aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
1
[LAST_7D]
157
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 212/643
VIEW ALL
01

EA-APO: A Universal Proactive Defense Against Facial Manipulation

securityresearch
Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
May 25, 2026

Facial manipulation techniques like face-swapping and face attribute editing (changing features in images) threaten privacy and identity security, but existing defense methods work poorly against both types of attacks in a unified way. Researchers developed EA-APO (Epoch-Adaptive Adversarial Perturbation Optimization), a defense framework that adds specially designed invisible noise patterns to face images to disrupt both face-swapping and attribute-editing AI models, even ones the defense hasn't seen before. The method was tested across multiple commercial facial manipulation tools and remained effective even after common image processing and social media compression.

IEEE Xplore (Security & AI Journals)
02

AI security needs a shift from models to systems, researchers argue

securityresearch
May 25, 2026

Researchers argue that enterprises cannot secure AI agents by making the underlying models more robust. Instead, they must enforce security controls at the system level, treating AI models as fundamentally untrusted components, similar to how operating systems treat processes. The paper identifies five security principles from traditional systems security (least privilege, tamper resistance, complete mediation, secure information flow, and accounting for human error) that should be applied to AI agents, and notes that all eleven real-world attacks analyzed violated the secure information flow principle.

CSO Online
03

<em>Infer-Shield</em>: Defending against membership inference attacks in heterogeneous federated learning via adaptive distillation

securityresearch
May 25, 2026

This research paper describes a defense technique called Infer-Shield that protects AI models trained across multiple organizations (federated learning, where different parties train a shared model without sharing raw data) from membership inference attacks (attempts to determine if specific individuals' data was used in training). The paper proposes using adaptive distillation (a technique where a smaller model learns from a larger one to reduce information leakage) as a way to make these distributed AI systems more secure.

Elsevier Security Journals
04

As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free

securityindustry
May 25, 2026

CVE Lite CLI is an open-source tool that scans JavaScript and TypeScript project dependencies for vulnerabilities by analyzing lockfiles (files that track which packages a project uses) locally while developers are coding, rather than waiting for security checks to fail later in the CI pipeline (automated testing system). The tool provides detailed remediation guidance, distinguishing between direct dependencies (packages you explicitly use) and transitive dependencies (packages that your dependencies use), and recommending specific upgrade paths. According to the creator, this local-first approach is increasingly important because AI coding assistants allow developers to add packages quickly, potentially without proper security review.

Fix: CVE Lite CLI scans npm, pnpm, and Yarn lockfiles using OSV vulnerability data and can be configured for JSON, SARIF, or HTML outputs and integrated into CI workflows as a GitHub Action. The tool analyzes lockfiles to identify which vulnerabilities are direct versus transitive, validates upgrade targets, and recommends actionable fix paths while developers are still writing code.

CSO Online
05

The Alert Firehose Finally Meets Its Match

securityindustry
May 25, 2026

Network Detection and Response (NDR, a security tool that monitors network traffic for threats) has traditionally been criticized for generating too many alerts, but newer NDR systems using agentic AI (AI that autonomously performs tasks like data analysis and alert prioritization) are reducing false positives by correlating multiple data points and automatically triaging alerts for analysts. This allows security teams to focus on genuine threats rather than sorting through overwhelming amounts of data.

Fix: The source discusses operational best practices but does not explicitly describe a specific fix or mitigation. It mentions that NDR systems should be properly deployed through baselining (allowing the system to learn normal network behavior), staying tuned (ongoing configuration), and SOC integration, but does not present these as solutions to a problem—rather as necessary deployment steps. N/A -- no mitigation discussed in source.

The Hacker News
06

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

securityresearch
May 25, 2026

Anthropic's Claude Mythos model, an AI system designed to find security vulnerabilities (bugs that attackers could exploit), discovered over 23,000 potential weaknesses across more than 1,000 open source software projects, with 1,726 confirmed vulnerabilities including over 1,000 rated as high or critical severity. So far, 75 of these serious issues have been patched by software vendors, and Anthropic expects this number to grow significantly as vendors continue their 90-day review period. The company has also released Claude Security, a tool to help developers scan their own code for security issues.

Fix: Anthropic has unveiled Claude Security, a codebase scanner designed to help developers find security issues in their applications. Additionally, Anthropic is working to add safeguards to prevent misuse of Mythos and has limited its access through Project Glasswing (a program that gives about 50 organizations controlled access to the model) while developing stronger protections before making it more widely available.

SecurityWeek
07

The AI Era Is Creating a Bug Hunting Arms Race

securityindustry
May 25, 2026

AI models are becoming better at automatically finding software vulnerabilities (weaknesses in code) and creating exploits (tools to attack them), which is flooding bug bounty programs (programs that reward researchers for reporting bugs) with submissions. This surge is changing how companies pay for bug discoveries and forcing faster security responses, potentially shortening the traditional 90-day responsible disclosure window (the agreed-upon time between finding a bug and publicly revealing it) where companies typically release patches (fixes).

Wired (Security)
08

OpenAI, Grupo Folha and Grupo UOL announce strategic content partnership

industry
May 24, 2026

OpenAI has partnered with two major Brazilian news organizations, Folha de S.Paulo and Grupo UOL, to integrate their journalism into ChatGPT. Starting immediately, ChatGPT's 900 million weekly active users can access summaries and articles from these sources with attribution and links back to the original reporting. This partnership is part of OpenAI's broader effort to work with news publishers globally and bring trusted journalism into AI-powered experiences.

OpenAI Blog
09

Scotland’s ‘green datacentres’ policy ignores emissions impact of AI, analysis shows

policysafety
May 24, 2026

Scotland's policy encouraging "green datacentres" (facilities designed to minimize environmental impact) was created in 2022 before AI tools like ChatGPT became widespread, and a Scottish charity warns it may not account for the significant carbon emissions that AI systems actually produce. The policy is meant to attract AI investment to Scotland as part of the country's economic development strategy, but it appears outdated regarding the true environmental costs of running AI.

The Guardian Technology
10

Hackers are learning to exploit chatbot &#8216;personalities&#8217;

securitysafety
May 24, 2026

Early AI chatbots were vulnerable to jailbreaks, which are attacks where users trick the AI into ignoring its safety guidelines by simply asking it to do so, requiring no technical expertise or coding knowledge. Hackers are now becoming more sophisticated in exploiting chatbot personalities to bypass safety measures that were built into these expensive AI systems.

The Verge (AI)
Prev1...210211212213214...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026