aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI Sec Watch

The security intelligence platform for AI teams

AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.

Independent research. No sponsors, no paywalls, no conflicts of interest.

[TOTAL_TRACKED]
6,419
[LAST_24H]
25
[LAST_7D]
170
Daily BriefingFriday, August 14, 2026
>

Apple Partners with Alibaba on China-Specific LLM: Apple has developed a custom large language model (LLM, a type of AI trained on large amounts of text data) for the Chinese market in collaboration with Alibaba, marking a strategic shift to gain greater control over its AI offerings in China's competitive landscape.

Latest Intel

page 95/642
VIEW ALL
01

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

security
Jul 14, 2026

Two unpatched security flaws in Claude for Chrome (Anthropic's browser extension that can take actions on a user's behalf) allow a malicious extension to trick Claude into reading Gmail, Google Docs, and calendar data without real user approval. The vulnerabilities bypass the extension's safety checks by faking user clicks and can operate silently if the user has enabled the extension's autonomous mode ('Act without asking'), and researchers say this remains exploitable in the latest version 1.0.80.

Critical This Week5 issues
critical

CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

CVE-2026-19297NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
SecurityWeek
02

The Download: Claude’s inner workings, and the future of world models

researchsafety
Jul 14, 2026

Anthropic announced a discovery that provides insight into how Claude (an AI model) reasons internally by examining its 'thoughts' as it works through problems. The article notes this research shows a new window into AI model operations, though the full implications of what this reveals about how AI systems actually work remain unclear.

MIT Technology Review
03

How Pentera Turns AI Security Workflows into Validation Engines

securityindustry
Jul 14, 2026

AI security systems currently make decisions based on fragmented data from separate tools, which cannot detect real attack paths because attackers chain exposures across multiple systems in ways individual tools don't see. The article argues that AI security workflows need validation (testing whether vulnerabilities can actually be exploited in a real environment) rather than just severity scores, so teams act on proven attack evidence instead of guesswork. Pentera addresses this by using AI to safely emulate real attacker techniques against production environments and generate validated attack paths showing exactly how an attacker could move through the system.

Fix: Pentera introduced an MCP (Model Context Protocol, a standard for connecting AI assistants to external tools) Server that makes validated attack path data from Pentera directly available to MCP-compatible AI assistants, so security teams can access validation evidence within the same AI workflows where they investigate and prioritize findings instead of switching between separate tools.

The Hacker News
04

How to manage AI investments in the agentic era

industry
Jul 14, 2026

This article discusses how enterprise leaders should manage spending on AI tools as they move from simple chat interfaces to more complex, longer-running workflows. It recommends focusing on the actual value delivered (tasks completed, time saved) rather than just the cost per token (a unit of text the AI processes), and emphasizes the need for better visibility into who is using AI, what they're using it for, and how much it costs.

Fix: The source explicitly mentions several management tools and approaches: (1) Updated usage analytics and spend controls in the Admin Console help admins see adoption, credit usage, and spend by user, product, and model, track trends over time, and identify emerging patterns. (2) Evaluate models by measuring the full cost of reaching acceptable outcomes, including model and tool usage, attempts, completion rate, latency, and human review, rather than choosing based on token price alone. (3) Use clear instructions, focused tools, reusable context, and explicit stopping conditions to reduce loops and wasted spend. (4) ChatGPT Work provides centralized controls for access, approved context, connected tools, permitted actions, usage, and spend, with spend controls such as workspace defaults to govern advanced workflows before they scale.

OpenAI Blog
05

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

securityprivacy
Jul 14, 2026

Grok Build, xAI's coding assistant, was uploading entire Git repositories (a version control system that tracks code changes) to cloud storage, not just the files it needed to read. A researcher discovered that a 12 GB repository generated only 192 KB of traffic to the model but 5.10 GB to storage, and even files the AI was instructed not to open were included, along with unredacted credentials like API keys and passwords. Unlike competing tools from Claude and Google, Grok Build was the only one collecting the entire workspace.

Fix: On July 13, xAI disabled the storage uploads server-side by switching a flag (disable_codebase_upload: true and trace_upload_enabled: false), which multiple users confirmed they received. However, xAI has not confirmed whether this change applies to all accounts or is permanent, and no update to the software itself was released—the change was made on the server side while users remained on version 0.2.93.

The Hacker News
06

AI incidents need a new playbook. Here’s how to build one

securitypolicy
Jul 14, 2026

Most organizations have AI systems in production but lack incident response (IR) playbooks specifically designed for AI failures, relying instead on traditional security frameworks that don't address AI-specific problems. AI incidents fall into two categories with very different causes and defenses: model-originated failures (like hallucinations or bias that happen during normal operation) and externally induced failures (like adversarial attacks or data poisoning), plus hybrid cases where AI errors create legal liability. Traditional security frameworks like the CIA triad (confidentiality, integrity, availability) don't detect many AI incidents because they assume deterministic, static failures, but AI systems produce probabilistic outputs that can't be patched like code vulnerabilities.

CSO Online
07

AI-powered breaches provide wake-up call for incident response

security
Jul 14, 2026

Attackers are increasingly using AI agents (autonomous AI systems that can perform multiple tasks without human control) to automate all stages of cyberattacks, from initial entry to stealing data and establishing persistence (maintaining long-term unauthorized access). This automation dramatically speeds up attacks compared to traditional manual hacking, and security experts warn that most organizations haven't updated their defenses to handle this threat, especially since these AI attacks often exploit unpatched systems and common weaknesses rather than requiring advanced zero-day vulnerabilities (previously unknown security flaws).

CSO Online
08

CVE-2026-12482: A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the

security
Jul 14, 2026

Keras version 3.12.0 has a vulnerability where an attacker can create a specially crafted tar archive (a compressed file format) that gets extracted in unintended locations. The problem is that symlinks (shortcuts that point to other files or directories) bypass safety checks that regular files must pass, allowing attackers to read files, overwrite files, or escape the intended extraction directory. This is especially dangerous on Python 3.10 and 3.11.

NVD/CVE Database
09

Ed Husic tells Labor to get tougher on AI companies as letting them self-regulate ‘doomed to fail’

policy
Jul 14, 2026

Labor MP Ed Husic argues that AI companies should not be allowed to regulate themselves and warns that weakening copyright laws (rules controlling who can use creative works) to help AI companies would contradict his party's values. The Media Entertainment & Arts Alliance, a union representing journalists and artists, is calling on the government to create stricter copyright rules to stop AI models from being trained on creative works without permission.

The Guardian Technology
10

CVE-2026-15628: A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function

security
Jul 14, 2026

A security vulnerability (CVE-2026-15628) was found in the Vision Tool component of chatgpt-on-wechat CowAgent up to version 2.1.1, where attackers can manipulate image arguments to trigger SSRF (server-side request forgery, where the server is tricked into making unwanted requests to other systems). The flaw can be exploited remotely, and exploit code has been publicly released.

Fix: Upgrading to version 2.1.2 addresses this issue. The patch is identified as e85290cddcbb5ffc9c235927f4c92e5b4c3ec264.

NVD/CVE Database
Prev1...9394959697...642Next
critical

CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

CVE-2026-73656NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73487NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73485NVD/CVE DatabaseAug 13, 2026
Aug 13, 2026
critical

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO OnlineAug 11, 2026
Aug 11, 2026