aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9294 items

Why a decade of doomsday warnings failed to slow the AI race

infonews
safetypolicy
Sep 15, 2026

Despite over a decade of warnings from prominent scientists and tech leaders, including Stephen Hawking in 2014 and recent resignations from AI companies like Anthropic, about risks that advanced AI could pose to humanity, these concerns have not slowed down the development and public release of AI systems like ChatGPT. The article suggests that despite widespread alarm about potential existential threats from superintelligent AI (AI systems smarter than humans across most domains), the AI industry continues to pursue rapid development.

The Guardian Technology

Trump facing AI backlash in Congress as push for guardrails intensifies

infonews
policyindustry

CVE-2026-90878: A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/comp

mediumvulnerability
security
Sep 15, 2026
CVE-2026-90878

A vulnerability was found in vLLM (a library for running large language models) version 0.27.1 and earlier, where attackers can manipulate the chat_template parameter to cause excessive resource consumption through Jinja template rendering (a system for dynamically generating text). The vulnerability can be exploited remotely, and a fix has been proposed but not yet officially accepted.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

highnews
security
Sep 15, 2026

A financially motivated bug bounty hunter created PhantomRaven, a JavaScript-based information stealer (malware that collects sensitive data) distributed through npm, a popular platform where developers share code packages. The threat actor likely used an LLM to write the malware and deployed it via dependency-confusion attacks (tricking systems into downloading malicious packages instead of legitimate ones), though CrowdStrike's analysis suggests they use the stolen information only to identify bug bounty opportunities rather than selling it.

Samsung backs Nvidia AI chip rival in $230 million funding round as GPU alternatives boom

infonews
industry
Sep 14, 2026

Samsung invested $231 million in Euclyd, a Dutch startup designing AI chips with a different architecture than Nvidia's GPUs (graphics processing units, specialized chips for processing data). Euclyd is developing chips specifically for inference (running already-trained AI models) and claims its systems will reduce energy use and costs for AI data centers, targeting commercial deployment starting in 2028.

Is Big Tech’s AI slowdown a safety pact or a cartel?

infonews
policy
Sep 14, 2026

Major AI company leaders including those from OpenAI, Anthropic, Google DeepMind, and SpaceX agreed to slow down AI development, citing safety reasons and proposing third-party auditors (independent evaluators who check whether systems are safe) and global regulations. Critics argue the agreement is actually an anticompetitive cartel (illegal cooperation between companies to limit competition) designed to block smaller competitors and the open-source community rather than improve safety.

Broadcom CEO addresses Anthropic's slowdown push, says AI revenue targets haven't changed

infonews
industry
Sep 14, 2026

Broadcom's CEO dismissed concerns that Anthropic's proposal to slow down frontier AI model development (the creation of increasingly powerful AI systems) would hurt the chipmaker's business, stating the company maintains its revenue forecasts for AI semiconductors through 2028. The slowdown proposal from Anthropic's CEO sparked a stock market sell-off among chip companies, but Broadcom's leader expressed confidence that demand for compute infrastructure (the hardware needed to run AI systems) and AI inference (using trained models to make predictions or generate outputs in real-world applications) will remain strong.

CrowdStrike CEO on Anthropic’s AI safety warning: ‘The genie’s out of the bottle’

infonews
safetypolicy

CVE-2026-12944: IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0)

criticalvulnerability
security
Sep 14, 2026
CVE-2026-12944

IBM Langflow OSS versions 1.0.0 through 1.10.0 have a critical vulnerability where attackers can run arbitrary Python code (code that does whatever the attacker wants) with root privileges (the highest access level) by uploading components that import socket or urllib libraries. This allows attackers to steal AWS credentials, steal files from the server, or attack other services like PostgreSQL and Redis running on the same network, while a faulty security check incorrectly marks these malicious components as safe.

Trump phones Nvidia’s Huang at All-In Summit, calls data center opposition a ‘hoax’

infonews
policy
Sep 14, 2026

President Trump called Nvidia CEO Jensen Huang at a tech conference to express support for AI data center development, calling concerns about data centers and AI a 'hoax' and praising them as 'the oil of the next 20, 25 years.' This followed Trump's criticism of Anthropic CEO Dario Amodei's argument that AI companies should intentionally slow down development to address safety concerns. The phone call highlights Trump's opposition to AI regulation and his alignment with major tech companies pushing for rapid AI advancement.

What execs and politicians are saying about slowing down AI development

infonews
policysafety

CVE-2026-12767: IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic

mediumvulnerability
security
Sep 14, 2026
CVE-2026-12767

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a server-side request forgery vulnerability (SSRF, a flaw that lets attackers trick the server into making unauthorized requests on their behalf). An attacker without authentication could exploit this to probe the network or launch further attacks.

CVE-2026-12766: IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat

mediumvulnerability
security
Sep 14, 2026
CVE-2026-12766

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery vulnerability (SSRF, a flaw where an attacker tricks the server into making unwanted network requests). An authenticated attacker (someone with valid login credentials) could exploit this to send unauthorized requests from the system, potentially discovering network information or launching further attacks.

CVE-2026-12765: IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic

mediumvulnerability
security
Sep 14, 2026
CVE-2026-12765

IBM Langflow OSS versions 1.0.0 through 1.10.2 have a server-side request forgery (SSRF, a vulnerability where an attacker tricks the server into making unintended requests to other systems) vulnerability that lets unauthenticated attackers send unauthorized requests from the affected system. This could be used to scan networks or set up follow-on attacks.

CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context

mediumvulnerability
security
Sep 14, 2026
CVE-2026-12763

IBM Langflow OSS versions 1.0.0 through 1.11.5 has a security flaw where a logged-in attacker can view another user's MCP (Model Context Protocol, a system for connecting AI tools to external services) server settings because the cache key isolation (the method that keeps different users' data separate in temporary storage) is not working properly in the MCP Tools component.

CVE-2026-55093: Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1

mediumvulnerability
security
Sep 14, 2026
CVE-2026-55093

Tract, a toolkit for running machine learning models (TensorFlow and ONNX inference, which means executing pre-trained AI models), has a vulnerability in how it handles tensor dimensions (the sizes of data arrays). Before versions 0.21.16, 0.22.2, and 0.23.1, an attacker could craft a malicious model file that tricks Tract into allocating a small amount of memory while actually trying to access a much larger area, potentially exposing nearby data in memory or crashing the program.

CVE-2026-17628: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account d

mediumvulnerability
security
Sep 14, 2026
CVE-2026-17628

IBM Langflow OSS (an open-source tool for building AI applications) versions 1.0.0 through 1.10.2 has a security flaw where an attacker who is already logged into an account can change another user's password because the system doesn't properly verify who should be allowed to make that change. This allows unauthorized account takeovers for authenticated users.

Jensen Huang puts Trump on speakerphone onstage to announce robots won’t take over the world

infonews
industry
Sep 14, 2026

NVIDIA CEO Jensen Huang took a speakerphone call from President Trump during an industry summit, where Trump dismissed concerns about AI safety as a "hoax" and stated that "robots will not be taking over." The call occurred amid broader debate in the AI industry about how quickly AI development should proceed, including a recent essay from Anthropic's CEO arguing for slower AI advancement.

China dismisses AI ‘fearmongering’ as spy chief warns of threat to Communist party rule

infonews
policy
Sep 14, 2026

China dismissed calls from Anthropic's CEO Dario Amodei for the US to block China's AI development as 'fearmongering,' while China's top spy official warned that advanced AI could threaten Communist party rule. Amodei had written that the US should both slow global AI progress and specifically prevent China from advancing in AI to maintain technological advantage.

The AI industry has taken a doomer turn. What now?

infonews
safetypolicy
Previous13 / 465Next
Sep 15, 2026

Members of Congress from both parties are pushing for guardrails (safety rules and oversight) on AI companies, with surveys showing most Americans support a new federal agency to monitor AI and require safety tests for critical decisions. President Trump dismissed these concerns as a hoax, but lawmakers like Democrat Don Beyer argue the government must regulate AI rather than letting companies regulate themselves, comparing the need to existing oversight in industries like medicine and automobiles.

The Guardian Technology
NVD/CVE Database
CrowdStrike Blog
CNBC Technology
The Verge (AI)
CNBC Technology
Sep 14, 2026

CrowdStrike CEO George Kurtz argues that slowing AI development won't reduce security risks because dangerous models are already widely available, including both frontier models (the most advanced AI systems) and open-weight models (publicly shared AI systems that anyone can download). He says the real solution is stronger AI-powered cybersecurity tools that can monitor and control AI agents (autonomous programs that make decisions independently) once they are deployed, rather than trying to prevent their development.

Fix: According to Kurtz, companies should implement runtime security monitoring of AI agents. This involves using AI defenses to 'look at what these programs do,' 'put our own guardrails around them at runtime,' 'instrument them to see what they're doing, and prevent them from doing bad things.' He also mentions that AI developers and cybersecurity firms should 'work together to protect models both during development and after deployment' and that 'greater safety in the lab and greater safety in production in runtime is ultimately the best course of action.' The text references Anthropic's Project Glasswing as an example of this approach used to safeguard their Mythos model.

CNBC Technology
NVD/CVE Database
CNBC Technology
Sep 14, 2026

Anthropic CEO Dario Amodei published an essay arguing that AI development should be slowed down for safety reasons, and other AI leaders and politicians have responded with support or opposition to his ideas. Amodei's proposal includes three steps for pacing AI development: using independent third-party evaluators (external reviewers who aren't part of the company) to check if companies are following safety practices, and coordination between major AI companies in democratic countries on standards.

The Verge (AI)
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database

Fix: This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.

NVD/CVE Database
NVD/CVE Database
The Verge (AI)
The Guardian Technology
Sep 14, 2026

AI lab leaders, including the CEOs of Anthropic, OpenAI, Google DeepMind, and SpaceX, have publicly called for slowing down the development of large language models (LLMs, which are AI systems trained on massive amounts of text data) because they worry about risks from cyberattacks, bioterrorism, and economic harm. However, the article notes it's unclear what these companies actually mean by a slowdown or how they would implement it, and suggests they may be using safety concerns partly to improve their public image ahead of potential investments.

MIT Technology Review