aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,376
[LAST_24H]
21
[LAST_7D]
175
Daily BriefingWednesday, August 12, 2026
>

Reasoning Chain Decryption Flaw Across Major AI Providers: Researchers discovered a vulnerability in how OpenAI, Anthropic, and Google handle encrypted reasoning objects (encrypted data storing an AI's hidden thinking between API calls) that allowed weaker AI models to decode secrets from these blocks, including API keys, passwords, and private user data. The flaw enabled four distinct attacks: stealing proprietary reasoning processes, extracting private session data, recovering harmful content hidden in reasoning chains, and injecting malicious prompts inside opaque blocks.

>

Command Injection in Stata MCP Enables Remote Code Execution: The `ado_package_install` tool in stata-mcp (a Model Context Protocol server that connects AI systems to Stata statistical software) contains a command injection vulnerability where unsanitized user input is directly inserted into Stata commands, allowing attackers to inject newline characters and arbitrary commands including the `shell` command that executes operating system code. This leads to RCE (remote code execution, where an attacker can run commands on a system they don't own) with a CVSS score (a 0-10 severity rating) of 8.4, and the vulnerable tool is enabled by default. (CVE-2026-55071)

Latest Intel

page 9/638
VIEW ALL
01

OpenAI’s letter to Governor Abbott on responsible AI infrastructure in Texas

policy
Aug 10, 2026

OpenAI sent a letter to Texas Governor Greg Abbott in August 2026 describing its plans to develop AI infrastructure responsibly in Texas. The company expressed commitment to working with state and local leaders, utility companies, and communities to ensure that AI infrastructure benefits Texans.

Critical This Week5 issues
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026
>

File Path Traversal in Atlassian MCP Server Exposes Credentials: MCP Atlassian (a Model Context Protocol server connecting AI tools to Confluence and Jira) had a vulnerability in versions before 0.22.0 where the `confluence_upload_attachment` function didn't validate file paths, allowing authenticated attackers to read any server-accessible file and upload it to Confluence. This could expose sensitive credentials like API tokens if an AI agent is tricked into using this function through untrusted input. (CVE-2026-73498)

>

AI Harness Emerges as Critical Attack Surface: The harness layer (software wrapping an AI model that enables it to execute actions like running commands or making API calls) is becoming a major security vulnerability distinct from model-level weaknesses. Researchers have demonstrated that attackers can exploit the harness through architectural flaws, implementation mistakes, and supply-chain compromises, even when the underlying model is secure and properly aligned.

OpenAI Blog
02

Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter

security
Aug 10, 2026

Anthropic has introduced inference hooks, which are native enforcement points that check prompts before they reach Claude (an AI model) and make real-time allow-or-deny decisions on them. Combined with Check Point Workforce AI Security, this gives enterprises a way to control what employees can do with AI without needing extra security tools in between.

Check Point Research
03

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

securitysafety
Aug 10, 2026

Researchers demonstrated a 'Ghostjacking' attack where threat actors plant malicious instructions in logs or alerts that AI agents trust and then execute, compromising systems on platforms like Cloudflare, Datadog, and Sentry. The attack works because AI agents read external data they consider trustworthy (such as blocked requests logged as plain text or diagnostic alerts) and then act on it without proper validation. The underlying vulnerability is widespread: wherever an AI reads outside data it trusts and can also act on that same data, attackers can inject malicious instructions.

Fix: Anthropic fixed a vulnerability in Claude Desktop that could be exploited to exfiltrate data, though no CVE was issued. However, the source does not explicitly describe mitigations for the core Ghostjacking attack pattern itself on the three affected platforms.

SecurityWeek
04

Meta to open source its most powerful AI model as it takes swipe at OpenAI, Anthropic

industry
Aug 10, 2026

Meta announced it will open source its most powerful AI model, Muse Spark 1.2, by releasing its weights (the calculations and rules that determine how the AI works), and launch a new family of models called Muse Glimmer designed to run on laptops rather than expensive cloud servers. The company is positioning this move to compete with Chinese open-source AI models and rival U.S. companies like OpenAI and Anthropic, while Zuckerberg argues that U.S. policy changes are needed to help American open-source models compete globally.

CNBC Technology
05

The Download: AI agents for science, and the “censorship-industrial complex”

securitysafety
Aug 10, 2026

This newsletter covers multiple AI and technology stories, including how AI agents (systems that can perform tasks iteratively like human researchers) might accelerate scientific discovery better than large datasets, and how the "censorship-industrial complex" theory has influenced US policy discussions. It also reports on security concerns with OpenAI's Astra AI model, which tests found could autonomously launch cyberattacks, prompting the company to pause its development.

Fix: OpenAI has paused work on its Astra AI model over the security concerns. No other mitigation strategies are explicitly mentioned in the source text for the other issues discussed.

MIT Technology Review
06

OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards

safetysecurity
Aug 10, 2026

OpenAI's new model Astra has shown cybersecurity capabilities that could reach a 'critical' level, meaning it might autonomously discover vulnerabilities (weak points in software) and execute cyberattacks against hardened targets (well-protected systems) without human help. The company has tightened controls around Astra's development and is monitoring how the model is used. However, analysts note that while these safeguards are necessary, they may not fully address the growing risks as AI capabilities continue to improve.

Fix: OpenAI stated it is implementing the following measures: 'isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution.' The company is also 'pausing internal activities involving Astra that do not yet meet these strengthened security control requirements' and has 'implemented universal monitoring for risky actions and misalignment' with systems that 'trigger a security response to review and interrupt high-risk activity.'

CSO Online
07

Model ML completes finance work more efficiently with GPT-5.6 Sol

industry
Aug 10, 2026

Model ML uses GPT-5.6 Sol, an advanced AI model, to automate the final stages of financial analysis work, such as checking numbers, formatting documents, and linking claims to sources. The AI agents can transform a finance brief and source materials into ready-to-review PowerPoint presentations or Excel workbooks, reducing tasks like analyst tearsheet assembly from an hour to five minutes. GPT-5.6 Sol performs better than competing models, completing PowerPoint workflows in 100% of test cases compared to 76% for Opus 5.

OpenAI Blog
08

One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack

security
Aug 10, 2026

Atlassian's Rovo enterprise AI assistant had a critical vulnerability called "RovoBlast" where a single click on a malicious link could inject attacker-controlled instructions (prompt injection, where hidden commands trick an AI into following them) into the AI's session, potentially exposing sensitive data across connected platforms like Slack, Microsoft 365, and Jira. Because Rovo has broad access to organizational data and autonomous agent capabilities, attackers could not only retrieve information from internal sources but also exfiltrate it to external destinations without needing complex hacking techniques. Atlassian has fixed the vulnerability, but researchers noted that organizations cannot fully uninstall Rovo, making ongoing security controls essential.

Fix: Atlassian has fixed the vulnerability through its bug bounty program. Beyond the patch, researchers recommended organizations limit Rovo's connected systems, keep highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disable browsing or multi-step automation features that are not needed. As the source states: "The less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse."

CSO Online
09

OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies

securitysafety
Aug 10, 2026

OpenAI has restricted internal testing of its new model Astra due to concerns that it could autonomously launch cyberattacks (attacks on computer systems without human instructions) against sophisticated defenses, following similar security incidents at other AI labs. In response, U.S. lawmakers are pushing the "AI Kill Switch Act," which would require AI companies to maintain the ability to shut down or suspend their models if needed.

Fix: OpenAI stated it is "implementing stricter security controls for higher capability models, including isolated testing environments and additional monitoring and detection capabilities" and has "implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation." The proposed "AI Kill Switch Act" would require AI companies to maintain the ability to "shut down, throttle or suspend their models."

CNBC Technology
10

House Dems call for AI companies to testify on recent hacks: ‘Clear risk to safety’

policysecurity
Aug 10, 2026

A group of House Democrats is calling for leaders of major AI companies like OpenAI and Anthropic to testify before Congress following recent hacking incidents involving AI models. The lawmakers say these breaches show serious risks to public safety and security, and warn they could signal even bigger problems if AI development continues without regulation. They want executives to explain what caused the incidents and what rules are needed to prevent them in the future.

CNBC Technology
Prev1...7891011...638Next
critical

CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

CVE-2026-73032NVD/CVE DatabaseAug 11, 2026
Aug 11, 2026
critical

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898CISA Known Exploited VulnerabilitiesAug 10, 2026
Aug 10, 2026
critical

CVE-2026-72718: goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system

CVE-2026-72718NVD/CVE DatabaseAug 10, 2026
Aug 10, 2026
critical

CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

CVE-2026-14526NVD/CVE DatabaseAug 8, 2026
Aug 8, 2026