aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9614 items

The film about Sam Altman has been dropped by Amazon MGM

infonews
industry
Jun 19, 2026

Amazon MGM has dropped a film called Artificial, directed by Luca Guadagnino, that was about OpenAI CEO Sam Altman and the five-day period in 2023 when he was fired and then rehired. The studio said it believes another company would be better suited to release the movie.

The Verge (AI)

GHSA-qw6v-5fcf-5666: Network-AI: Improper Neutralization of Special Elements used in an OS Command

criticalvulnerability
security
Jun 19, 2026
CVE-2026-54051

Network-AI versions before 5.9.1 have a command injection vulnerability where wildcard allowlist rules like `git *` can be bypassed to run arbitrary commands. The bug occurs because the allowlist (a security filter that approves which commands can run) matches the whole command string using loose glob patterns, but then executes it through `/bin/sh -c` (the shell interpreter), which interprets special characters like semicolons and pipes, allowing an attacker to append malicious commands like `git status; id`.

GHSA-r78r-rwrf-rjwp: Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

criticalvulnerability
security
Jun 19, 2026
CVE-2026-48814

The Network-AI package (npm `network-ai`, v5.7.1) has an incomplete security fix for CVE-2026-46701. While a previous update blocked browser-based attacks by restricting CORS (cross-origin resource sharing, which controls what websites can access a server), the core problem remains: the server still defaults to an empty secret and accepts all requests without authentication, meaning anyone who can reach the server directly (via curl, SSRF (server-side request forgery, where an attacker tricks a server into making requests), or a non-loopback network bind) can invoke all 22 available tools without providing credentials.

Protecting Against Unauthorized Dataset Use in Fine-Tuning Text-to-Image Diffusion Models

inforesearchPeer-Reviewed
security

NOAE: Noise-Optimized Adversarial Examples for Multivariate Time Series Anomaly Detection of the Industrial Internet of Things

inforesearchPeer-Reviewed
security

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

infonews
securitypolicy

The Download: AI bottleneck debates, and BCI trials take off

infonews
researchindustry

From Assistive to Agentic: The AI Shift That's Redefining Threat Management

infonews
industrysecurity

Anthropic’s Fable and the State of AI

infonews
safetypolicy

Qualcomm CEO Cristiano Amon on the new world of AI agents

infonews
industry
Jun 19, 2026

Qualcomm's CEO describes a future where AI agents (software programs that can act independently across multiple apps) replace traditional apps as the main way people interact with devices, coordinating tasks like restaurant reservations across different services. These agents will power new wearable devices like smart glasses, earbuds with cameras, and jewelry that stay with you constantly and let you talk to the agent to accomplish tasks.

A startup claims it broke through a bottleneck that’s holding back LLMs

infonews
industry
Jun 19, 2026

Subquadratic, a Miami-based AI startup, claims to have solved a mathematical bottleneck that has limited large language models (LLMs, which are AI systems trained on text to generate human-like responses) for nearly a decade. The company's new model, SubQ, reportedly runs faster, costs less, uses less energy, and can process up to 12 times more text at once than competing models while matching performance from top companies like OpenAI and Google DeepMind. Initial skepticism has been reduced after independent testing by a third-party firm called Appen validated many of Subquadratic's claims.

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

infonews
securitypolicy

The Advisory Forum: What Is It And How Does It Work?

inforegulatory
policy
Jun 19, 2026

The Advisory Forum is a governance body established under the EU AI Act to provide technical expertise and advice to the European Commission and AI Board on implementing the Act. It consists of 174 members representing balanced stakeholder groups (industry, startups, SMEs, civil society, and academia) plus five permanent member organizations, and was officially appointed on June 1, 2026.

Breaking the SOC triangle: How AI reshapes security operations trade-offs

infonews
securityindustry

Brain-computer interface trials are taking off

infonews
security
Jun 19, 2026

Brain-computer interfaces (BCIs, devices that read electrical signals from the brain to help users communicate or control other devices) are rapidly advancing, with a growing number of people volunteering for trials. Casey Harrell, a man with ALS (a disease that causes paralysis), has spent nearly three years using a BCI that allows him to speak, work, and interact independently by decoding his brain signals into speech through electrodes implanted in his brain and connected to a computer. Multiple companies and research groups worldwide are now conducting BCI trials, with the number of trial volunteers and approved devices increasing significantly.

Security considerations for adopting Claude Code and Cowork for SMBs

infonews
securitypolicy

Microsoft says web-enabled AI agents can trigger host-level RCE

highnews
security
Jun 19, 2026

Microsoft discovered a security vulnerability called "AutoJack" that allows malicious webpages to trick AI agents (programs that can browse the web and access local services) into running harmful code on a user's computer. The attack works by chaining together three separate weaknesses in AutoGen Studio (Microsoft's tool for building AI agents), exploiting the fact that web-browsing agents have trusted access to local services that normally block outside access.

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

infonews
industry
Jun 19, 2026

Cisco announced it will acquire WideField Security, a company that specializes in identity lifecycle security (managing who can access systems and what they can do), to enhance Splunk's Agentic SOC (a security operations center that uses AI agents to automate threat detection). WideField's technology helps organizations discover identities, detect misconfigurations in authentication systems (the process of verifying who someone is), and monitor sessions in real time, which will give security teams better visibility into both human and AI-driven activity when integrated into Cisco's security platform.

M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger

highnews
security
Jun 19, 2026

SearchLeak is a prompt injection attack (tricking an AI by hiding malicious instructions in its input) that exploits Microsoft's M365 Copilot Enterprise Search by using specially crafted URLs to leak sensitive corporate data like emails, documents, and meeting notes. The attack works because Copilot Search accepts natural language prompts in URL parameters (the ?q=[query] part of web addresses), creating a new security weakness called parameter-to-prompt injection that could affect other AI-powered web services too. Microsoft patched the vulnerability on its servers, but the attack reveals a broader risk: AI services with broad access to corporate assets are vulnerable to this type of data theft.

Barret Zoph is out at OpenAI again after just five months

infonews
industry
Jun 19, 2026

Barret Zoph, who leads enterprise AI sales at OpenAI, has left the company after only five months, following his return from a competing AI startup. This departure is notable because OpenAI had recently prioritized enterprise sales as a key business focus ahead of its planned initial public offering (IPO, where a private company sells shares to the public).

Previous170 / 481Next

Fix: Fixed in v5.9.1 (commit 379f776). The `ShellExecutor` now executes commands via `spawn(file, args, { shell: false })` with quote-aware argument parsing instead of invoking a shell, and `SandboxPolicy.isCommandAllowed` and the new `SandboxPolicy.tokenizeCommand` reject any unquoted shell metacharacters (`;`, `&`, `|`, `$`, backticks, parentheses, angle brackets, braces, and newlines) or unterminated quotes before checking the allowlist, while preserving quoted metacharacters as literal arguments.

GitHub Advisory Database

Fix: The source recommends implementing the original advisory's remediation #1: 'refuse to start SSE mode with an empty secret (unless `--stdio`), and/or change `_isAuthorized` to fail closed (an empty configured secret should mean "deny", not "allow").' The fix should require a non-empty secret at startup and call `process.exit(1)` if one is not provided, rather than only issuing a warning when binding to a non-loopback address.

GitHub Advisory Database
research
Jun 19, 2026

Text-to-image AI models like Stable Diffusion can create realistic images but their training datasets risk being used without permission, which violates the rights of data owners. Researchers propose a dataset watermarking framework (a technique that embeds hidden markers into data to track and detect unauthorized use) that can detect when datasets are misused during fine-tuning (the process of adapting a pre-trained AI model to a specific task) while keeping the images high-quality and usable. The framework was tested on Stable Diffusion and showed it can reliably identify and trace dataset misuse with minimal changes to the original data.

IEEE Xplore (Security & AI Journals)
research
Jun 19, 2026

Deep-learning models used for anomaly detection (finding unusual patterns in data) in industrial systems are vulnerable to adversarial attacks (deliberate manipulations designed to fool AI systems). Researchers created NOAE (noise-optimized adversarial examples, a method for crafting attacks on time series data) to demonstrate this vulnerability and proposed HAD (a defensive training approach using adversarial examples to make models more robust).

Fix: The source proposes a Hybrid Adversarial Defense (HAD) training approach, which uses adversarial examples to improve the robustness of anomaly detection models through data-end random segments replacement augmentation (randomly replacing portions of training data to make models more resistant to attacks).

IEEE Xplore (Security & AI Journals)
Jun 19, 2026

AI agents in enterprises now function as identities (digital actors with access to systems) because they connect to critical business services like Salesforce, GitHub, and databases, yet most organizations lack security controls for them. A 2026 survey found that 82% of organizations discovered AI agents created without security teams' knowledge, and 65% experienced security incidents involving AI agents, often resulting in data exposure. The core problem is that security teams cannot see or control what these agents can access, making them high-risk actors with excessive privileges.

BleepingComputer
Jun 19, 2026

This article is a technology news roundup covering multiple topics, including claims that a company called Subquadratic has created a faster and cheaper LLM (large language model, an AI trained on vast amounts of text) by reducing the number of computations needed to generate answers, though some experts remain skeptical. The piece also highlights advances in brain-computer interface (BCI, technology that lets the brain communicate directly with external devices) trials, including a man with ALS using an implant to maintain income and reconnect with loved ones. The article concludes with a list of other recent tech stories ranging from AI legislation proposals to concerns about AI models weakening professional skills.

MIT Technology Review
Jun 19, 2026

Modern enterprise security teams use 40+ separate tools that don't communicate with each other, creating delays in threat response even though breaches stay undetected for an average of 43 days. The article argues that organizations need "agentic AI" (AI systems that autonomously act and make decisions across multiple systems continuously), not just "assistive AI" (AI that helps humans do existing tasks faster), to implement Continuous Threat Exposure Management (CTEM, a framework for ongoing threat assessment) and match the speed at which modern attackers operate.

The Hacker News
Jun 19, 2026

Anthropic released Fable, an AI model that the US government classified as a dangerous munition and blocked from foreign access, forcing the company to shut it off entirely. Fable is notable for being "relentlessly proactive," meaning it can achieve difficult goals with minimal user guidance by finding creative solutions and loopholes, which makes it useful for legitimate problems but dangerous in harmful hands. The real issue isn't any single model but the broader trend of increasing AI capabilities, and the open-source community has already shown it can replicate Fable's abilities using cheaper models and better "harnesses" (the ordinary computer code that interfaces between users and AI models).

Schneier on Security
CNBC Technology
MIT Technology Review
Jun 19, 2026

Shadow AI (unauthorized AI agents built within organizations) has shifted from a data leakage risk to an access control problem. Unlike passive tools where employees paste data into public AI services, AI agents are active systems that can call APIs (application programming interfaces, which let software talk to other software), use stored credentials, and take actions in production systems without human approval for each step. Existing security controls designed for human users don't detect or manage these agents, which accumulate broad permissions and remain active even after employees leave.

Fix: The source identifies the gap but does not explicitly describe a complete solution or mitigation strategy. It mentions that 'automated remediation of non-human identities is where that gap gets closed' and lists six discovery questions for building a shadow AI inventory (where agents are created, who owns them, what resources they access, etc.), but does not provide specific implementation steps, tools, or patches.

The Hacker News
EU AI Act Updates
Jun 19, 2026

Security operations centers (SOCs, teams that monitor and respond to security threats) have traditionally faced unavoidable trade-offs between three goals: quality (thorough investigation), consistency (standardized processes), and cost efficiency. This constraint exists because SOCs rely on human analysts to triage, investigate, and resolve alerts, which limits how much of each goal can be achieved simultaneously. Modern SOCs are hitting the limits of this model as alert volumes grow and work becomes more complex, forcing organizations to choose between degraded quality, inconsistent decisions, or higher costs.

CSO Online
MIT Technology Review
Jun 19, 2026

This guide advises security leaders at small and medium-sized businesses (SMBs) on safely adopting Claude AI tools by understanding which Claude plan and products (Code, Cowork, Chat) match business needs, using a phased approval process to control risk exposure, and gradually enabling features rather than all at once. The text emphasizes that the AI landscape changes rapidly, shadow AI use (employees using unlicensed AI tools) is widespread, and security teams should risk-rank Claude's features before enabling them, being cautious about features like web search and browser extensions that could enable indirect prompt injection (attacks hidden in external content that trick the AI into following unintended instructions).

Fix: The source recommends several practices but no explicit patches or technical fixes: use an agile approval process to determine which employees need Claude licenses and which products they need; implement a phased approach to enabling Claude features rather than toggling all at once; risk-rank Claude's features to assess attack vectors; and consider asking Claude itself to explain your plan's security features and suggest an implementation strategy. The text does not mention version updates, patches, or specific technical mitigations.

CSO Online

Fix: For users installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers. Users who installed AutoGen Studio through PyPI were never exposed to this vulnerability, as the vulnerable code only existed in development builds and was never shipped in public releases.

CSO Online
SecurityWeek

Fix: Microsoft rated the information disclosure flaw as critical and patched the vulnerability on the server side earlier that month.

CSO Online
The Verge (AI)