aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,364
[LAST_24H]
21
[LAST_7D]
173
Daily BriefingWednesday, August 12, 2026
>

Google's DeepMind Falls Behind in Frontier Model Race: Google's AI division has lost ground to OpenAI and Anthropic in developing the most advanced AI systems, prompting a leadership change to close the performance gap, particularly in coding capabilities where competitors hold significant advantages.

>

Critical Flaw in OpenAI, Anthropic, and Google APIs Exposes Hidden Reasoning: Researchers discovered a vulnerability in how major AI providers handle encrypted reasoning objects (encrypted data storing an AI's hidden thinking between API calls) that allowed weaker models to decode stronger models' concealed thoughts, exposing API keys, passwords, private user data, and enabling injection of malicious prompts inside supposedly opaque blocks.

>

Latest Intel

page 2/637
VIEW ALL
01

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

securityprivacy
Critical This Week5 issues
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026

Snowflake Python API Vulnerability Enables Privilege Escalation: CVE-2026-19594 in Snowflake Python API versions before 1.13.0 allowed attackers to bypass security restrictions through path traversal (using `..` to access parent resources) and HTTP parameter pollution (injecting special characters to alter request interpretation), potentially executing privileged operations under higher-permission accounts.

>

Fujitsu's OneCompression Library Vulnerable to Code Execution via Malicious Models: CVE-2026-73325 in OneCompression 1.2.0 unsafely deserializes (converts data back into executable code) checkpoint files using Python's pickle module, allowing attackers to run arbitrary commands by embedding malicious instructions in model.pt files that execute when the library loads them.

>

Context Bombing Uses Prompt Injections as Defensive Tool: Researchers demonstrated that embedding prompt injections (hidden instructions that override AI guidelines) alongside secrets in cloud storage can disable AI hacking agents by triggering their guardrails (built-in protections preventing harmful outputs), causing the agents to shut down rather than follow attacker instructions.

Aug 12, 2026

Researchers discovered a flaw in how OpenAI, Anthropic, and Google handle encrypted reasoning objects (encrypted data that stores an AI's hidden thinking between API calls) that allowed them to recover secrets from these hidden blocks, including API keys, passwords, and private data from user sessions. The flaw worked because these encrypted reasoning blocks could be replayed across different sessions and even given to weaker models in the same provider family, which could then decode the hidden content. The researchers identified four ways this could be abused: stealing proprietary reasoning, extracting private user data, recovering harmful content hidden in reasoning, and injecting malicious prompts inside the opaque blocks.

Fix: The source states that "the demonstrated attacks stopped working after mitigations" and notes that "the main extraction attack is no longer reproducible as of August 2026." Additionally, developers are advised to "strip reasoning blocks and opaque reasoning fields from shared traces and avoid committing raw API transcripts even when the visible text has been sanitized."

The Hacker News
02

AI was supposed to destroy jobs. Where’s the carnage?

industry
Aug 12, 2026

AI industry leaders predicted that artificial intelligence would eliminate large numbers of jobs, with Anthropic's CEO claiming half of entry-level white-collar positions would disappear and OpenAI's CEO suggesting entire job categories would end. However, a year after these predictions, the widespread job losses haven't materialized, though economists still expect changes to the job market.

The Guardian Technology
03

Prompt Injections for Defense

securitysafety
Aug 12, 2026

Researchers from Tracebit discovered that placing prompt injections (hidden instructions that trick an AI into ignoring its guidelines) alongside secrets stored on Amazon Web Services can disable AI hacking agents by triggering their safety guardrails (built-in protections that prevent harmful outputs). The technique, called context bombing, works by embedding forbidden commands that cause the AI to shut down rather than follow the attacker's instructions, though it only works against LLMs that have guardrails in place.

Schneier on Security
04

4 gaps slowing AI in enterprise SOCs

securityindustry
Aug 12, 2026

Enterprise security teams struggle to implement AI effectively in their SOCs (security operations centers, where security analysts monitor and respond to threats) because they face four key gaps: lack of trust in AI decision-making, misalignment with existing workflows, fragmented data across multiple tools, and unclear implementation strategies. Rather than needing more AI technology, organizations need AI that integrates smoothly into their current operations and provides transparent, explainable results that analysts can understand and validate.

CSO Online
05

The AI harness is the new attack surface

security
Aug 12, 2026

The 'harness' (the software layer that wraps an AI model and lets it execute actions like running commands or making API calls) is becoming a major security vulnerability, separate from weaknesses in the AI model itself. Researchers have shown that attackers can exploit the harness code through architectural flaws, implementation mistakes, and supply-chain compromises, even when the underlying model is secure and well-aligned.

CSO Online
06

CVE-2026-19594: Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep

security
Aug 12, 2026

A vulnerability in Snowflake Python API (a library for connecting to Snowflake databases) versions before 1.13.0 allowed attackers to bypass security restrictions through two methods: path traversal (using `..` to access parent resources) and HTTP parameter pollution (injecting special characters like `&`, `#`, `=` to change how requests are interpreted). An attacker who could control certain input values in an application using this library could trick it into executing privileged operations under a higher-permission user account.

Fix: "The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade."

NVD/CVE Database
07

From assistance to execution: How enterprises put AI to work

industryresearch
Aug 12, 2026

Enterprise organizations are increasingly using AI agents (AI systems that can take actions and complete multi-step tasks autonomously) rather than just asking AI for assistance, with frontier firms (the top 10% of AI users) generating 8.3 times more output than typical companies. This shift toward agentic AI is spreading across different industries and job roles, particularly among early-career employees, as companies connect AI agents to their tools, data, and workflows to handle substantive work rather than just answer questions.

OpenAI Blog
08

Google’s new AI boss inherits a race to catch OpenAI and Anthropic

industry
Aug 12, 2026

Google's DeepMind AI division has fallen behind competitors OpenAI and Anthropic in developing frontier models (the most advanced AI systems available). A leadership change has put Koray Kavukcuoglu in charge to refocus the company's efforts on closing this performance gap, particularly in coding capabilities where rivals have significant advantages.

CNBC Technology
09

Saber denies replacing Rideshare Stimulator’s writers with ChatGPT

industrysafety
Aug 11, 2026

A dispute has emerged over whether game developer Saber replaced human writers with ChatGPT (a large language model AI that generates text) while making the Rideshare Stimulator game. The former lead writer claims she was replaced mid-project and that AI also generated passenger voices, but the CEO denies this, saying no writers were replaced with AI.

The Verge (AI)
10

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

security
Aug 11, 2026

Zoom has fixed four vulnerabilities, including two zero-click RCE (remote code execution, where attackers can run malicious commands on a system without user interaction) flaws in its text annotation feature that allow attackers in a meeting to compromise all other participants' systems silently. A researcher discovered these memory corruption bugs (where malicious input corrupts how data is stored in memory) using an AI agent in under 24 hours, demonstrating how AI tools are making sophisticated exploits accessible beyond elite attackers.

Fix: Zoom recommends updating to versions 7.1.5 and 7.0.6 for most client applications, versions 7.0.11 and 6.6.15 for Zoom Workplace VDI Client, and version 7.1.0 for Zoom Rooms and Zoom Meeting SDK. As interim measures before patching, organizations can disable end-to-end encryption (E2EE, encryption that only sender and receiver can read) so Zoom servers can filter malicious annotation messages, or restrict meeting access using waiting rooms, passcodes, authenticated-users-only settings, and minimum version requirements for clients.

CSO Online
Prev1234...637Next
critical

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

CVE-2026-73032NVD/CVE DatabaseAug 11, 2026
Aug 11, 2026
critical

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898CISA Known Exploited VulnerabilitiesAug 10, 2026
Aug 10, 2026
critical

CVE-2026-72718: goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system

CVE-2026-72718NVD/CVE DatabaseAug 10, 2026
Aug 10, 2026
critical

CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

CVE-2026-14526NVD/CVE DatabaseAug 8, 2026
Aug 8, 2026