aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
7,866
[LAST_24H]
2
[LAST_7D]
231
Daily BriefingSunday, September 27, 2026
>

Comprehensive Survey Maps AI Auditing Landscape: A new academic survey consolidates existing frameworks, principles, and methodologies used to audit AI systems for safety, fairness, and reliability, providing practitioners with a structured overview of current evaluation approaches.

Latest Intel

page 40/787
VIEW ALL
01

Salesforce CEO Marc Benioff joins growing chorus of tech leaders warning about AI risks

policysafety
Critical This Week5 issues
critical

CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm

CVE-2026-84462NVD/CVE DatabaseSep 25, 2026
Sep 25, 2026
Sep 15, 2026

Salesforce CEO Marc Benioff joined other tech leaders in warning that AI companies must act responsibly as they develop increasingly powerful models, comparing the situation to social media's harmful impact on society. Benioff argued that companies building AI have a responsibility to consider its broader consequences and be ethical, rather than endorsing calls to slow AI development entirely. His comments come as Anthropic CEO Dario Amodei recently called for frontier AI labs (companies developing cutting-edge AI systems) to reduce their development pace to allow safety measures time to catch up.

CNBC Technology
02

Two camps have emerged in the debate over AI safety and regulation

policy
Sep 15, 2026

Two opposing camps have formed in the debate over AI safety and regulation. One camp, led by President Trump, Nvidia CEO Jensen Huang, and others, opposes AI regulation and calls for faster development to compete with China, while the other camp, including AI lab leaders like Dario Amodei and Sam Altman along with researchers, warns that AI poses existential risks (dangers to human survival) and calls for slowing AI model development. The disagreement centers on whether AI safety concerns justify regulation or whether such regulations would hamper innovation and America's competitiveness.

CNBC Technology
03

Nvidia's Huang rips Anthropic's proposal for AI safety antitrust waiver: 'Completely unnecessary'

policysafety
Sep 15, 2026

Nvidia CEO Jensen Huang criticized Anthropic's proposal for antitrust exemptions (legal exceptions that would allow competing companies to coordinate without violating competition laws) to let AI companies deliberately slow model development for safety testing. Huang argued that AI safety should be solved through engineering and testing rather than new laws, saying companies already have sufficient regulations governing product reliability and can independently ensure their products are safe before release.

CNBC Technology
04

Nvidia boss says AI 'doesn't need new laws' as safety concerns grow

policysafety
Sep 15, 2026

Nvidia's CEO Jensen Huang argues that AI companies should self-regulate rather than face new laws, saying safety is an engineering problem that company leaders can manage by choosing not to release products they don't trust. This stance contrasts with other AI executives like Anthropic's Dario Amodei, who have called for slower AI development and government regulation due to concerns that advanced AI could pose serious risks to humanity.

Fix: According to the source, OpenAI and Anthropic leaders have stated they are working toward industry-wide safety agreements. Specifically, Anthropic is in 'a dialogue with the rest of the industry' about committing to better safety standards and checks on AI tools and development. OpenAI is also 'working with other AI labs to advance frontier AI standards, building a voluntary effort now, with or without government support,' including collaboration with Anthropic and Google DeepMind.

BBC Technology
05

Labor accused of throwing creatives ‘under the bus’ with proposal to ease copyright protections for AI giants

policy
Sep 15, 2026

The Australian government is considering easing copyright protections to allow AI companies like OpenAI to access and use Australian creative works by default for training their models (the process where an AI learns patterns from data). OpenAI met with government officials to argue that current Australian copyright laws are preventing them from developing AI systems locally.

The Guardian Technology
06

Anthropic’s CEO calls for AI slowdown as Nvidia’s urges acceleration

safetypolicy
Sep 15, 2026

At a San Francisco conference, leaders from major AI companies expressed differing views on AI development: Anthropic's CEO called for slowing down AI progress and reviewing safety practices (comparing it to how car companies respond to safety incidents), while Nvidia's CEO argued against slowing down and OpenAI's CEO emphasized the need for stronger security measures as AI systems become more powerful.

The Guardian Technology
07

GHSA-5648-rgj9-v224: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

security
Sep 15, 2026

The @zereight/mcp-gitlab package, which connects GitLab to an AI agent, has five security flaws that bypass its safety controls (read-only mode, project allow-lists, and authentication). These flaws let attackers execute write operations through GraphQL, access the tool without credentials, perform DNS rebinding attacks, exhaust sessions with fake tokens, and inject malicious instructions through CI job logs.

GitHub Advisory Database
08

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

policyprivacy
Sep 15, 2026

Microsoft has agreed to adopt privacy and safety rules for its AI tools used in schools, negotiated with the American Federation of Teachers, including a commitment not to use student data to train AI systems and a ban on features designed to create emotional dependency. However, experts warn these protections will only be effective if other major tech companies like Google, OpenAI, and Anthropic adopt similar standards, and some question whether AI belongs in classrooms at all.

Fix: Microsoft's agreement includes specific commitments: the company will not use student or educator data to train AI systems (with narrow exceptions for student protection), will not sell or use collected data for advertising or product development, will prohibit AI features designed to foster emotional attachment or dependency, and will provide third-party audits and plain-language transparency disclosures to families. These standards apply to all schools with Microsoft contracts starting November 1. Additionally, New York City and Los Angeles school districts have implemented yearlong AI moratoriums and plan extensive audits of their education technology contracts focusing on data privacy, transparency, and accountability.

SecurityWeek
09

CVE-2026-83416: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

security
Sep 15, 2026

Oracle Coherence, a data management product in Oracle Fusion Middleware, has a vulnerability (CVE-2026-83416) that allows attackers with low-level network access to partially disable the service through a denial of service attack (DOS, where a system is made unavailable to legitimate users). The flaw affects several versions of the software and has a moderate severity rating of 4.3 out of 10.

NVD/CVE Database
10

CVE-2026-83410: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

security
Sep 15, 2026

A serious vulnerability exists in Oracle Coherence (a data management product used in Oracle Fusion Middleware) that allows an attacker with low-level network access to take complete control of the system. The flaw affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, and has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 8.8, indicating high risk to confidentiality, integrity, and availability of data.

NVD/CVE Database
Prev1...3839404142...787Next
critical

GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

CVE-2026-61742GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

CVE-2026-61732GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security BulletinsSep 24, 2026
Sep 24, 2026
critical

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker NewsSep 22, 2026
Sep 22, 2026