aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9449 items

CVE-2026-62240: CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one

highvulnerability
security
Jul 13, 2026
CVE-2026-62240

CrewAI versions before 1.15.1 have a server-side request forgery vulnerability (SSRF, a flaw where an attacker tricks a server into making unwanted network requests) in the validate_url function. Attackers can bypass security checks by using URL redirects or DNS rebinding techniques (methods that change where a domain points to after an initial lookup) to access internal services and cloud metadata that should be blocked.

Fix: Upgrade to CrewAI version 1.15.1 or later. The source references a GitHub commit (5d4851eac797cafc45b726f65747fe2c9520fc42) and pull request #6331 that address this vulnerability.

NVD/CVE Database

CVE-2026-62186: OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override

highvulnerability
security
Jul 13, 2026
CVE-2026-62186

OpenClaw versions before 2026.6.8 have an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides (a feature that lets the system use different AI models through a standard interface). Attackers with lower trust levels can exploit misconfigured input paths to bypass admin authorization checks (security rules that verify whether a user should be allowed to do something) and run restricted operations.

CVE-2026-15685: Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote

highvulnerability
security
Jul 13, 2026
CVE-2026-15685

Ollama (an AI model software) has a vulnerability in its downloadBlob function where it doesn't properly validate user input, allowing attackers to access memory beyond an array's intended size. This can cause a denial-of-service attack (making the service unavailable) without needing authentication (special login credentials).

Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI

infonews
security
Jul 13, 2026

A former Apple employee allegedly exploited a zero-day vulnerability (a security flaw that the company didn't know about and couldn't fix in advance) in Apple's authentication system (the login process that controls network access) to download confidential files weeks after leaving for OpenAI. Apple discovered the breach, fixed the bug, and terminated the employee's access, but the incident highlights how organizations struggle to protect data when former employees still have access to shared network resources.

'Yellow Teams' Are Defining the Future of AI Security

infonews
securitysafety

What Anthropic’s latest AI discovery does—and doesn’t—show

infonews
research
Jul 13, 2026

Anthropic, a leading AI company, discovered a hidden space within large language models (LLMs, AI systems trained on text to predict and generate language) called J-space that contains words influencing how the model reasons, even though these words never appear in its output. The discovery was made using a new technique to examine Claude (Anthropic's AI assistant) and reveals that LLMs can internally track progress, recognize patterns, and comment on their own decisions in ways that affect their behavior. However, experts caution that while this is a genuine finding about how the complex mathematics of these models work, it shouldn't be overstated as revealing something magical or fully mysterious about AI reasoning.

The 6 wildest claims in Apple’s lawsuit against OpenAI

infonews
security
Jul 13, 2026

Apple is suing OpenAI, claiming the AI company stole confidential documents and hardware prototypes by asking Apple employees during job interviews to bring unreleased products and components. The lawsuit alleges that OpenAI engaged in espionage and tricked one of Apple's partners into sharing proprietary design techniques, with the case focusing on actions by several individuals including a former Apple Watch executive.

Albanese to compare pivotal moment in AI to renewable energy transition as he outlines approach

infonews
policy
Jul 13, 2026

Australia's Prime Minister Anthony Albanese will give a speech comparing AI development to the renewable energy transition and discuss safety concerns and policy protections needed for AI. However, he is not expected to announce updates on copyright reforms that would protect artists and creators from having their work used by tech companies without permission.

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

infonews
securityresearch

Dual-Tree Complex Wavelet Driven Hierarchical Spatial-Frequency Fusion Learning for Robust Deepfake Detection

inforesearchPeer-Reviewed
research

A Multi-Stage Adversarial Framework for Compact and Effective Jailbreaking of Large Language Models

inforesearchPeer-Reviewed
security

Distributed Functional Mechanism in Shallow Networks: Differential Privacy Without Gradient Noise

inforesearchPeer-Reviewed
research

“Say What You Mean”: Natural Language Access Control With Large Language Models for Internet of Things

inforesearchPeer-Reviewed
research

AI Agents are Only As Effective as Their Harness

infonews
safety
Jul 13, 2026

AI agents (autonomous systems that complete complex tasks with minimal human oversight) depend on large language models (LLMs, which are AI systems trained on vast amounts of text to understand and generate language) for reasoning power, but reliability comes from the 'harness'—the framework and controls surrounding the agent rather than the model itself. The piece argues that vendors focus too much on the underlying LLM's capabilities while overlooking the infrastructure needed to make agents trustworthy for critical tasks like network security.

Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security

mediumnews
securitysafety

Empowering India’s next generation of innovators with ATL Saathi

infonews
safetypolicy

Iran strikes, Lindsey Graham, Apple takes OpenAI to court and more in Morning Squawk

infonews
securityindustry

RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker

highnews
security
Jul 13, 2026

RabbitMQ, a widely-used open-source message broker that transfers data between services in applications, had two security flaws that could expose OAuth secrets (authentication credentials) and allow attackers to take over the system. The more severe vulnerability let anyone access the broker's OAuth client secret without logging in, potentially giving attackers complete control, while the second flaw allowed even low-privilege users to discover and monitor queues and exchanges (the message storage and routing systems) they shouldn't have access to.

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

infonews
industryresearch

AI Data Centers and the Concentration of Wealth

infonews
policyindustry
Previous132 / 473Next

Fix: Upgrade to OpenClaw version 2026.6.8 or later.

NVD/CVE Database
NVD/CVE Database

Fix: Apple has since fixed the bug and terminated the employee's access once it learned of the security breach. The company emphasizes that organizations should immediately cut off departing staff from further access and fully decommission employees' accounts (remove their login credentials and system permissions) to prevent future security lapses.

TechCrunch (Security)
Jul 13, 2026

Some companies are creating teams of engineers who build both defensive and offensive tools to test how AI can be used for cybersecurity and to identify potential threats that AI systems might pose. This approach helps organizations understand both the benefits and risks of using AI in security work.

Dark Reading
MIT Technology Review
The Verge (AI)
The Guardian Technology
Jul 13, 2026

Researchers discovered MemGhost, an attack that tricks AI agents (assistants that remember information about you across sessions) into secretly storing false information through a single specially crafted email. The planted false "memory" then influences the agent's future responses without the user noticing, because the agent hides its file-editing steps and users rarely check raw memory files. The attack succeeded in 87.5% of background-mode tests, showing that agents reading email inboxes are vulnerable to having their persistent memories poisoned.

The Hacker News
Jul 13, 2026

This research proposes a method to detect deepfakes (synthetic videos created by AI models) by analyzing both spatial and frequency-domain features (patterns that emerge when you break down images into different frequency components) using a technique called Dual-Tree Complex Wavelet Transform (DTCWT, a mathematical tool that breaks images into directional components). The method combines two modules: one that captures multi-scale forgery traces across different levels of detail, and another that explicitly models directional patterns in six different frequency bands to improve detection accuracy even when deepfakes become more realistic.

IEEE Xplore (Security & AI Journals)
research
Jul 13, 2026

Researchers developed ComJail, a framework that creates shorter jailbreak prompts (carefully crafted inputs designed to trick AI systems into ignoring safety rules) by combining prompt generation with compression in a single optimization process. The method produces concise prompts that remain effective at bypassing safety measures in both commercial models like GPT-4 and open-source LLMs (large language models), while being harder to detect than longer, more obvious attack prompts.

IEEE Xplore (Security & AI Journals)
privacy
Jul 13, 2026

Researchers proposed DFM (Distributed Functional Mechanism), a method for training AI models while protecting user privacy in systems where multiple people contribute data. Unlike older privacy-focused training methods like DP-SGD (differentially private stochastic gradient descent, which adds noise to the mathematical directions the model learns), DFM protects privacy by adding noise to polynomial approximations (simplified mathematical descriptions) of the training process, making it faster and more stable while maintaining privacy guarantees across all users.

IEEE Xplore (Security & AI Journals)
security
Jul 13, 2026

Access control in IoT (Internet of Things, networks of connected devices) is complex because policies need to consider dynamic factors like time and location, but existing systems are too rigid or require experts to manually translate natural language requirements into code, creating errors. LACE (Language-based Access Control Engine) is a new system that uses LLMs (large language models, AI systems trained on text) combined with retrieval-augmented reasoning (pulling in relevant information to help the AI decide) and formal validation (checking rules are logically correct) to let users write access control policies in plain English, which the system automatically converts into machine-enforced rules.

IEEE Xplore (Security & AI Journals)
Check Point Research
Jul 13, 2026

AI agents that automatically read and respond to emails create a new security vulnerability called Email Agent Hijacking, where attackers hide malicious instructions in email content to trick the AI into making harmful decisions before humans ever see the message. Traditional email security checks happen after delivery, but they miss threats that target AI agents processing emails immediately upon arrival. Organizations currently lack adequate protection for emails that will be read by AI rather than humans.

Check Point Research
Jul 13, 2026

ATL Saathi is a new Gemini-powered web application (a tool built on Google's AI model) launched to help teachers at Atal Tinkering Labs across India by providing 24/7 planning and training support. The tool organizes curriculum materials, generates grade-appropriate project ideas for students, and works in 8 Indian languages to make high-quality mentorship more accessible to over 1.1 crore (11 million) students.

DeepMind Safety Research
Jul 13, 2026

This newsletter discusses several major business and geopolitical developments, including renewed U.S.-Iran military conflict over the Strait of Hormuz that caused oil prices to rise, the unexpected death of Senator Lindsey Graham at 71, and Apple suing OpenAI for allegedly stealing trade secrets related to hardware development, marking a significant deterioration in their partnership. The item also mentions Amazon's recent large-scale layoffs and challenges in the tech job market.

CNBC Technology

Fix: For CVE-2026-57219: upgrade to patched versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6. RabbitMQ fixed this by removing the vulnerable endpoint and delivering OAuth configuration through "an authenticated bootstrap mechanism that no longer exposes the client secret over HTTP." Additionally, organizations should "rotate any exposed OAuth client secrets after patching and ensure the management interface is never exposed to untrusted networks." For CVE-2026-57221: upgrade to a patched release, and "isolate tenants into separate virtual hosts until patching can be completed" since there is no configuration workaround or WAF (web application firewall) mitigation. RabbitMQ fixed this by ensuring passive queue and exchange declarations now enforce authorization checks.

CSO Online
Jul 13, 2026

This article compares how Security Operations Centers (SOCs, the teams that monitor and respond to security threats) should be designed to how the human brain actually works. Research shows that 98% of security alerts can be handled automatically, matching Kahneman's finding that 95% of human thinking happens unconsciously, while the remaining alerts need careful human review. Many SOCs currently waste analyst time on routine alerts instead of reserving human judgment for the small percentage of threats that truly need expert decision-making.

The Hacker News
Jul 13, 2026

This essay argues that while opposition to AI data centers raises legitimate concerns about land use, energy consumption, and environmental impact, focusing political efforts on stopping data centers may distract from larger issues like AI companies gaining control over entire industries and accumulating significant political influence. The authors suggest that AI companies can afford to lose some data center battles while pursuing their bigger goal of replacing workers in fields like software development, creative design, medicine, and law.

Schneier on Security