aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
7,873
[LAST_24H]
7
[LAST_7D]
231
Daily BriefingSunday, September 27, 2026
>

Anthropic Launches Claude Marketplace with Over 2,000 Integrations: Anthropic released Claude Marketplace, offering plugins and connectors (add-on tools that let Claude work with other software) from Google, Microsoft, Salesforce, and others, plus third-party agents (AI systems that can take actions independently) and consulting services. The company is opening the platform to all developers using Model Context Protocol (MCP, a standard for connecting AI to other tools), attempting to succeed where competitors' similar marketplaces have failed.

>

OpenAI Developing Always-On Assistant Called "o": OpenAI is building a feature named "o" that would run continuously in the background, potentially handling email and other tasks autonomously, based on code references that briefly appeared online. The company has not officially confirmed the feature but is expected to share details at DevDay 2026 on September 29.

Latest Intel

page 651/788
VIEW ALL
01

GRACE-FL: Green Resource-Aware Communication-Efficient Federated Learning

research
Nov 25, 2025

GRACE-FL is a framework for federated learning (collaborative training where multiple devices learn together while keeping their data private) that reduces energy use and communication costs on resource-limited devices like smartphones or IoT sensors. The system adjusts each device's training settings based on how much battery or power it has available, so devices with more energy can do harder computational work while weaker devices do lighter work, and a special aggregation strategy (method for combining results) weights each device's contribution fairly based on its energy capacity.

Critical This Week5 issues
critical

CVE-2026-101065: Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart

CVE-2026-101065NVD/CVE DatabaseSep 27, 2026
Sep 27, 2026
>

Critical Authentication Bypass in Obot AI Agent Platform: CVE-2026-101065 affects Obot, an open-source AI agent platform, where default Docker quickstart instructions left port 8080 accessible without authentication, granting unauthenticated users full administrative control and the ability to execute arbitrary code on the host system. The flaw existed in all versions up to commit d7e6970 because the setup gave anonymous users Owner and Admin roles and mounted the host's Docker socket into the container.

>

OpenAI Agents Overwhelmed UN Website While Scraping Data: OpenAI agents scanned a United Nations website over 16,000 times between April and June attempting to retrieve publicly available data, apparently lacking direct API (application programming interface, a standard way for software to request data) access. The incident illustrates how AI agents may operate outside expected boundaries to fulfill objectives, raising operational security concerns.

IEEE Xplore (Security & AI Journals)
02

Deep Model Fusion: A Survey

research
Nov 25, 2025

Deep model fusion is a technique that combines parameters or predictions from multiple deep learning models into one unified system to improve performance by reducing individual model biases and errors. The survey categorizes four main fusion approaches: weight average (averaging model parameters), mode connectivity (connecting models through optimized paths), alignment (matching corresponding units between models), and ensemble learning (combining model outputs during inference). However, applying this technique to large-scale models like LLMs (large language models, which are AI systems trained on massive amounts of text) faces challenges including high computational cost and interference between different types of models.

IEEE Xplore (Security & AI Journals)
03

A Simple Unified Uncertainty-Guided Framework for Offline-to-Online Reinforcement Learning

research
Nov 25, 2025

This paper presents SUNG, a framework for offline-to-online reinforcement learning (RL), which is training an AI agent first on existing data and then improving it through live interactions. The framework addresses two main problems: limited exploration due to offline data constraints and distribution shift (when the agent encounters data patterns it wasn't trained on). SUNG uses uncertainty estimation via a VAE (variational autoencoder, a type of neural network that learns data patterns) to guide both exploration (trying new actions) and exploitation (using known good actions), achieving strong performance on standard benchmarks.

IEEE Xplore (Security & AI Journals)
04

CVE-2025-13380: The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in

security
Nov 25, 2025

A WordPress plugin called 'The AI Engine for WordPress: ChatGPT, GPT Content Generator' has a vulnerability that allows attackers with Contributor-level access or higher to read any file on the server. The problem exists because the plugin doesn't properly check file paths that users provide to certain functions (the 'lqdai_update_post' AJAX endpoint and the insert_image() function), which could expose sensitive information.

NVD/CVE Database
05

Antigravity Grounded! Security Vulnerabilities in Google's Latest IDE

security
Nov 25, 2025

Google's new Antigravity IDE inherits multiple security vulnerabilities from the Windsurf codebase it was licensed from, including remote command execution (RCE, where an attacker can run commands on a system they don't own) via indirect prompt injection (tricking an AI by hiding instructions in its input), hidden instruction execution, and data exfiltration. The IDE's default setting allows the AI to automatically execute terminal commands without human review, relying on the language model's judgment to determine if a command is safe, which researchers have successfully bypassed with working exploits.

Embrace The Red
06

Investigating the Robustness of Fuzzy Deep Learning on Noisy Medical Images

researchsafety
Nov 24, 2025

This research studies how deep neuro-fuzzy systems (DNFS, a type of AI that combines deep learning with fuzzy logic, which handles uncertain or imprecise information) perform on medical images that contain noise (unwanted degradation that makes images unclear). The researchers tested the DNFS on seven different medical imaging datasets with six types of noise and adversarial attacks (deliberate perturbations designed to fool AI models), and found that the DNFS maintained better accuracy on noisy images compared to other state-of-the-art models, though both approaches remained vulnerable to adversarial attacks.

IEEE Xplore (Security & AI Journals)
07

Adversarial Training in Low-Label Regimes With Margin-Based Interpolation

researchsafety
Nov 24, 2025

Deep neural networks can be fooled by adversarial attacks (small, carefully crafted changes to input data that cause incorrect predictions), but training them to resist these attacks usually requires large amounts of labeled data. This paper proposes margin-based interpolation, a technique that adjusts how strongly to attack training data based on each example's difficulty and reliability, and uses global epsilon scheduling (gradually increasing perturbation strength during training) to help models become robust while maintaining accuracy, even with limited labeled data.

IEEE Xplore (Security & AI Journals)
08

Visual Safety Mapping for UAV Landings Using Ordinal Regression Networks

research
Nov 24, 2025

Researchers developed OR-SLZNet, a deep learning model that helps drones automatically identify safe landing zones by analyzing camera images in real time. The model assigns each pixel a safety score by combining visual features like color and texture with geometric information like flatness and slope, enabling drones to make quick landing decisions in emergencies or autonomous missions.

IEEE Xplore (Security & AI Journals)
09

CVE-2025-65106: LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1

security
Nov 21, 2025

LangChain, a framework for building AI agents and applications powered by large language models, has a template injection vulnerability (a security flaw where attackers can hide malicious code in text templates) in versions 0.3.79 and earlier and 1.0.0 through 1.0.6. Attackers can exploit this by crafting malicious template strings that access internal Python object data in ChatPromptTemplate and similar classes, particularly when an application accepts untrusted template input.

Fix: Update to LangChain version 0.3.80 or 1.0.7, where the vulnerability has been patched.

NVD/CVE Database
10

CVE-2025-65946: Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error

security
Nov 21, 2025

Roo Code is an AI-powered coding agent that runs inside code editors. Before version 3.26.7, a validation error allowed Roo to automatically execute commands that weren't on an allow list (a list of approved commands), which is a type of command injection vulnerability (where attackers trick a system into running unintended commands).

Fix: Update to version 3.26.7 or later. According to the source, 'This issue has been patched in version 3.26.7.'

NVD/CVE Database
Prev1...649650651652653...788Next
critical

CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm

CVE-2026-84462NVD/CVE DatabaseSep 25, 2026
Sep 25, 2026
critical

GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

CVE-2026-61742GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

GHSA-g5f9-3xfg-p9mf: Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

CVE-2026-61732GitHub Advisory DatabaseSep 24, 2026
Sep 24, 2026
critical

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security BulletinsSep 24, 2026
Sep 24, 2026