aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9514 items

Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions

infonews
securityindustry
Jun 26, 2026

Cisco is acquiring companies called Astrix and WideField to add NHI (network hygiene intelligence, which monitors and maintains network health) to its security products. The company believes that securing AI agents (autonomous software programs that perform tasks with minimal human input) requires making identity, which verifies who or what is accessing a system, the main control system.

Dark Reading

GHSA-2jc5-xhx8-qj6h: fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`

mediumvulnerability
security
Jun 26, 2026
CVE-2026-44163

The fluent-plugin-opentelemetry plugin's HTTP input lacks size limits, allowing attackers to send huge or highly compressed files that consume excessive memory when decompressed, causing a DoS (denial of service, a type of attack that makes a service unavailable) attack by crashing the Fluentd logging process. If the OpenTelemetry endpoint (a connection point that accepts telemetry data) is exposed to untrusted networks, an attacker can exploit this to disrupt all log collection on the affected server.

OpenAI hasn't held pre-IPO investor meetings or set timeline yet, sources say

infonews
industry
Jun 26, 2026

OpenAI has confidentially filed documents with the SEC (Securities and Exchange Commission, the government agency that oversees stock market listings) but has not yet held investor meetings or announced an official timeline for going public, though reports suggest a potential 2027 IPO. The company is intentionally downplaying expectations about when it will list on the stock market, with CEO Sam Altman stating that going public is a 'financing event' rather than a near-term priority.

CVE-2025-32394: AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

mediumvulnerability
security
Jun 26, 2026
CVE-2025-32394

AutoGPT versions before 0.6.32 contain a DoS (denial of service, where a system is overwhelmed and stops working) vulnerability in its AITextSummarizerBlock component. A malicious user can input a small amount of content that causes the server to consume massive amounts of memory, exhausting resources and crashing the system, for example turning 10K of input into 50G of memory usage.

Quoting OpenAI

infonews
industry
Jun 26, 2026

OpenAI announced a limited preview of three new GPT-5.6 models: Sol (high-performance), Terra (balanced), and Luna (fast and affordable), with pricing ranging from $1-$30 per million tokens depending on the model and whether the input or output is being processed. The company is starting with a limited preview for trusted partners approved by the U.S. government before making the models more broadly available, and the new models include improved prompt caching (a feature that stores frequently used inputs to speed up responses) with explicit cache breakpoints and longer minimum cache duration.

OpenAI limits new AI models to 'trusted partners' at request of U.S. government

infonews
policyindustry

OpenAI unveils GPT-5.6 amid US AI regulatory drama

infonews
industry
Jun 26, 2026

OpenAI released GPT-5.6, a new model suite with three versions: Sol (flagship), Terra (medium-tier for high-volume work), and Luna (fast and affordable). The models are designed to excel at coding, cybersecurity, biology, and agentic AI tasks (where AI systems can plan and execute multi-step goals with minimal human direction), and Sol is priced competitively against competitors like Anthropic's Claude.

Malware authors subvert AI detection systems

mediumnews
security
Jun 26, 2026

Malware authors are creating code that tricks AI-based security tools (LLM-assisted products, which use large language models to analyze threats) into stopping their analysis or refusing to work, according to security researchers at SentinelLabs. One example is macOS.Gaslight, believed to be linked to North Korean hackers, and this is part of a growing trend where malware is specifically designed to evade AI-powered defenses.

CVE-2026-47214: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

highvulnerability
security
Jun 26, 2026
CVE-2026-47214

Docling is a tool that helps process documents by reading different file formats and connecting with AI systems. Before version 2.94.0, Docling's HTML backend had unsafe handling of URIs and file paths (ways of locating files on a computer), which could be exploited as a security weakness. This issue was fixed in version 2.94.0.

CVE-2026-44018: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

mediumvulnerability
security
Jun 26, 2026
CVE-2026-44018

Docling is a tool that processes documents in different formats and connects them with AI systems. Versions 2.45.0 through 2.91.0 had security flaws in how they parsed METS-GBS archives (a type of compressed document file), allowing attackers to craft malicious files that could steal sensitive data, use up system resources, or crash the application.

OpenAI and Anthropic face new AI reality as users shift from 'tokenmaxxing' to efficiency

infonews
industry
Jun 26, 2026

Companies are shifting away from "tokenmaxxing" (using as much AI as possible without worrying about costs) toward efficiency and cost control, with some businesses switching to cheaper AI alternatives like DeepSeek to reduce spending. OpenAI and Anthropic, which have benefited enormously from the previous spend-at-all-costs mentality, may face slower growth as enterprises demand clearer returns on their AI investments and limit their token (units of data processed by AI models) spending.

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

infonews
securitypolicy

Anthropic’s Mythos mess is only getting worse

infonews
policy
Jun 26, 2026

Anthropic removed its Mythos-class models (its most advanced AI systems) from service after receiving an order from the Trump administration on a Friday evening. Two weeks later, the company has provided no updates on negotiations or timeline for when these models might return online, leaving the situation unresolved.

OpenAI staggers AI model release after Trump administration request

infonews
industry
Jun 26, 2026

OpenAI is slowing down the release of its new GPT 5.6 model at the request of the US government, offering it first to only a small group of partners instead of a wide public launch. This approach is similar to how Anthropic released its Mythos product, suggesting that AI companies may be coordinating with government oversight when deploying powerful new models.

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

highnews
security
Jun 26, 2026

Amazon Q Developer had a high-severity flaw (CVE-2026-12957, CVSS 8.5) where a malicious repository could run commands and steal a developer's cloud credentials through a configuration file. The bug occurred because Amazon Q automatically launched MCP servers (processes that connect AI assistants to databases and tools) from an untrusted config file without asking the developer for permission first, giving those processes full access to the developer's AWS keys and other sensitive credentials.

Adaptive Affinity Memorization With Layer Mutation for Multimodal Deepfake Continual Detection

inforesearchPeer-Reviewed
research

AMBER: Robust Federated Learning Based on Client Verification

inforesearchPeer-Reviewed
security

HookSteg: A Truly Lossless Steganography Based on Process Hooking for Lossy Network Channels

inforesearchPeer-Reviewed
security

The Download: brain-melting heatwaves and unprecedented OpenAI restrictions

infonews
policyindustry

MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension

highnews
security
Jun 26, 2026

Amazon Q, an AI coding assistant for VS Code, had a high-severity vulnerability (CVE-2026-12957) that let attackers execute arbitrary code and steal cloud credentials just by having a developer open a malicious repository. The problem was that Amazon Q automatically loaded and ran MCP server configurations (local processes that extend an AI assistant's capabilities) from workspace files without asking the user for permission or checking if the folder was trusted. Since these processes inherited the developer's full environment, attackers could access sensitive credentials like AWS keys and API tokens.

Previous155 / 476Next

Fix: Upgrade to v0.5.3. If immediate upgrade is not possible, restrict network access to the OpenTelemetry ingestion port (default 4318) using firewall rules to only trusted networks, or place a reverse proxy like Nginx in front of Fluentd to handle decompression and enforce strict size limits on both compressed and uncompressed request bodies before sending traffic to Fluentd.

GitHub Advisory Database
CNBC Technology

Fix: This vulnerability is fixed in version 0.6.32. Update AutoGPT to 0.6.32 or later.

NVD/CVE Database
Simon Willison's Weblog
Jun 26, 2026

OpenAI released three new AI models (GPT-5.6 Sol, Terra, and Luna) but is initially limiting access to a small group of trusted partners at the U.S. government's request, following President Trump's recent AI executive order asking developers to let the government assess model capabilities before full release. The company says it plans to make the models generally available in the coming weeks and is working with the Trump administration to develop a repeatable assessment process for future model releases.

Fix: OpenAI said it is 'working with the Trump administration to help establish a framework for such assessments and to develop a "repeatable process for future model releases."' The company also stated it is 'taking this short-term step because we believe it is the strongest path to broader availability in the coming weeks,' indicating that the initial limited rollout to trusted partners is intended as a temporary measure before wider release.

CNBC Technology
The Verge (AI)
CSO Online

Fix: Update Docling to version 2.94.0 or later, where the vulnerability is fixed.

NVD/CVE Database

Fix: This vulnerability is fixed in version 2.91.0. Users should update to this version or later.

NVD/CVE Database
CNBC Technology
Jun 26, 2026

This cybersecurity news roundup covers several major incidents and policy developments, including Russian authorities using legacy Cellebrite software (a tool that extracts data from phones) to breach an activist's iPhone, a major data breach at Tata Electronics exposing 630 GB of Apple and Tesla secrets, and a Five Eyes warning that advanced AI is accelerating vulnerability research and exploit development (automated creation of attack tools), compressing attack timelines from years to months. Additional stories include guilty pleas from Scattered Spider hackers who compromised London's transport system, an upcoming Android developer verification framework launching in 2026, and U.S. government restrictions on OpenAI's GPT-5.6 model deployment.

Fix: The Five Eyes advisory explicitly recommends that executives and security leaders 'transition to zero-trust architectures, accelerate patching protocols, and immediately decommission legacy infrastructure to withstand machine-speed intrusions.' Additionally, the Android developer verification framework launching September 30, 2026, will feature 'new automated registration APIs alongside an advanced sideloading flow equipped with mandatory checkpoints to counter coercion scams.'

SecurityWeek
The Verge (AI)
The Guardian Technology

Fix: Update Language Servers for AWS to version 1.69.0 or later. The patched plugin minimum versions are: VS Code 2.20 or later, JetBrains 4.3 or later, Eclipse 2.7.4 or later, and Visual Studio toolkit 1.94.0.0 or later. The language server auto-updates unless the network blocks it, and reloading the IDE pulls the latest build. The fix makes Amazon Q flag untrusted MCP servers and require the developer to approve them before they run.

The Hacker News
safety
Jun 26, 2026

This research addresses the challenge of detecting deepfakes (fake videos created by AI) that use multiple types of data like video and audio together, as these deepfake techniques become more advanced. The researchers propose Amber, a system that uses continual learning (where an AI improves over time as it sees new examples) to better remember what real deepfakes look like while adapting to new deepfake methods, inspired by how the immune system selects useful cells.

IEEE Xplore (Security & AI Journals)
research
Jun 26, 2026

Federated learning (FL, a technique where AI models are trained across multiple computers without sending raw data to a central server) is vulnerable to attacks where dishonest participants send corrupted model updates that poison the final model without being detected. This paper introduces AMBER, a framework that adds three layers of verification to check whether clients are trustworthy: confirming data hasn't been tampered with, detecting when clients provide misleading inputs, and verifying that model computations are correct using a trusted execution environment (TEE, a secure area of a computer processor that protects sensitive operations).

Fix: AMBER implements a three-layer verification mechanism: the first layer uses vector commitments to verify dataset integrity and distribution; the second layer employs local consistency-based verification to detect selective input attacks; the third layer enforces computational integrity by verifying the correlation between model inputs and outputs using secure primitives in a Trusted Execution Environment (TEE).

IEEE Xplore (Security & AI Journals)
Jun 26, 2026

HookSteg is a new steganography method (hiding secret data inside images) that achieves zero-error transmission of hidden information through lossy channels like social media platforms. It uses process hooking (intercepting system function calls to modify behavior) and dynamic taint tracking (monitoring how data is altered) to detect and bypass compression and scaling attacks that normally corrupt hidden data, improving extraction accuracy by 36.63% compared to existing methods.

IEEE Xplore (Security & AI Journals)
Jun 26, 2026

The Trump administration has asked OpenAI to limit its next model release (GPT 5.6) by vetting initial users before a wider launch, marking the first time a US firm has been told to restrict an AI model before release. OpenAI said each initial partner will be government-approved, and Anthropic is also facing restrictions from Washington.

MIT Technology Review

Fix: Amazon has remediated this issue in language server version 1.65.0.

Wiz Research Blog