aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
1
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 210/643
VIEW ALL
01

Rethinking organizational design in the age of agentic AI

industry
May 26, 2026

Many organizations want to adopt agentic AI (AI systems that can independently execute complete workflows with minimal human input), but 76% say their current operations cannot support this change. The problem is that most companies are simply adding AI agents onto existing human-centered business models rather than fundamentally redesigning their operations, technology, workflows, and decision-making systems to work with AI as an integrated part of the organization.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
MIT Technology Review
02

CVE-2026-9540: A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component

security
May 26, 2026

A vulnerability (CVE-2026-9540) was found in vllm version 0.19.0 that affects the OpenAI-compatible Serving Path component and can be exploited remotely to cause a denial of service (making a service unavailable by overwhelming it). The vulnerability has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 5.5 (medium severity), and a public exploit is already available.

Fix: A pull request to fix this issue awaits acceptance (mentioned in the source as pending at https://github.com/vllm-project/vllm/pull/37594).

NVD/CVE Database
03

GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos

security
May 26, 2026

The Megalodon campaign used compromised credentials to inject malicious commits into over 5,500 GitHub repositories, modifying GitHub Actions workflows (automation tools that run code tasks) to steal sensitive secrets like cloud credentials and SSH keys (authentication files). The attack hid malicious code in base64-encoded bash payloads (encoded script commands) and used fake author names like "build-bot" to disguise itself as routine maintenance, with researchers detecting unexpected workflow runs as a warning sign.

Fix: SafeDep recommended checking GitHub Actions tabs for unexpected workflow_dispatch runs (manual workflow triggers), and if using OIDC federation (a cloud authentication method) for deployments, review cloud audit logs for token requests from unknown workflow runs. The researchers also shared a list of indicators of compromise (IOCs), including the attacker's command-and-control domain (216.126.225.129:8443), campaign signatures, forged author names and emails, commit messages, and names of compromised repositories to aid in detection and cleanup.

CSO Online
04

How Varonis Atlas integrates Claude Compliance API for AI governance

securityindustry
May 26, 2026

Varonis Atlas has integrated with the Claude Compliance API to help organizations monitor and secure their use of Claude Enterprise and Claude Platform, which are AI tools used for tasks like document analysis and building custom applications. The integration allows security teams to track AI usage, detect misuse and sensitive data exposure, investigate complete chat sessions, and test for vulnerabilities like prompt injection (tricking an AI by hiding instructions in its input) and jailbreaks. Varonis Atlas connects AI activity to underlying data permissions and access controls to help organizations understand what data their AI systems can reach and whether that access is safe.

Fix: The source does not explicitly describe a specific fix or mitigation for a particular vulnerability. Instead, it describes Varonis Atlas's features for monitoring and securing AI systems: continuous monitoring of conversation content, real-time detection of sensitive data exposure and jailbreak attempts, session-level investigations, runtime guardrails, and proactive pen testing (stress-testing assistants and agents for vulnerabilities). Organizations can access these capabilities through the Varonis Atlas platform, including its AI inventory, posture management, security testing, runtime guardrails, and compliance reporting functionality.

BleepingComputer
05

Sundar Pichai on AI, the future of search, and what’s happening to the web

industry
May 26, 2026

Google CEO Sundar Pichai discusses major AI changes coming to Google Search and YouTube, including new Gemini models (advanced AI systems for generating text and understanding information) and AI agents that can perform tasks rather than just deliver search results. These changes will likely reduce traffic to websites from Google Search, a phenomenon the interviewer calls 'Google Zero,' forcing publishers and content creators to adapt their business strategies.

The Verge (AI)
06

Check Point Frontier AI Models Readiness Program – Security Update

security
May 26, 2026

Check Point launched a proactive Frontier AI Models Readiness Program to protect their products against threats from increasingly capable AI systems that could help attackers find and exploit vulnerabilities. The program involved scanning their code with AI tools, reviewing security, strengthening weak components, and speeding up their ability to create and release security patches.

Check Point Research
07

Musk and Altman’s AI rivalry reaches boiling point as IPO race heats up

industry
May 26, 2026

This article discusses the competitive race between Elon Musk's SpaceX and Sam Altman's OpenAI as both companies move toward initial public offerings (IPOs, which is when a private company sells shares to the public for the first time). The piece highlights how a small group of tech leaders is gaining increasing influence over the future direction of artificial intelligence development.

The Guardian Technology
08

Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations

securitypolicy
May 26, 2026

Anthropic announced that Claude now integrates with 28 enterprise security and compliance platforms, allowing organizations to monitor and govern Claude's use alongside other workplace software. The integration works through the Claude Compliance API, which gives security teams access to conversation content and activity logs from Claude Enterprise, enabling them to apply their existing monitoring policies to Claude.

SecurityWeek
09

TrapDoor malware campaign puts developer workstations in CISO spotlight

security
May 26, 2026

The TrapDoor malware campaign compromised over 34 malicious packages across npm, PyPI, and Crates.io (popular code repositories where developers download libraries) to steal developer secrets like AWS credentials, GitHub tokens, and SSH keys (authentication credentials for secure systems). The campaign is particularly dangerous because it targets entire developer workflows, including AI coding assistants, and uses normal software development processes as cover, making it harder to detect and potentially giving attackers access to CI/CD pipelines (automated systems that build and deploy software) and cloud infrastructure.

CSO Online
10

Uber president says AI spending is getting ‘harder to justify’

industry
May 26, 2026

Uber has spent its entire annual AI budget in just four months of 2026 and is questioning whether the spending is worthwhile, as the company struggles to see a clear connection between rising token consumption (the computational cost of running AI models like Claude Code) and actual improvements in features delivered to customers. Uber's president says it's difficult to prove that increased AI spending is directly producing more useful features for consumers.

The Verge (AI)
Prev1...208209210211212...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026