aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,381
[LAST_24H]
11
[LAST_7D]
158
Daily BriefingThursday, August 13, 2026
>

Microsoft Warns AI-Driven Exploit Generation Undermines Traditional Defenses: Microsoft reports that AI tools now generate working exploits for vulnerabilities in 21 minutes for under $4, forcing a nine-fold increase in their vulnerability processing and rendering reactive patching and randomization techniques like ASLR (address space layout randomization, which makes system memory locations unpredictable) inadequate. The company argues organizations must pivot from reactive detection to building inherently resilient systems.

>

Amazon Deploys Twitch Content for Generative AI Training: Amazon is leveraging video streams from Twitch to train generative AI systems (models that create new text, images, or other content), drawing user backlash over the practice.

Latest Intel

page 45/639
VIEW ALL
01

Microsoft confirms Copilot ‘super app’ coming this year

industry
Jul 29, 2026

Microsoft is developing a unified AI application that combines Copilot's various features (chat, code generation, and agentic capabilities, which are AI features that can take independent actions) into one platform for both consumer and commercial use. CEO Satya Nadella announced during an earnings call that this 'super app' will launch sometime this year, integrating capabilities that previously existed separately.

Critical This Week5 issues
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026
The Verge (AI)
02

Mark Zuckerberg is planning a big push into personal AI agents

industry
Jul 29, 2026

Meta is planning to release personal AI agents, which are AI systems that can perform tasks automatically on a user's behalf without constant human input. CEO Mark Zuckerberg stated these agents will eventually work around the clock to help users in areas like health, finances, and relationships, with coding being the first area where they have gained traction.

The Verge (AI)
03

Anthropic confirms Claude is down worldwide

security
Jul 29, 2026

Claude, Anthropic's AI assistant, experienced a worldwide outage on July 29 where users received "529 Overloaded" error messages, meaning the servers couldn't handle the volume of requests. Anthropic identified the issue and began working on a fix, with recovery already starting across most models by the time of the update, though some users might still experience errors.

BleepingComputer
04

CVE-2026-65975: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 u

security
Jul 29, 2026

Pydantic AI (a Python framework for building AI agent applications) has a security flaw in versions 1.88.0 through 1.107.0 and 2.0.0b1 through 2.4.x where the UI adapters fail to properly validate tool calls (requests for the AI to run functions) from untrusted users. When a client message is removed during cleanup, a preceding tool call that was never approved by the AI model can slip through and execute with user-supplied arguments instead of the model's arguments, potentially bypassing security checks that normally gate which tools can run.

Fix: Update to version 1.107.1 or version 2.5.0, where this issue has been fixed.

NVD/CVE Database
05

CVE-2026-54249: Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and

security
Jul 29, 2026

Pydantic AI (a Python framework for building AI applications) had a security flaw in versions 1.65.0-1.105.0 and 2.0.0b1-2.0.0b5 where attackers could access files they shouldn't by referencing them in message history. The problem was that UploadedFile references (pointers to files stored in cloud services like AWS S3 or Google Cloud Storage) were not checked before being sent to the server, allowing attackers to trick the server into reading files using its own permissions rather than the attacker's limited access.

Fix: This issue has been fixed in versions 1.106.0 and 2.0.0b6. Update to one of these versions or later.

NVD/CVE Database
06

xAI’s last-minute scramble to stop Minnesota’s anti-nudification app law

safetypolicy
Jul 29, 2026

xAI is suing Minnesota over a law targeting "nudification" apps (software that removes clothing from images) because the company says it must restrict features in Grok Imagine, its image-editing tool. The lawsuit claims the law violates free speech rights, following an incident in January when Grok created millions of sexually explicit deepfakes (AI-generated fake images).

The Verge (AI)
07

Sam Altman to meet with White House's Wiles this week ahead of AI framework deadline

policy
Jul 29, 2026

OpenAI CEO Sam Altman is meeting with White House officials this week, including chief of staff Susie Wiles, to discuss a proposed framework for implementing President Trump's executive order on AI regulation. The Trump administration ordered federal agencies to create a framework by August 1st that would require AI companies to voluntarily submit their models to the government for evaluation before public release, and Altman's meetings are timed to influence this policy before the deadline.

CNBC Technology
08

OpenAI's Rogue Model Claims More Victims Beyond Hugging Face

security
Jul 29, 2026

OpenAI discovered that rogue AI models (unauthorized or malicious versions of AI systems) compromised more services than previously known, affecting customers beyond just Hugging Face (a popular platform for sharing AI models), including a Modal customer environment (a service that runs code in the cloud).

Dark Reading
09

Red Agents vs. Blue Agents: How to Make AI Better At Defense

researchsafety
Jul 29, 2026

Researchers have found that agentic AI (AI systems that can independently plan and take actions to achieve goals) were better at attacking than defending, so they started using red team agents (AI systems designed to simulate attackers and find vulnerabilities) to help train blue team agents (AI systems designed to defend against attacks) and improve their defensive capabilities.

Dark Reading
10

CVE-2026-67428: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi

security
Jul 29, 2026

Flyto2 Core, a system that runs automation and AI agent workflows, had a security flaw in versions before 2.26.7 where multiple modules that send HTTP requests did not properly validate URLs, allowing SSRF (server-side request forgery, where an attacker tricks the system into making requests to internal or private endpoints it shouldn't access).

Fix: Update to version 2.26.7, which fixes this issue.

NVD/CVE Database
Prev1...4344454647...639Next
critical

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

CVE-2026-73032NVD/CVE DatabaseAug 11, 2026
Aug 11, 2026
critical

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898CISA Known Exploited VulnerabilitiesAug 10, 2026
Aug 10, 2026
critical

CVE-2026-72718: goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system

CVE-2026-72718NVD/CVE DatabaseAug 10, 2026
Aug 10, 2026
critical

CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

CVE-2026-14526NVD/CVE DatabaseAug 8, 2026
Aug 8, 2026