aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,381
[LAST_24H]
14
[LAST_7D]
162
Daily BriefingThursday, August 13, 2026
>

Microsoft Warns AI-Driven Exploit Generation Undermines Traditional Defenses: Microsoft reports that AI tools now generate working exploits for vulnerabilities in 21 minutes for under $4, forcing a nine-fold increase in their vulnerability processing and rendering reactive patching and randomization techniques like ASLR (address space layout randomization, which makes system memory locations unpredictable) inadequate. The company argues organizations must pivot from reactive detection to building inherently resilient systems.

>

Amazon Deploys Twitch Content for Generative AI Training: Amazon is leveraging video streams from Twitch to train generative AI systems (models that create new text, images, or other content), drawing user backlash over the practice.

Latest Intel

page 41/639
VIEW ALL
01

CVE-2026-13435: IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl

security
Jul 30, 2026

IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 has a vulnerability in its PythonREPL sandbox implementation where it doesn't properly validate user input, potentially allowing code injection (inserting malicious code into a program). This could allow attackers to execute arbitrary code through the affected sandbox component.

Critical This Week5 issues
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026
NVD/CVE Database
02

CVE-2026-12942: IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c

security
Jul 30, 2026

IBM Langflow OSS (an open-source AI framework) versions 1.0.0 through 1.10.1 has a path traversal vulnerability (a flaw that lets attackers access files outside their allowed directory) where an attacker can send specially crafted URLs with "dot dot" sequences (/../) to view arbitrary files on the system.

NVD/CVE Database
03

CVE-2026-10700: IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th

security
Jul 30, 2026

IBM Langflow OSS versions 1.0.0 through 1.8.4 have broken access control vulnerabilities in its file handling API (a set of tools that lets software request files). One endpoint allows anyone to download image files without logging in, while another endpoint lets logged-in users access files belonging to other users by guessing file identifiers, potentially exposing sensitive data across multiple users.

NVD/CVE Database
04

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI

securityindustry
Jul 30, 2026

Google announced it fixed 1,072 security bugs in Chrome during June 2024 using AI tools, which is more than the 1,036 bugs patched over the previous two years combined. AI systems like LLMs (large language models, which are neural networks trained on massive amounts of text) are dramatically accelerating vulnerability discovery (finding weaknesses in software) at an industrial scale, forcing both defenders and attackers to use AI to stay ahead of each other. Other companies like Microsoft are also seeing record numbers of bug fixes thanks to AI-assisted detection, though Apple has not shown the same exponential increase.

TechCrunch (Security)
05

OpenAI cuts prices for two of its GPT-5.6 AI models as companies grow sensitive to costs

industry
Jul 30, 2026

OpenAI announced price cuts for two of its GPT-5.6 AI models (Terra and Luna) in response to companies becoming more cost-conscious about AI spending, as enterprises worry about return on investment and face competition from cheaper alternatives like Chinese open-weight models (models available for download and modification on users' own infrastructure) and offerings from Google and Microsoft. The price reductions include a 20% cut for Terra and an 80% cut for Luna, while the company maintains its strategy of improving AI capability and efficiency to accomplish more work at lower costs.

CNBC Technology
06

Google DeepMind’s new AI model can control a robot’s entire body

industry
Jul 30, 2026

Google DeepMind has released Gemini Robotics 2, an AI model that can control a humanoid robot's entire body, including its legs and arms, whereas the previous version only controlled the upper body. This advancement allows robots like Apptronik's Apollo 2 to perform complex tasks such as walking, bending down to pick up objects, and retrieving specific items from shelves.

The Verge (AI)
07

CVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug

security
Jul 30, 2026

IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 has a security flaw where authenticated users (those with login credentials) can view and change other users' build jobs because certain endpoints lack proper access control checks. This happens through improper authorization on log retrieval and unauthenticated build endpoints (entry points that don't require login verification).

NVD/CVE Database
08

CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable

security
Jul 30, 2026

IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 have a security flaw that allows attackers to run arbitrary code without authentication by injecting malicious environment variables (settings that control how programs behave) through the MCP (Model Context Protocol) launcher. The vulnerability exists because the security blocklist protecting against dangerous environment variables is incomplete, missing SHELLOPTS, BASHOPTS, and PS4.

NVD/CVE Database
09

Rethinking Scanning for the AI Era: Wiz’s Agentic Code Security System

securityresearch
Jul 30, 2026

AI models are becoming highly effective at finding complex security vulnerabilities in code, but enterprises cannot simply run expensive, deep scans once and expect continuous protection as code changes constantly. Instead, organizations need a layered system that combines broad, continuous AI scanning across the entire codebase with targeted deep scans reserved for high-risk applications, using multiple specialized AI models and scanning engines rather than relying on a single tool.

Wiz Research Blog
10

Okta buys AI security startup Permiso; source says for about $200M

industrysecurity
Jul 30, 2026

Okta, an identity management company, is acquiring Permiso Security, an AI security startup, for approximately $200 million to strengthen its ability to protect AI agents and machine identities (non-human software entities that need security access) in cloud environments. Permiso develops software that detects suspicious activity and malicious behavior in cloud infrastructure, including a tool called SandyClaw that tests AI agents in a sandboxed environment (an isolated testing area) before they are deployed. This acquisition reflects growing demand from enterprises to secure AI systems as they become more integrated into business operations.

TechCrunch (Security)
Prev1...3940414243...639Next
critical

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

CVE-2026-73032NVD/CVE DatabaseAug 11, 2026
Aug 11, 2026
critical

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898CISA Known Exploited VulnerabilitiesAug 10, 2026
Aug 10, 2026
critical

CVE-2026-72718: goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system

CVE-2026-72718NVD/CVE DatabaseAug 10, 2026
Aug 10, 2026
critical

CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

CVE-2026-14526NVD/CVE DatabaseAug 8, 2026
Aug 8, 2026