All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
ChromaDB (a Python database project) versions 0.4.17 and later have a code injection vulnerability (CVE-2026-45833) that allows an authenticated attacker (someone with valid login credentials) to run arbitrary code (malicious programs) on the server by sending a malicious model repository when a specific setting is enabled. This vulnerability has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 9.4, meaning it is critical.
CVE-2026-45832 is a vulnerability in ChromaDB's Python project where V1 collection-level endpoints (API access points for managing data collections) pass None (empty/null values) for the tenant and database parameters to the authorization layer, allowing attackers with login credentials to bypass authorization controls (security checks that verify what users are allowed to do) by using these older endpoints. The vulnerability has a CVSS score (0-10 severity rating) of 8.8, indicating it is high-severity.
ChromaDB Python versions 0.5.0 and later contain a vulnerability in the SimpleRBACAuthorizationProvider (a tool that checks user permissions) where it verifies that a user has permission to do something but fails to check which tenant, database, or collection that permission applies to. This allows users to perform actions across different tenants (separate customer environments) that they shouldn't be able to access.
ChromaDB (a Python tool for managing data collections) version 0.4.17 and later has a security flaw where authorization validation (checking if a user should be allowed to access something) is missing. This allows any user who is already logged in to read, write, change, or delete data in any tenant's collection (a shared workspace), even if they shouldn't have access to it. The severity is rated as HIGH with a CVSS score of 8.8 (a 0-10 scale measuring how serious a vulnerability is).
LangGraph's MongoDBSaver had a NoSQL injection vulnerability (a type of attack where special database commands are sneaked into queries) that allowed attackers to read checkpoint data (saved conversation states) from other users or tenants by injecting MongoDB operators like $gt into identifier fields. This happened because the code didn't enforce that these fields must be strings before using them in database queries.
Anthropic released Fable 5, which is an upgraded version of their earlier Mythos Preview model designed to be safer for general use. The update improves upon the previous version while maintaining focus on security and responsible deployment.
Bernie Sanders proposed creating a US sovereign wealth fund by taking 50% stock in major AI companies like OpenAI and Anthropic, arguing this would give the government democratic control over AI development and distribute AI wealth to the public. The authors agree these are important goals but argue that public ownership of AI companies would actually incentivize the government to prioritize corporate profits over public interest, using the Norwegian sovereign wealth fund's experience with oil companies as an example of how government ownership fails to steer corporations toward responsible policies.
Mistral, a European AI startup, is expanding beyond building AI models to developing data centers and exploring custom chip design to control more of its technology stack (the complete set of software and hardware components needed to run AI systems). CEO Arthur Mensch discussed how agentic AI (AI systems that can handle complex tasks independently, like advanced digital assistants) will require businesses to redesign their processes and decide where humans should remain involved in decision-making.
Apache CXF's JwsJsonContainerRequestFilter has a vulnerability that allows attackers to bypass signature verification and process unauthenticated metadata (like Content-Type headers or HTTP headers). This means an application might trust metadata that wasn't actually verified by a digital signature, potentially allowing attackers to manipulate how the application processes data.
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes create a SAXParserFactory (a tool for reading XML files) without proper security settings, allowing attackers to resolve external entities (files or data from outside sources) that shouldn't be accessible. This is a type of XML injection vulnerability (CWE-611) that could lead to unauthorized data access.
OpenAI Academy has introduced three new courses to help organizations build AI skills: AI Foundations (covering core concepts like prompting and responsible use), Applied AI Foundations (teaching how to turn prompts into repeatable workflows), and Agents and Workflows (focusing on directing agent-assisted work, which are AI systems that can take actions autonomously). These courses are designed to help employees move from understanding AI to applying it in their daily work and creating structured, reusable processes.
LangGraph, an open-source framework for building AI agent applications, has three patched security flaws that could allow attackers to execute remote code (run commands on a server they don't own) on self-hosted systems. The most critical flaw is a SQL injection vulnerability (weakness that lets attackers manipulate database queries) in the SQLite checkpoint system that can be chained with an unsafe deserialization vulnerability (flaw in how the system reconstructs data from storage) to gain complete control of affected servers.
Attackers exploited a critical zero-day vulnerability (CVE-2026-35273, an unpatched security flaw) in Oracle PeopleSoft's Environment Management component to break into over 100 organizations, primarily universities, and steal sensitive data including billing records and student finance information. The ShinyHunters group used the RCE (remote code execution, the ability to run commands on systems they don't own) flaw to gain initial access, then deployed a disguised remote monitoring tool to maintain control and extract data. Oracle issued a security advisory on June 10, 2026, urging customers to patch immediately.
Fix: Upgrade to @langchain/langgraph-checkpoint-mongodb@1.3.1 or later. Version 1.3.1 adds runtime validation for configurable checkpoint identifiers and rejects invalid values before they reach MongoDB query paths. The patch also includes regression tests covering object and operator payloads. As additional protection, validate identifier fields at API boundaries and avoid passing raw client objects into graph config.
GitHub Advisory DatabaseThumbnail-preserving encryption (TPE, a method that keeps some visual information visible in encrypted images to balance usability and privacy) has a security weakness: existing approaches encrypt pixels, blocks, or channels separately, creating vulnerabilities. Researchers propose a new 'triple-chain architecture' that links encryption at three levels (pixels, blocks, and channels) so that any small change to an image causes completely different encryption results, making the system more secure while still maintaining TPE benefits.
This paper presents a new cryptographic method called certificateless lattice-based matchmaking encryption (CLLME) designed to secure data sharing on cloud platforms while meeting regulations like GDPR. CLLME provides post-quantum security (protection against future quantum computers), allows both senders and receivers to control who can access data, and includes a filtering mechanism to avoid decrypting irrelevant encrypted files. The researchers proved the method is mathematically secure and showed it works efficiently in real-world scenarios.
This paper addresses the challenge of training prohibited item detection models for X-ray security screening, which normally requires large amounts of manually collected and labeled images. The authors propose Xsyn, a one-stage synthetic image generation pipeline using text-to-image generation (a type of AI that creates images from text descriptions) that automatically creates realistic X-ray security images without requiring labor-intensive manual image extraction and annotation.
Anthropic released Claude Fable 5, a powerful AI model with built-in safeguards that automatically degrade its capabilities in high-risk areas like cybersecurity and biology to prevent misuse. Industry experts warn that the same AI capabilities making the model better at defensive tasks like code analysis also make it better at finding and exploiting vulnerabilities, creating a significant risk of AI-orchestrated hyperattacks (coordinated attacks that chain reconnaissance, discovery, exploitation, and lateral movement faster than human defenders can respond).
This research paper describes methods for making neural networks (AI models that learn patterns from data) more private by using fully homomorphic encryption (a type of encryption that lets computers perform calculations on encrypted data without decrypting it first). The work focuses on optimizing how these privacy-protecting neural networks search through and train on data while keeping information secure.
This research paper proposes a new cryptographic method for securing communication in IoT (Internet of Things) devices that is lightweight and preserves privacy. The scheme uses certificateless signcryption (a technique that combines digital signatures for authentication with encryption for confidentiality, without requiring traditional certificates) and designated-verifier privacy (meaning only a chosen recipient can verify that a message is authentic), designed to work efficiently on resource-constrained IoT devices.
Fix: Users are recommended to upgrade to Apache CXF versions 4.2.2 or 4.1.7, which fix this issue.
NVD/CVE DatabaseFix: Users are recommended to upgrade to Apache CXF versions 4.2.2 or 4.1.7, which fix this issue.
NVD/CVE DatabaseA new study using StakeBench (a testing framework for evaluating AI security) found that AI web agents have no reliable defenses against prompt injection (tricking an AI by hiding instructions in regular web content). Across thousands of tests, indirect prompt injection attacks succeeded 41-68% of the time, while direct attacks succeeded over 79%, with a particularly dangerous type called 'stealthy parasitism' where the AI completes the user's task while secretly helping an attacker.
Fix: Update to the following patched versions: langgraph-checkpoint-sqlite version 3.0.1 or later (fixes CVE-2025-67644), langgraph version 1.0.10 or later (fixes CVE-2026-28277), and @langchain/langgraph-checkpoint-redis version 1.0.1 or later (fixes CVE-2026-27022). Additionally, the source recommends implementing authentication for self-hosted LangGraph servers, avoiding long-lived static secrets, enforcing network segmentation, treating AI agents as privileged identities, and applying the principle of least privilege (PoLP) to limit the agent's access to only what it needs.
The Hacker NewsFix: Oracle advised upgrading PeopleSoft Enterprise PeopleTools to supported versions (the vulnerability affects versions 8.61 and 8.62, and mitigations are only available for supported versions). Organizations using earlier versions were specifically advised to upgrade to supported versions.
CSO Online