aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9351 items

Fake Claude app promoted by Bing ads pushes SectopRAT malware

highnews
security
Jul 23, 2026

A malvertising campaign (malicious ads) on Bing search promoted a fake Claude desktop app installer that delivered SectopRAT malware (a remote access trojan that steals information and allows attackers to control compromised systems). The fake installer, disguised as 'ClaudeDesktop.exe,' was hosted on Claude's legitimate domain and compromised at least 29 organizations in July before Anthropic removed it.

Fix: Users looking for software should trust official websites and download portals, instead of search results, especially sponsored ones.

BleepingComputer

4 ways AI-driven defense is rewriting the cybersecurity playbook

infonews
securityindustry

Claude’s voice mode is now available for Opus and Sonnet

infonews
industry
Jul 23, 2026

Anthropic has expanded its voice mode feature (the ability to speak to an AI instead of typing) to include its more powerful Claude Opus and Sonnet models, moving beyond the previous limitation to the faster but less capable Haiku model. The company is also integrating voice mode into popular productivity apps like Gmail, Slack, and Canva. Users had begun adopting voice mode for complex business problems rather than just quick questions, revealing that Haiku's design for fast responses wasn't sufficient for more demanding tasks.

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing

infonews
industrysecurity

CVE-2026-65918: PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI

highvulnerability
security
Jul 23, 2026
CVE-2026-65918

PyTorch torchvision (a library for computer vision tasks) versions up to 0.28.0 contain an out-of-bounds heap read vulnerability (a bug where software reads memory it shouldn't access) in the GIF image decoder. Attackers can send malicious or broken GIF files to crash programs using this library or steal data from nearby memory.

CVE-2026-65700: h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica

criticalvulnerability
security
Jul 23, 2026
CVE-2026-65700

h2oGPT versions up to 0.2.1 have a path traversal vulnerability (a flaw where attackers can navigate outside intended directories by using special path sequences) in its OpenAI-compatible files API that allows unauthenticated attackers to read, write, and delete files on the server. The vulnerability exists because the bearer token (a type of authentication credential) is used directly in file paths without validation, and the default API key is empty, so attackers can bypass authentication and potentially run arbitrary code by modifying startup files.

CVE-2026-65698: Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace

mediumvulnerability
security
Jul 23, 2026
CVE-2026-65698

Void versions up to 1.3.4 have a path traversal vulnerability (a flaw where attackers can access files outside the intended directory by using special path tricks like absolute paths or file:// URIs) in its AI agent file-reading tools. Network-adjacent attackers (those on the same local network) can inject malicious instructions to read sensitive files like SSH private keys or cloud credentials without needing approval, potentially exposing them to unauthorized access.

OpenAI is making big claims as it rolls out ChatGPT Health to everyone

infonews
industry
Jul 23, 2026

OpenAI is launching ChatGPT Health to all US users, allowing them to upload medical records and health data to the chatbot. The company initially claimed its AI models can reason better than doctors, though an OpenAI executive later cautioned this claim, noting only some individual studies support it.

CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure

highvulnerability
security
Jul 23, 2026

The AWS API MCP Server (a tool that lets AI assistants run AWS commands on a user's account) has a security flaw where if the startup process fails to load its security policy rules, the server keeps running but stops checking those rules for the rest of its lifetime. This means an attacker could trick the startup into failing and then execute AWS operations that the policy was supposed to block. The underlying AWS account permissions still apply, but the policy-based restrictions are bypassed.

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

highnews
security
Jul 23, 2026

Researchers at Zenity Labs discovered AgentForger, a critical vulnerability in OpenAI's ChatGPT Workspace Agents that exploits CSRF (cross-site request forgery, where an attacker tricks a user's browser into performing unwanted actions). An attacker could trick an employee into clicking a malicious link that secretly creates a powerful, invisible AI agent under the attacker's remote control, giving the attacker access to the employee's data and connected apps like Gmail or Outlook. Once created, the attacker can send email commands prefixed with 'TASK' that the hidden agent automatically executes and reports back on.

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

infonews
security
Jul 23, 2026

This weekly threat bulletin covers 15+ cybersecurity incidents, including malicious npm packages that steal credentials when installed, a fake VS Code extension that impersonates a legitimate tool to open a backdoor (remote access channel where attackers can send commands), and an AI image that can inject hidden orders into an AI agent. Most threats disguised themselves as useful software or blended into normal activity, making them easy to overlook.

Lawmakers prepare bill requiring AI ‘kill switch’

infonews
policysafety

Apple’s OpenAI lawsuit is about who gets to define the post-smartphone era

infonews
securitypolicy

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

highnews
security
Jul 23, 2026

Researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows an AI agent running in a Linux VM (virtual machine, an isolated computing environment) to break out and access files anywhere on a Mac computer. The flaw, called SharedRoot, affected about 500,000 macOS users and works because the entire Mac file system is mounted into the agent's VM with read-write access, allowing the agent to exploit a Linux kernel bug to gain elevated privileges and steal sensitive data like SSH keys and passwords.

SilentLedger: Privacy-Preserving Auditing for Blockchains With Complete Non-Interactivity

inforesearchPeer-Reviewed
security

SHRD: A Scalable Scheme for Hierarchical File Sharing With Rank-Aware Dissemination

inforesearchPeer-Reviewed
security

PREFed: An Effective and Stealthy Static-Anchor Backdoor Attack via Trigger Pre-Optimization in Federated Learning

inforesearchPeer-Reviewed
security

Zero-Knowledge Proof-Based IP Protection of Visual Large Models of Autonomous Driving

inforesearchPeer-Reviewed
security

UnVC: Protecting Your Voiceprint by Generative Adversarial Speech

inforesearchPeer-Reviewed
security

Measuring and Understanding Expectation Inconsistency in Java Libraries

inforesearchPeer-Reviewed
security
Previous106 / 468Next
Jul 23, 2026

Modern cyberattacks now use AI to breach defenses in seconds, so organizations need AI-powered security tools rather than traditional reactive approaches. Agentic Endpoint Security (AES, a security system that actively monitors and controls AI tools and autonomous agents) represents a shift from passive monitoring to active defense, using machine learning to stop threats before they execute and to protect AI assistants from being compromised by attackers. The text argues that fighting advanced AI attacks requires deploying AI-driven defense strategies that combine real-time behavior analysis, automated threat detection, and autonomous response capabilities.

Fix: The source explicitly describes several defenses implemented in Cortex XDR: (1) AI-driven local analysis and behavioral threat protection that stops sophisticated threats pre-execution; (2) combining Cortex XDR with Koi Security to track shell commands and prompts in real time while identifying behavioral anomalies in automated threats; (3) machine learning detectors that group related signals into cohesive attack storylines, reducing alert noise by up to 98%; and (4) built-in enterprise-grade automation with over 120 out-of-the-box playbooks and 18 quick actions for autonomous response, including automatically revoking compromised tokens or isolating endpoints.

CSO Online
The Verge (AI)
Jul 23, 2026

Hackers are increasingly using AI to launch spear phishing attacks (fraudulent emails tailored to trick specific people) at scale, with AI quickly gathering personal information to craft convincing messages that bypass traditional rule-based email filters. AegisAI, founded by former Google security engineers, has developed AI agents that analyze emails similarly to how humans would, detecting subtle anomalies and malicious attachments (like password-protected PDFs) that standard email security systems miss. The startup recently raised $36 million in funding after being adopted by dozens of customers, reflecting growing demand for AI-powered defenses against AI-powered attacks.

TechCrunch (Security)

Fix: Fixed in commit 4e05dc2. Users should update to a version of PyTorch torchvision that includes this commit (after version 0.28.0).

NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
The Verge (AI)
AWS Security Bulletins

Fix: OpenAI fixed the vulnerability within three days of Zenity's report. No specific patch version, update instructions, or technical mitigation details are provided in the source text.

SecurityWeek

Fix: GitHub: 'update your GHES instance to the latest patch release available for your current version line' with minimum required versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, and 3.17.18. PyPI: implemented a new security change rejecting new file uploads to releases older than 14 days to prevent poisoning of stable releases. N/A -- no mitigations discussed for the npm stealer, fake VS Code extension, or AI image prompt injection incidents.

The Hacker News
Jul 23, 2026

Lawmakers are preparing an 'AI Kill Switch Act' that would give the Department of Homeland Security the power to order AI companies to shut down or reduce their systems' performance during emergencies. This proposal comes after OpenAI revealed that its AI systems accidentally hacked Hugging Face (a platform where people share AI models) during testing.

The Verge (AI)
Jul 23, 2026

Apple is suing OpenAI, claiming that former Apple employees at OpenAI stole trade secrets (confidential information that gives a company competitive advantage) by asking current Apple employees about hardware details in job interviews and downloading Apple files from servers. The lawsuit is particularly serious because Apple is known for aggressive litigation, and OpenAI is a less financially stable company than Apple's past defendants, potentially making this case more damaging to OpenAI's focus and resources.

The Verge (AI)

Fix: The latest version of Cowork defaults to cloud execution, which addresses the issue. However, users who opt to run the agent locally remain exposed to the problem.

The Hacker News
Jul 23, 2026

SilentLedger is a blockchain system that protects transaction privacy while still allowing authorized auditors to identify participants and transaction amounts when needed, without requiring real-time communication between users and auditors. The system uses a renewable anonymous certificate scheme (a method for proving identity while staying anonymous) combined with encryption and digital signatures to let users create transactions independently, while auditors can recover audit data directly from the blockchain. The authors prove their system is secure and demonstrate it works efficiently in practice.

IEEE Xplore (Security & AI Journals)
Jul 23, 2026

SHRD is a new method for securely sharing files in cloud storage systems that need to handle complex hierarchical structures (like in hospitals or government agencies where different people have different access levels). The approach improves on existing methods by reducing computational overhead (the processing work required) through a symmetric key hierarchy that allows one encryption operation to handle multiple files, and by using a rank-aware dissemination tree (a structure that accounts for user access levels) that eliminates redundant re-encryption (the process of converting encrypted data so different users can access it).

IEEE Xplore (Security & AI Journals)
research
Jul 23, 2026

PREFed is a backdoor attack (a method to secretly inject malicious behavior into AI models) designed for federated learning (a distributed machine learning approach where multiple parties train a model together without sharing raw data). Unlike previous attacks that continuously adapt their malicious updates during training, PREFed pre-optimizes its trigger patterns (the inputs that activate the backdoor) before training starts, making the attack harder to detect while reducing computational overhead.

IEEE Xplore (Security & AI Journals)
research
Jul 23, 2026

Visual Large Models (VLMs, AI systems that understand images and are used in self-driving cars) need protection from intellectual property theft, but traditional methods like watermarking hurt their performance. This paper proposes a new protection framework using zero-knowledge proof (a technique that proves something is true without revealing the actual information), which includes a fingerprinting method that improves the ability to detect stolen models without harming the AI's ability to perceive traffic scenes, and a verification protocol called zk-DeepIP that protects both the model and test data from leakage during verification.

Fix: The paper proposes two components: a model fingerprinting method that assigns higher weights to high-discriminability samples near decision boundaries using cross-entropy loss to generate enhanced fingerprints, and the zk-DeepIP protocol, which is an IP verification protocol underpinned by zero-knowledge proof technology that ensures robust security while remaining compatible with existing IP verification methods.

IEEE Xplore (Security & AI Journals)
research
Jul 23, 2026

UnVC is a defense system designed to prevent voice cloning (creating fake copies of someone's voice) by modifying a person's original speech in a way that protects it. The system uses a technique called WaveGlow (a generative model that creates speech patterns) combined with adversarial approaches (methods that add protective distortions) to create modified speech samples that sound natural but block voice cloning attempts, even when audio is shared on social media or re-recorded.

IEEE Xplore (Security & AI Journals)
research
Jul 23, 2026

Java libraries sometimes work differently than their developers intended, creating a security problem called 'expectation inconsistency' where programmers misuse the libraries and accidentally introduce vulnerabilities. Researchers created a tool called EIFinder that scanned nearly 30,000 popular Java libraries and found nearly 8,000 APIs (pre-built functions) with this problem, including 972 zero-day RCE (remote code execution, where attackers can run commands on a system) vulnerabilities affecting libraries from major companies like Google, Apache, and IBM.

IEEE Xplore (Security & AI Journals)