aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9693 items

Amazon CEO reportedly raised Anthropic model concerns before government crackdown

infonews
securitypolicy
Jun 13, 2026

Amazon CEO Andy Jassy reportedly told U.S. government officials that researchers discovered security vulnerabilities in Anthropic's Claude models that could be exploited for cyberattacks, leading the government to ban exports of two models (Fable 5 and Mythos 5). Anthropic subsequently cut off worldwide access to these models, though the company stated that the concerning capabilities were already available in other public models.

TechCrunch (Security)

My yard is dying, so I made an app for that

infonews
industry
Jun 13, 2026

A user prompted Google's Gemini AI to build a functional app in a single request, and the AI generated working code in a preview window. However, Gemini encountered a bug (a race condition, which is when the order of operations in code causes unexpected behavior) and reported a broken channel, though it provided a button to fix the issue, which succeeded after 233 seconds.

Anthropic cuts off Fable 5 and Mythos 5 access following government order

infonews
securitypolicy

Anthropic to disable its most advanced AI models after US order limiting foreign access

infonews
policysecurity

The future of Hollywood isn’t feeding prompts into vanilla gen AI models 

infonews
industry
Jun 13, 2026

Despite excitement about generative AI transforming filmmaking, current AI video models can only produce short clips with inconsistent visuals, and several major Hollywood-AI partnerships have ended, suggesting studios cannot yet depend on this technology for professional entertainment products.

US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos

infonews
securitypolicy

Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

infonews
policy
Jun 13, 2026

Anthropic took its latest AI models, Fable 5 and Mythos 5, offline after receiving a directive from the U.S. government to comply with new export controls (restrictions on who can access advanced technology) that prevent foreign nationals from using them. The company disagreed with how the government handled the order, saying it lacked transparency and technical justification, and expressed hope to restore access soon.

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

infonews
safetypolicy

Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive

infonews
policy
Jun 12, 2026

Anthropic disabled access to its Fable 5 and Mythos 5 AI models after receiving a U.S. government order citing national security concerns and export control restrictions, preventing foreign nationals from using them whether inside or outside the United States. The company immediately suspended the models for all customers to ensure compliance, though other Anthropic models remain available. Anthropic stated the government did not provide specific details about the security concern and said the action did not follow transparent or fair procedures.

OpenAI says it's engaging 'constructively' with state AGs about concerns

inforegulatory
policysafety

Uncovering robot joint-level controller actions from encrypted network traffic: Empirical attacks and information-theoretic bounds

inforesearchPeer-Reviewed
security

OpenAI WebRTC Audio Session, now with document context

infonews
industry
Jun 12, 2026

OpenAI released a new model called GPT-Realtime-2 for their WebRTC API (a protocol for real-time audio communication in web browsers), which offers improved reasoning capabilities with knowledge through September 2024. A developer updated their audio conversation tool to support this new model and added the ability to paste document context, allowing users to have voice conversations in their browser about custom information.

CVE-2026-42853: ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and

mediumvulnerability
security
Jun 12, 2026
CVE-2026-42853

ApostropheCMS versions up to 3.6.0 contain a command injection vulnerability (CWE-78, a weakness where user input is directly used in system commands without cleaning) in the @apostrophecms/cli package's apos create command. An attacker can input malicious commands through the password prompt that will execute on the host system because the input is not properly sanitized (cleaned of dangerous characters) before being used in a shell command.

CVE-2026-50287: AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a

highvulnerability
security
Jun 12, 2026
CVE-2026-50287

AgenticMail, a tool that allows AI agents to access email and phone services, has a security flaw in versions before 0.9.27 where the /mcp endpoint (a communication interface) accepts requests without requiring authentication (verification of identity) when started in HTTP mode. This means a remote attacker could connect to the service and use its tools directly to access real email addresses and phone numbers.

GHSA-p5j5-4j3q-8mq8: TYPO3 HTML Sanitizer allows Cross-site Scripting

mediumvulnerability
security
Jun 12, 2026
CVE-2026-47345

This item describes TYPO3 HTML Sanitizer (a tool that removes potentially dangerous code from HTML), which has a Cross-site Scripting vulnerability (XSS, where attackers inject malicious scripts into web pages). The content provided explains the framework for measuring vulnerability severity through metrics like attack vector, complexity, and impact, but does not describe the actual vulnerability details or its fix.

CVE-2026-47138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

highvulnerability
security
Jun 12, 2026
CVE-2026-47138

Parse Server, an open source backend framework that runs on Node.js, has a vulnerability where attackers can send specially crafted HTTP requests that cause the server to spend seconds or minutes processing a single request before checking user permissions or rate limits. An attacker only needs to know the application's public ID and can overload the server by sending a few concurrent requests or one large request, making it slow or unresponsive for legitimate users.

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

highnews
security
Jun 12, 2026

Google is suing a Chinese cybercrime network called Outsider that uses Gemini (Google's AI agent) to create phishing pages and send smishing attacks (fraudulent text messages impersonating trusted brands to steal personal and financial information). The network sells access to its phishing-as-a-service (PhaaS, a software tool that makes it easy for criminals to launch phishing campaigns) for as little as $88 per week, and has victimized over 100,000 people with millions in losses.

GHSA-cv96-5348-p5p8: Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

mediumvulnerability
security
Jun 12, 2026
CVE-2026-48148

Budibase's VectorDB configuration endpoint accepts a host parameter with no validation, allowing any authenticated builder-level user to make the server connect to internal IP addresses or cloud metadata endpoints (like AWS's 169.254.169.254). This is an SSRF vulnerability (server-side request forgery, where a server is tricked into making requests to unintended destinations), enabling attackers to scan internal networks, discover running services, and potentially steal cloud credentials.

The AI Your Security Team Can’t See Is the One You Should Worry About

infonews
securitypolicy

CVE-2026-8828: A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users

highvulnerability
security
Jun 12, 2026
CVE-2026-8828

ChromaDB Rust (version 1.0.0 and later) has a security flaw where authorization validation (checking whether a user has permission to access data) is missing, allowing any logged-in user to read, write, update, or delete data from any tenant's collection (a storage area for data), even if they shouldn't have access to it. This is rated as HIGH severity with a CVSS score (a 0-10 rating of how severe a vulnerability is) of 8.8.

Previous183 / 485Next
The Verge (AI)
Jun 13, 2026

The U.S. government ordered Anthropic to block access to two AI models called Fable 5 and Mythos 5 due to unspecified national security concerns, and the company complied by cutting off access for all users worldwide, including its own employees. Anthropic stated that the government did not provide detailed information about the security threat and only mentioned potential jailbreak (tricks to make the AI ignore its safety instructions) vulnerabilities verbally, which the company claims were minor.

The Verge (AI)
Jun 13, 2026

Anthropic will disable its most advanced AI models (Fable 5 and Mythos 5) for all users after the US government ordered the company to stop letting foreign nationals access them, citing national security concerns. The US government believes the safeguards protecting these models can be bypassed and the models could be used to identify software vulnerabilities, though Anthropic was not given specific details about the security concern.

The Guardian Technology
The Verge (AI)
Jun 13, 2026

The US government issued an export control directive requiring Anthropic to block access to its two most advanced AI models, Fable 5 and Mythos 5, for all foreign nationals worldwide, citing national security concerns. Anthropic complied by suspending these models for all users globally, though the company disputes the government's reasoning, which appears related to a reported jailbreak (a method to bypass the model's safety restrictions) that Anthropic says it reviewed and found to be minor and not unique to their system.

Fix: Anthropic states in its developer notice that 'new sessions would fall back to a user's default model or Opus 4.8, existing Fable 5 sessions would end with an error, and Platform requests to Fable 5 would also fail' and told integrators to 'migrate to other models.' The company also says it is 'working to restore access' to these models and promised 'more details within 24 hours,' though no specific technical fix or timeline for restoration is provided in the source text.

BleepingComputer
SecurityWeek
Jun 13, 2026

The U.S. government ordered Anthropic to suspend access to its advanced AI models Claude Fable 5 and Mythos 5 for all foreign nationals due to national security concerns, citing a discovered method of bypassing (jailbreaking, or tricking the AI's safety rules) these models. Anthropic disputed the order, arguing that the vulnerabilities identified are minor and already known, that its safety systems are robust, and that perfect jailbreak resistance is impossible for any AI company.

The Hacker News
CNBC Technology
Jun 12, 2026

OpenAI says it will work constructively with state attorneys general who are investigating the company over concerns about advertising, data handling, and potential harms to minors and seniors. The investigation comes amid multiple lawsuits against OpenAI, including cases where families allege ChatGPT (a conversational AI chatbot) was misused to cause harm, and as the company prepares for a public stock offering.

Fix: OpenAI stated that 'Today's ChatGPT includes a more protective experience for minors and people experiencing difficult situations, with safeguards that direct them to real-world resources and trusted human contacts.' No specific version numbers or technical implementation details are provided in the source.

CNBC Technology
Jun 12, 2026

Researchers discovered that they can figure out what actions industrial robots are performing just by analyzing encrypted network traffic (data traveling across networks in scrambled form) without being able to read the actual messages. The study shows both practical attacks that successfully identified robot movements and theoretical limits on how much information can be extracted from this type of traffic. This reveals a security gap where encryption alone may not fully protect sensitive robot operations from being monitored.

Elsevier Security Journals
Simon Willison's Weblog
NVD/CVE Database

Fix: This issue has been patched in version 0.9.27.

NVD/CVE Database
GitHub Advisory Database

Fix: Update Parse Server to version 8.6.77 or 9.9.1-alpha.1 or later, as this issue has been patched in these versions.

NVD/CVE Database

Fix: Google is filing a lawsuit to dismantle the network's infrastructure and partnering with AT&T, T-Mobile, and Verizon to block phishing messages from reaching customers.

The Hacker News
GitHub Advisory Database
Jun 12, 2026

Shadow AI (AI tools used by employees without IT approval or visibility) is becoming a major security risk because employees adopt AI faster than security teams can track, often on devices that traditional security tools can't monitor. Most organizations cannot see how many AI tools are in use, where they're being used, or what data is being shared with them, creating a dangerous gap between employee activity and security oversight.

Check Point Research
NVD/CVE Database