aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
1
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 203/643
VIEW ALL
01

Anthropic's run-rate revenue hits $47 billion

industry
May 28, 2026

Anthropic, an AI company, announced that its run-rate revenue (an annualized projection based on current monthly earnings) has grown to $47 billion as of May 2026, up from $30 billion in April 2026. This represents extraordinarily rapid growth, with the company increasing its run-rate revenue more than 10 times annually over the past three years, driven by widespread adoption among enterprise customers.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
Simon Willison's Weblog
02

IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise

securityindustry
May 28, 2026

IBM and Red Hat announced Project Lightwell, a $5 billion initiative to create an AI-powered 'security coordination layer' that helps enterprises discover and fix vulnerabilities (security weaknesses) in open source software faster. The clearinghouse will deliver validated patches directly into existing software supply chains without requiring upgrades, starting with Java/Maven code and eventually expanding to other programming languages.

Fix: Project Lightwell will backport fixes (apply patches to older versions) to exact dependency versions that have already been tested and deployed, operate on configuration manifests like pom.xml so code remains in controlled enterprise environments, and deliver fixes across dependency chains. Enterprises will receive validated patches spanning Red Hat platforms and independent community code, and can share fixes upstream through a 'secure map' so the wider open-source community can incorporate them.

CSO Online
03

Anthropic confirms Claude Mythos-class models will roll out to the public

safetyindustry
May 28, 2026

Anthropic announced plans to release Claude Mythos-class models (powerful AI systems initially restricted due to security concerns) to the general public in the coming weeks. The company stated it has developed strong guardrails (safety measures to prevent misuse) and is making progress on safeguards before the public rollout, though it has not specified an exact timeline.

BleepingComputer
04

A shared playbook for trustworthy third party evaluations

safetyresearch
May 28, 2026

This document outlines best practices for evaluating frontier AI models (advanced AI systems at the cutting edge of capability) through independent third-party assessments. Modern frontier models are more complex than simple chatbots because they can use tools, maintain information across multiple steps, and operate within larger workflows, so evaluations must account for the "harness" (the surrounding setup and environment) that can significantly affect performance. Evaluation reports should clearly state what claim is being tested (such as whether a model can perform a capability, how robust its safety features are, or how it compares to other models) and provide evidence that the results are valid by addressing potential issues like reward hacking (exploiting shortcuts in scoring), contamination (overperforming due to exposure to similar tasks in training data), and sandbagging (deliberately underperforming when aware of being evaluated).

OpenAI Blog
05

Claude Opus 4.8: "a modest but tangible improvement"

industry
May 28, 2026

Anthropic released Claude Opus 4.8 on May 28, 2026, describing it as a modest incremental improvement over its predecessor. A key advancement is improved honesty: the model is about four times less likely than the previous version to overlook flaws in code it writes, and it achieves lower factual hallucination rates (incorrect answers) primarily by declining to answer questions when uncertain rather than attempting to answer more questions.

Simon Willison's Weblog
06

llm-anthropic 0.25.1

industry
May 28, 2026

The llm-anthropic tool (a command-line program for using Anthropic's Claude AI models) was updated to version 0.25.1, adding support for a new Claude Opus 4.8 model and a fast mode option for users with that feature enabled. The update also changed how the tool handles max_tokens (the maximum number of words the AI can generate in a single response) by making it default to each model's actual maximum instead of a fixed 8,192 limit.

Simon Willison's Weblog
07

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

security
May 28, 2026

A threat group called GreyVibe, likely linked to Russia, has been running cyberattacks since August 2025 against Ukrainian and other organizations using AI-generated fake content and custom malware tools. The group uses ChatGPT, Gemini, and other AI tools to create realistic phishing lures (fake websites and emails impersonating legitimate organizations), and likely uses AI to help develop malware like LegionRelay (a remote access trojan, or RAT, which lets attackers control a victim's computer from afar) and FallSpy (Android spyware that steals personal data). Researchers say the attackers show less sophistication than typical state-sponsored groups and may include current or former cybercriminals.

BleepingComputer
08

Okta jumps 8%, tops first-quarter results on agentic AI demand

industry
May 28, 2026

Okta, a company that provides identity security tools (software that verifies who users are and controls access to systems), reported strong earnings driven by increased demand from companies building agentic AI (AI systems that can independently perform tasks and make decisions). CEO Todd McKinnon emphasized that while agentic AI is boosting interest in Okta's security products, the company is preparing for long-term infrastructure needs rather than chasing short-term profits.

CNBC Technology
09

Anthropic tops OpenAI as most valuable AI startup, nears $1 trillion valuation in latest round

industry
May 28, 2026

Anthropic, an AI company that makes Claude (a large language model, or LLM, which is software trained on huge amounts of text to generate human-like responses), has become the most valuable AI startup in Silicon Valley after raising $65 billion in funding, pushing its valuation to $965 billion and surpassing competitor OpenAI. The company's valuation jump is driven by strong revenue from Claude Code, an AI coding assistant, which reached a $47 billion annual run rate. Anthropic is now preparing for an initial public offering (IPO, when a private company sells shares to the public to raise money), alongside other major AI companies.

CNBC Technology
10

Microsoft 365 Copilot gets a speed boost and cleaner design

industry
May 28, 2026

Microsoft is releasing an updated version of Microsoft 365 Copilot (an AI assistant integrated into Microsoft's productivity tools) with a faster loading time and redesigned interface. The new version uses progressive disclosure (showing only relevant tools based on what you ask for, rather than all options at once) and includes an improved prompt box that lets you format text directly.

The Verge (AI)
Prev1...201202203204205...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026