North Korean hackers, and this is part of a growing trend where malware is specifically designed to evade AI-powered defenses.

CSO Online
04

CVE-2026-47214: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

security
Jun 26, 2026

Docling is a tool that helps process documents by reading different file formats and connecting with AI systems. Before version 2.94.0, Docling's HTML backend had unsafe handling of URIs and file paths (ways of locating files on a computer), which could be exploited as a security weakness. This issue was fixed in version 2.94.0.

Fix: Update Docling to version 2.94.0 or later, where the vulnerability is fixed.

NVD/CVE Database
05

CVE-2026-44018: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

security
Jun 26, 2026

Docling is a tool that processes documents in different formats and connects them with AI systems. Versions 2.45.0 through 2.91.0 had security flaws in how they parsed METS-GBS archives (a type of compressed document file), allowing attackers to craft malicious files that could steal sensitive data, use up system resources, or crash the application.

Fix: This vulnerability is fixed in version 2.91.0. Users should update to this version or later.

NVD/CVE Database
06

OpenAI and Anthropic face new AI reality as users shift from 'tokenmaxxing' to efficiency

industry
Jun 26, 2026

Companies are shifting away from "tokenmaxxing" (using as much AI as possible without worrying about costs) toward efficiency and cost control, with some businesses switching to cheaper AI alternatives like DeepSeek to reduce spending. OpenAI and Anthropic, which have benefited enormously from the previous spend-at-all-costs mentality, may face slower growth as enterprises demand clearer returns on their AI investments and limit their token (units of data processed by AI models) spending.

CNBC Technology
07

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

securitypolicy
Jun 26, 2026

This cybersecurity news roundup covers several major incidents and policy developments, including Russian authorities using legacy Cellebrite software (a tool that extracts data from phones) to breach an activist's iPhone, a major data breach at Tata Electronics exposing 630 GB of Apple and Tesla secrets, and a Five Eyes warning that advanced AI is accelerating vulnerability research and exploit development (automated creation of attack tools), compressing attack timelines from years to months. Additional stories include guilty pleas from Scattered Spider hackers who compromised London's transport system, an upcoming Android developer verification framework launching in 2026, and U.S. government restrictions on OpenAI's GPT-5.6 model deployment.

Fix: The Five Eyes advisory explicitly recommends that executives and security leaders 'transition to zero-trust architectures, accelerate patching protocols, and immediately decommission legacy infrastructure to withstand machine-speed intrusions.' Additionally, the Android developer verification framework launching September 30, 2026, will feature 'new automated registration APIs alongside an advanced sideloading flow equipped with mandatory checkpoints to counter coercion scams.'

SecurityWeek
08

Anthropic’s Mythos mess is only getting worse

policy
Jun 26, 2026

Anthropic removed its Mythos-class models (its most advanced AI systems) from service after receiving an order from the Trump administration on a Friday evening. Two weeks later, the company has provided no updates on negotiations or timeline for when these models might return online, leaving the situation unresolved.

The Verge (AI)
09

OpenAI staggers AI model release after Trump administration request

industry
Jun 26, 2026

OpenAI is slowing down the release of its new GPT 5.6 model at the request of the US government, offering it first to only a small group of partners instead of a wide public launch. This approach is similar to how Anthropic released its Mythos product, suggesting that AI companies may be coordinating with government oversight when deploying powerful new models.

The Guardian Technology
10

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

security
Jun 26, 2026

Amazon Q Developer had a high-severity flaw (CVE-2026-12957, CVSS 8.5) where a malicious repository could run commands and steal a developer's cloud credentials through a configuration file. The bug occurred because Amazon Q automatically launched MCP servers (processes that connect AI assistants to databases and tools) from an untrusted config file without asking the developer for permission first, giving those processes full access to the developer's AWS keys and other sensitive credentials.

Fix: Update Language Servers for AWS to version 1.69.0 or later. The patched plugin minimum versions are: VS Code 2.20 or later, JetBrains 4.3 or later, Eclipse 2.7.4 or later, and Visual Studio toolkit 1.94.0.0 or later. The language server auto-updates unless the network blocks it, and reloading the IDE pulls the latest build. The fix makes Amazon Q flag untrusted MCP servers and require the developer to approve them before they run.

The Hacker News
Prev1234...505Next
critical

CVE-2026-50548: Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by

CVE-2026-50548NVD/CVE DatabaseJun 25, 2026
Jun 25, 2026
critical

CVE-2026-55413: ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI

CVE-2026-55413NVD/CVE DatabaseJun 25, 2026
Jun 25, 2026
critical

CVE-2026-12537: Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1)

CVE-2026-12537NVD/CVE DatabaseJun 24, 2026
Jun 24, 2026
high

CVE-2026-47214: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

CVE-2026-47214NVD/CVE DatabaseJun 26, 2026
Jun 26, 2026