aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,428
[LAST_24H]
1
[LAST_7D]
156
Daily BriefingSaturday, August 15, 2026
>

Anthropic Revenue Surges Ahead of Planned IPO: The company behind Claude reported quarterly revenue exceeding $11.5 billion, a 14-fold year-over-year increase, as it prepares to go public and compete directly with OpenAI for enterprise AI adoption.

>

AI Firms Suspected of Covert Data Acquisition Through Book Purchases: Secondhand booksellers across the UK and Ireland report unusual bulk orders believed to be AI companies acquiring physical texts for training data, with Anthropic previously confirmed to have spent millions on such acquisitions.

Latest Intel

page 213/643
VIEW ALL
01

How big tech got its way on Trump’s AI executive order

policy
May 23, 2026

President Trump reversed his plan to require a government safety review of new AI models before their release, deciding instead that the US government would not slow down AI development. The reversal happened hours before the executive order was set to be signed, and Trump cited American competitiveness and competition with China as reasons for prioritizing speed over safety reviews despite expert warnings about security risks.

Critical This Week5 issues
critical

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

CVE-2026-49986NVD/CVE DatabaseAug 14, 2026
Aug 14, 2026
The Guardian Technology
02

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

securityindustry
May 23, 2026

Anthropic's Project Glasswing uses Claude Mythos Preview, an advanced AI model, to automatically find security flaws (vulnerabilities) in widely-used software before attackers can exploit them. Since launching last month, the program has identified over 10,000 high-severity vulnerabilities across critical software, with 97 already patched and 88 security advisories issued. However, Anthropic notes that finding vulnerabilities is much easier than fixing them, presenting a major challenge for cybersecurity.

Fix: Anthropic recommends that software developers and network defenders shorten their patch cycles and deployment timelines. Specific steps mentioned include: hardening networks' default configurations, enforcing multi-factor authentication (requiring two or more ways to verify identity), and keeping comprehensive logs for detection and response. Additionally, Anthropic launched a Cyber Verification Program that allows security professionals to use its models without safety restrictions for legitimate purposes such as vulnerability research, penetration testing, and red teaming (simulated attacks by friendly security experts).

The Hacker News
03

Google’s new anything-to-anything AI model is wild

safety
May 23, 2026

Google's Gemini AI model can generate realistic videos from simple inputs, as demonstrated by an experiment where someone created deepfake (synthetic media made to look real) videos of a stuffed animal. The article highlights how accessible and effective these video generation tools have become, raising questions about the line between harmless creative use and potentially misleading AI-generated content.

The Verge (AI)
04

Adaptive Trust-Aware SOC Human–AI Teaming for resilient operations

researchsafety
May 22, 2026

This research paper examines how Security Operations Centers (SOCs, teams that monitor and respond to security threats) can work effectively with AI systems by using adaptive trust mechanisms. The study focuses on building resilient operations, meaning systems that can continue functioning even when problems occur, through better collaboration between human security experts and AI tools that can process large amounts of data quickly.

Elsevier Security Journals
05

Elon, stop trying to make Grok happen

industry
May 22, 2026

According to a Reuters report, Grok (Elon Musk's AI chatbot) is not performing well and has minimal adoption, appearing in only 3 out of over 400 documented cases of U.S. government AI use, and only for basic tasks like document drafting or social media management. This low usage is a sign of trouble for xAI's flagship product, despite Musk's plans to make it central to a major financial offering.

The Verge (AI)
06

CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

security
May 22, 2026

Kiro CLI, a command-line tool that lets developers use AI to run code and shell commands, has a security flaw (CVE-2026-9255) where it doesn't properly check where input comes from before authorizing tool execution. An attacker on the same computer could trick the tool into running arbitrary commands without the user's permission by sending specially crafted data through stdin (the standard input stream that feeds data into a program).

Fix: Update kiro-cli to version 1.28.0 or later. The affected versions are kiro-cli prior to 1.28.0.

AWS Security Bulletins
07

Microsoft says it’s making AI ‘safe for work’ in your browser

securitypolicy
May 22, 2026

Microsoft is testing agentic AI (AI that can perform multi-step tasks automatically) in its Edge for Business browser to help employees complete routine work like filling forms and gathering information across tabs. A key focus is protecting corporate data through features that keep AI prompts within the company's Microsoft 365 tenant (a private cloud environment), prevent copy-paste operations, block sensitive uploads, and allow companies to audit what users do.

Fix: Microsoft provides several data protection features in Edge for Business: enterprises can block copy and paste functionality, ensure all AI prompts and responses stay within their Microsoft 365 tenant (preventing use for model training), enable audit capabilities for prompts, and use the Purview compliance tool to analyze file uploads and detect sensitive data to block risky actions. These protections are active as soon as users sign into Edge for Business.

CSO Online
08

The literary world isn’t prepared for AI

safety
May 22, 2026

A story selected for a prestigious British literary award appears to have been written by an LLM (large language model, an AI trained on text to generate human-like writing) rather than by a human author, raising concerns about how the literary world will handle AI-generated submissions. The story exhibits characteristic patterns of AI-generated text, such as repetitive sentence structures and predictable phrasing.

The Verge (AI)
09

Spotify says its AI remix tool is for superfans, but I’m not convinced

industry
May 22, 2026

Spotify has partnered with Universal Music Group (UMG) to create a new tool that uses generative AI (AI that creates new content from patterns in training data) to let users make remixes and covers of songs from UMG's music catalog. The article expresses concern that this tool will make it even easier to flood the internet with AI-generated music covers, which already appear widely on platforms like YouTube, TikTok, and Instagram.

The Verge (AI)
10

FairRoP: Robust Client Selection Scheme for Fairness-Aware Federated Learning

researchsecurity
May 22, 2026

Federated learning (a system where multiple computers train an AI model together while keeping their data private) can be unfair to some participants and vulnerable to attacks where bad actors tamper with the process. FairRoP is a new method that uses adaptive client selection (choosing which computers to include based on their trustworthiness) and a bandit algorithm (a technique for balancing exploration and exploitation in decision-making) to improve both fairness and robustness against attacks. The approach combines three components: fairness awareness, attack detection, and q-Balance to handle the different challenges involved.

IEEE Xplore (Security & AI Journals)
Prev1...211212213214215...643Next
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026