aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
7,866
[LAST_24H]
2
[LAST_7D]
231
Daily BriefingSunday, September 27, 2026
>

Comprehensive Survey Maps AI Auditing Landscape: A new academic survey consolidates existing frameworks, principles, and methodologies used to audit AI systems for safety, fairness, and reliability, providing practitioners with a structured overview of current evaluation approaches.

Latest Intel

page 44/787
VIEW ALL
01

Why a decade of doomsday warnings failed to slow the AI race

safetypolicy
Critical This Week5 issues
critical

CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm

CVE-2026-84462NVD/CVE DatabaseSep 25, 2026
Sep 25, 2026
Sep 15, 2026

Despite over a decade of warnings from prominent scientists and tech leaders, including Stephen Hawking in 2014 and recent resignations from AI companies like Anthropic, about risks that advanced AI could pose to humanity, these concerns have not slowed down the development and public release of AI systems like ChatGPT. The article suggests that despite widespread alarm about potential existential threats from superintelligent AI (AI systems smarter than humans across most domains), the AI industry continues to pursue rapid development.

The Guardian Technology
02

Trump facing AI backlash in Congress as push for guardrails intensifies

policyindustry
Sep 15, 2026

Members of Congress from both parties are pushing for guardrails (safety rules and oversight) on AI companies, with surveys showing most Americans support a new federal agency to monitor AI and require safety tests for critical decisions. President Trump dismissed these concerns as a hoax, but lawmakers like Democrat Don Beyer argue the government must regulate AI rather than letting companies regulate themselves, comparing the need to existing oversight in industries like medicine and automobiles.

The Guardian Technology
03

CVE-2026-90878: A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/comp

security
Sep 15, 2026

A vulnerability was found in vLLM (a library for running large language models) version 0.27.1 and earlier, where attackers can manipulate the chat_template parameter to cause excessive resource consumption through Jinja template rendering (a system for dynamically generating text). The vulnerability can be exploited remotely, and a fix has been proposed but not yet officially accepted.

NVD/CVE Database
04

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

security
Sep 15, 2026

A financially motivated bug bounty hunter created PhantomRaven, a JavaScript-based information stealer (malware that collects sensitive data) distributed through npm, a popular platform where developers share code packages. The threat actor likely used an LLM to write the malware and deployed it via dependency-confusion attacks (tricking systems into downloading malicious packages instead of legitimate ones), though CrowdStrike's analysis suggests they use the stolen information only to identify bug bounty opportunities rather than selling it.

CrowdStrike Blog
05

Samsung backs Nvidia AI chip rival in $230 million funding round as GPU alternatives boom

industry
Sep 14, 2026

Samsung invested $231 million in Euclyd, a Dutch startup designing AI chips with a different architecture than Nvidia's GPUs (graphics processing units, specialized chips for processing data). Euclyd is developing chips specifically for inference (running already-trained AI models) and claims its systems will reduce energy use and costs for AI data centers, targeting commercial deployment starting in 2028.

CNBC Technology
06

Is Big Tech’s AI slowdown a safety pact or a cartel?

policy
Sep 14, 2026

Major AI company leaders including those from OpenAI, Anthropic, Google DeepMind, and SpaceX agreed to slow down AI development, citing safety reasons and proposing third-party auditors (independent evaluators who check whether systems are safe) and global regulations. Critics argue the agreement is actually an anticompetitive cartel (illegal cooperation between companies to limit competition) designed to block smaller competitors and the open-source community rather than improve safety.

The Verge (AI)
07

Broadcom CEO addresses Anthropic's slowdown push, says AI revenue targets haven't changed

industry
Sep 14, 2026

Broadcom's CEO dismissed concerns that Anthropic's proposal to slow down frontier AI model development (the creation of increasingly powerful AI systems) would hurt the chipmaker's business, stating the company maintains its revenue forecasts for AI semiconductors through 2028. The slowdown proposal from Anthropic's CEO sparked a stock market sell-off among chip companies, but Broadcom's leader expressed confidence that demand for compute infrastructure (the hardware needed to run AI systems) and AI inference (using trained models to make predictions or generate outputs in real-world applications) will remain strong.

CNBC Technology
08

CrowdStrike CEO on Anthropic’s AI safety warning: ‘The genie’s out of the bottle’

safetypolicy
Sep 14, 2026

CrowdStrike CEO George Kurtz argues that slowing AI development won't reduce security risks because dangerous models are already widely available, including both frontier models (the most advanced AI systems) and open-weight models (publicly shared AI systems that anyone can download). He says the real solution is stronger AI-powered cybersecurity tools that can monitor and control AI agents (autonomous programs that make decisions independently) once they are deployed, rather than trying to prevent their development.

Fix: According to Kurtz, companies should implement runtime security monitoring of AI agents. This involves using AI defenses to 'look at what these programs do,' 'put our own guardrails around them at runtime,' 'instrument them to see what they're doing, and prevent them from doing bad things.' He also mentions that AI developers and cybersecurity firms should 'work together to protect models both during development and after deployment' and that 'greater safety in the lab and greater safety in production in runtime is ultimately the best course of action.' The text references Anthropic's Project Glasswing as an example of this approach used to safeguard their Mythos model.

CNBC Technology
09

CVE-2026-12944: IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0)

security
Sep 14, 2026

IBM Langflow OSS versions 1.0.0 through 1.10.0 have a critical vulnerability where attackers can run arbitrary Python code (code that does whatever the attacker wants) with root privileges (the highest access level) by uploading components that import socket or urllib libraries. This allows attackers to steal AWS credentials, steal files from the server, or attack other services like PostgreSQL and Redis running on the same network, while a faulty security check incorrectly marks these malicious components as safe.

NVD/CVE Database
10

Trump phones Nvidia’s Huang at All-In Summit, calls data center opposition a ‘hoax’

policy
Sep 14, 2026

President Trump called Nvidia CEO Jensen Huang at a tech conference to express support for AI data center development, calling concerns about data centers and AI a 'hoax' and praising them as 'the oil of the next 20, 25 years.' This followed Trump's criticism of Anthropic CEO Dario Amodei's argument that AI companies should intentionally slow down development to address safety concerns. The phone call highlights Trump's opposition to AI regulation and his alignment with major tech companies pushing for rapid AI advancement.

CNBC Technology
Prev1...4243444546...787Next
critical

GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

CVE-2026-61742GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

CVE-2026-61732GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security BulletinsSep 24, 2026
Sep 24, 2026
critical

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker NewsSep 22, 2026
Sep 22, 2026