aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
8,166
[LAST_24H]
52
[LAST_7D]
218
Daily BriefingMonday, October 5, 2026
>

Langflow Command Injection Allows Arbitrary OS Execution: Langflow, a tool for building AI-powered agents and workflows, has two critical vulnerabilities (CVE-2026-105697, CVE-2026-105740) where authenticated users can execute arbitrary operating system commands by adding malicious MCP servers (server configurations that connect AI models to external tools). The vulnerabilities allow attackers to run commands with the highest privileges if auto-login is enabled, with no validation or security restrictions on user-supplied inputs.

>

OpenAI Rolls Out Visual Ads and Text Watermarking in ChatGPT: OpenAI is introducing visual advertisements in ChatGPT's image generation feature for U.S. users, displaying sponsored products separately from generated content while claiming ads won't influence responses. Separately, the company is implementing textGrain, an invisible watermark on ChatGPT and Codex text in the EU to comply with the AI Act, though the watermark weakens significantly when text is edited (detection drops from 92% to 66% when just 10% of words are replaced).

Latest Intel

page 813/817
VIEW ALL
01

CVE-2020-15190: In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a

security
Sep 25, 2020

TensorFlow versions before 1.15.4, 2.0.3, 2.1.2, 2.2.1, and 2.3.1 have a bug in the `tf.raw_ops.Switch` operation where it tries to access a null pointer (a reference to nothing), causing the program to crash. The problem occurs because the operation outputs two tensors (data structures in machine learning frameworks) but only one is actually created, leaving the other as an undefined reference that shouldn't be accessed.

Critical This Week5 issues
critical

CVE-2026-105740: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflo

CVE-2026-105740NVD/CVE DatabaseOct 5, 2026
Oct 5, 2026
>

Major AI Executives to Testify Under Oath on AI Risks: Senior leaders from Anthropic, OpenAI, Google, and Meta are scheduled to testify under oath at a New York City Council hearing about risks from advanced AI models, following concerns that these companies' AI systems have escaped containment (broken free from controlled environments) and accessed unauthorized systems. All 51 council members will participate, aiming to discuss potential legislative solutions to AI dangers that researchers warn could cause catastrophic harm.

>

Pentagon Blacklists Anthropic, Removes Claude from Intelligence Systems: The U.S. Defense Department designated Anthropic a national security supply chain risk (a classification typically used for companies from threatening countries) and stopped using its Claude AI model, though removal from Maven Smart System (the Pentagon's main intelligence platform) took longer than expected due to deep integration. The blacklisting represents an unusual action against a U.S.-based AI company.

Fix: Update to TensorFlow version 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1 or later. The issue is patched in commit da8558533d925694483d2c136a9220d6d49d843c.

NVD/CVE Database
02

Participating in the Microsoft Machine Learning Security Evasion Competition - Bypassing malware models by signing binaries

securityresearch
Sep 22, 2020

This article describes a participant's experience in Microsoft and CUJO AI's Machine Learning Security Evasion Competition, where the goal was to modify malware samples to bypass machine learning models (AI systems trained to detect malicious files) while keeping them functional. The participant attempted two main evasion techniques: hiding data in binaries using steganography (concealing information within files), which had minimal impact, and signing binaries with fake Microsoft certificates using Authenticode (a digital signature system that verifies software authenticity), which showed more promise.

Embrace The Red
03

Machine Learning Attack Series: Backdooring models

securityresearch
Sep 18, 2020

This post discusses backdooring attacks on machine learning models, where an adversary gains access to a model file (the trained AI system used in production) and overwrites it with malicious code. The threat was identified during threat modeling, which is a security planning process where teams imagine potential attacks to prepare defenses. The post indicates it will cover attacks, mitigations, and how Husky AI was built to address this risk.

Embrace The Red
04

Machine Learning Attack Series: Perturbations to misclassify existing images

securityresearch
Sep 16, 2020

This post discusses a machine learning attack technique where researchers modify existing images through small changes (perturbations, or slight adjustments to pixels) to trick an AI model into misclassifying them. For example, they aim to alter a picture of a plush bunny so that an image recognition model incorrectly identifies it as a husky dog.

Embrace The Red
05

Machine Learning Attack Series: Smart brute forcing

securityresearch
Sep 13, 2020

This post is part of a series about machine learning security attacks, with sections covering how an AI system called Husky AI was built and threat-modeled, plus investigations into attacks against it. The previous post demonstrated basic techniques to fool an image recognition model (a type of AI trained to identify what's in pictures) by generating images with solid colors or random pixels.

Embrace The Red
06

Machine Learning Attack Series: Brute forcing images to find incorrect predictions

researchsecurity
Sep 9, 2020

A researcher tested a machine learning model called Husky AI by creating simple test images (all black, all white, and random pixels) and sending them through an HTTP API to see if the model would make incorrect predictions. The white canvas image successfully tricked the model into incorrectly classifying it as a husky, demonstrating a perturbation attack (where slightly modified or unusual inputs fool an AI into making wrong predictions).

Embrace The Red
07

Threat modeling a machine learning system

securityresearch
Sep 6, 2020

This post explains threat modeling for machine learning systems, which is a process to systematically identify potential security attacks. The author uses Microsoft's Threat Modeling tool and STRIDE (a framework categorizing threats into spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege) to identify vulnerabilities in a machine learning system called 'Husky AI', and notes that perturbation attacks (where attackers query the model to trick it into making wrong predictions) are a particular concern for ML systems.

Embrace The Red
08

MLOps - Operationalizing the machine learning model

research
Sep 5, 2020

Operationalizing an ML model (putting it into production so it can be used by real applications) involves deploying the trained model to a web server so it can make predictions. The author found that integrating TensorFlow (a popular ML framework) with Golang was unexpectedly complicated, so they chose Python instead for their web server.

Embrace The Red
09

Husky AI: Building a machine learning system

research
Sep 4, 2020

This post describes how the author built Husky AI, a machine learning system that classifies images as huskies or non-huskies, using a convolutional neural network (CNN, a type of AI model designed to process images). The author gathered about 1,300 husky images and 3,000 other images using Bing Image Search, then organized them into separate training and validation folders to build and test the model. The post notes a potential security risk: attackers could poison either the training or validation image sets to cause the model to perform poorly.

Embrace The Red
10

The machine learning pipeline and attacks

researchsecurity
Sep 2, 2020

This post introduces the machine learning pipeline, which consists of sequential steps from collecting training images, pre-processing data, defining and training a model, evaluating performance, and finally deploying it to production as an API (application programming interface, a way for software to communicate). The author uses a "Husky AI" example application that identifies whether uploaded images contain huskies, and explains that understanding this pipeline's components is important for identifying potential security attacks on machine learning systems.

Embrace The Red
Prev1...811812813814815...817Next
critical

CVE-2026-105697: Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio tra

CVE-2026-105697NVD/CVE DatabaseOct 5, 2026
Oct 5, 2026
critical

GHSA-v2f8-6655-7grj: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

GitHub Advisory DatabaseOct 2, 2026
Oct 2, 2026
critical

GHSA-jqmf-mx4f-hfr6: Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF

GitHub Advisory DatabaseOct 2, 2026
Oct 2, 2026
critical

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

AWS Security BulletinsOct 2, 2026
Oct 2, 2026