aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
7,866
[LAST_24H]
3
[LAST_7D]
231
Daily BriefingSunday, September 27, 2026
>

Comprehensive Survey Maps AI Auditing Landscape: A new academic survey consolidates existing frameworks, principles, and methodologies used to audit AI systems for safety, fairness, and reliability, providing practitioners with a structured overview of current evaluation approaches.

Latest Intel

page 36/787
VIEW ALL
01

Spain's data agency gets first report of AI-powered data breach

securitysafety
Critical This Week5 issues
critical

CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm

CVE-2026-84462NVD/CVE DatabaseSep 25, 2026
Sep 25, 2026
Sep 16, 2026

Spain's data protection agency received the first reported case of a data breach carried out by an AI agent (a system that can autonomously perform tasks) powered by a large language model. The AI agent autonomously searched for security flaws, logged into systems, found vulnerabilities in applications, modified personal data, and accessed financial documents. The agency emphasizes that while AI doesn't create entirely new threats, it dramatically increases the speed, scale, and adaptability of cyberattacks, requiring organizations to rethink their security defenses and response procedures.

BleepingComputer
02

CVE-2026-59974: Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language

security
Sep 16, 2026

Stanza is a Python library from Stanford for processing natural language (breaking text into words, sentences, identifying named entities, and analyzing grammar structure). Before version 1.14.0, it had a security flaw where it extracted downloaded files without checking if they tried to escape their intended folder, allowing a malicious file to overwrite important system files and potentially run harmful code.

Fix: Update to version 1.14.0 or later, which fixes this vulnerability.

NVD/CVE Database
03

CVE-2026-57173: vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v

security
Sep 16, 2026

vLLM (a system for running large language models) had a security flaw in versions before 0.24.0 where audio files sent to the chat endpoint could bypass safety limits designed to prevent memory overload. An attacker could submit a small compressed audio file that expands into massive data, crashing the system, without needing to log in first.

Fix: This issue is fixed in version 0.24.0.

NVD/CVE Database
04

Google will now let any AI agent run your smart home

security
Sep 16, 2026

Google is opening Google Home to third-party AI agents (AI programs that can make decisions and take actions) through a new integration called Home MCP (Model Context Protocol, a standardized way for AI systems to communicate). This lets AI tools like Claude and Open Claw access and control your connected smart home devices and analyze your home's data on your behalf.

The Verge (AI)
05

Our framework for reporting model misalignment

safetypolicy
Sep 16, 2026

OpenAI is introducing a new framework for systematically tracking, investigating, and publicly disclosing instances of model misalignment (cases where AI behavior doesn't match intended goals or safeguards fail). Previously, the company reported these issues inconsistently, but this framework aims to publish findings more quickly and transparently so researchers, policymakers, and the public can examine evidence and help improve AI safety across the industry.

OpenAI Blog
06

BragJack Attack Can Turn a Browser's Agentic AI Against It

security
Sep 16, 2026

A new attack called BragJack can hijack agentic AI (AI systems that can take actions and make decisions on their own) built into web browsers to steal sensitive information, run harmful commands, and extract data without the user's permission. This attack exploits the AI assistants that browsers now include to help users, turning them into tools for attackers instead.

Dark Reading
07

First Agentic AI Data Breach Reported to Spanish Regulator

securitysafety
Sep 16, 2026

The Spanish Data Protection Agency reported the first known data breach where an AI agent (a system that can autonomously set goals, plan tasks, use tools, and modify actions based on results) was used to execute an attack, successfully logging in, finding vulnerabilities, and accessing personal data. This represents a qualitative change in cyber threats because the agent chained together multiple attack phases autonomously and at speed, moving AI-assisted attacks from theory into reality.

Fix: The AEPD identifies four required modifications to risk management: (1) AI assistance and adversarial agents must become part of risk analysis, (2) incident response times must be improved, (3) digital IDs and credentials must be better protected, and (4) these modifications cannot rely solely on manual intervention. The agency states: 'Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough,' meaning defense must also use AI-assisted tools with humans overseeing the process.

SecurityWeek
08

Claude comes for Gemini with its own take on Docs and Slides

industry
Sep 16, 2026

Claude, an AI assistant made by Anthropic, is adding two new tools called Docs and Slides that let users create documents and presentations directly through AI conversations, which can then be exported and shared. Anthropic is also simplifying Claude's interface by combining different chat modes into a single unified experience where all productivity features, including Artifacts (saved code or content blocks) and design capabilities, are available from any conversation.

The Verge (AI)
09

Anthropic, OpenAI proposed new 'neutral' AI watchdogs. Why you should worry about the idea

policysafety
Sep 16, 2026

Anthropic CEO Dario Amodei has proposed embedding third-party safety evaluators (external researchers who monitor AI systems from inside the company) inside major AI companies like Anthropic and OpenAI to oversee the development of large language models (AI systems trained on vast amounts of text). However, experts argue this proposal lacks real enforcement power compared to banking regulation, since these evaluators could only investigate and report findings but could not actually stop or prevent a model from being trained or released, unlike bank regulators who can force changes or shut down operations.

CNBC Technology
10

Big Tech’s AI safety rift signals disruption and disparity for enterprises

policysecurity
Sep 16, 2026

Major AI companies disagree on how to secure powerful AI models, creating unpredictable access and deployment conditions for businesses rather than industry-wide slowdowns. Companies are applying different safety approaches, release schedules, and usage restrictions, meaning enterprises may access the same AI capabilities at different times and under different rules. An emerging "AI assurance" layer (third-party evaluations of models for safety and compliance) is developing, but enterprises should not assume a single evaluation means an AI system is fully safe.

CSO Online
Prev1...3435363738...787Next
critical

GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

CVE-2026-61742GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

CVE-2026-61732GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security BulletinsSep 24, 2026
Sep 24, 2026
critical

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker NewsSep 22, 2026
Sep 22, 2026