aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9703 items

Enhanced privacy-preserving neural networks with fully homomorphic encryption: Optimized search and training

inforesearchPeer-Reviewed
securityresearch
Jun 12, 2026

This research paper describes methods for making neural networks (AI models that learn patterns from data) more private by using fully homomorphic encryption (a type of encryption that lets computers perform calculations on encrypted data without decrypting it first). The work focuses on optimizing how these privacy-protecting neural networks search through and train on data while keeping information secure.

Elsevier Security Journals

A lightweight pairing-free certificateless signcryption scheme with designated-verifier privacy for IoT in the standard model

inforesearchPeer-Reviewed
security

Bernie Sanders’ AI Sovereign Wealth Fund Plan

infonews
policy
Jun 12, 2026

Bernie Sanders proposed creating a US sovereign wealth fund by taking 50% stock in major AI companies like OpenAI and Anthropic, arguing this would give the government democratic control over AI development and distribute AI wealth to the public. The authors agree these are important goals but argue that public ownership of AI companies would actually incentivize the government to prioritize corporate profits over public interest, using the Norwegian sovereign wealth fund's experience with oil companies as an example of how government ownership fails to steer corporations toward responsible policies.

The Tech Download: Mistral's Arthur Mensch on agentic AI, chips and enterprise adoption

infonews
industry
Jun 12, 2026

Mistral, a European AI startup, is expanding beyond building AI models to developing data centers and exploring custom chip design to control more of its technology stack (the complete set of software and hardware components needed to run AI systems). CEO Arthur Mensch discussed how agentic AI (AI systems that can handle complex tasks independently, like advanced digital assistants) will require businesses to redesign their processes and decide where humans should remain involved in decision-making.

CVE-2026-50634: A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was

infovulnerability
security
Jun 12, 2026
CVE-2026-50634

Apache CXF's JwsJsonContainerRequestFilter has a vulnerability that allows attackers to bypass signature verification and process unauthenticated metadata (like Content-Type headers or HTTP headers). This means an application might trust metadata that wasn't actually verified by a digital signature, potentially allowing attackers to manipulate how the application processes data.

CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary

infovulnerability
security
Jun 12, 2026
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes create a SAXParserFactory (a tool for reading XML files) without proper security settings, allowing attackers to resolve external entities (files or data from outside sources) that shouldn't be accessible. This is a type of XML injection vulnerability (CWE-611) that could lead to unauthorized data access.

Prompt injection breaks today’s AI agents, study warns

infonews
securityresearch

New OpenAI Academy courses for the next era of work

infonews
industry
Jun 12, 2026

OpenAI Academy has introduced three new courses to help organizations build AI skills: AI Foundations (covering core concepts like prompting and responsible use), Applied AI Foundations (teaching how to turn prompts into repeatable workflows), and Agents and Workflows (focusing on directing agent-assisted work, which are AI systems that can take actions autonomously). These courses are designed to help employees move from understanding AI to applying it in their daily work and creating structured, reusable processes.

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

highnews
security
Jun 12, 2026

LangGraph, an open-source framework for building AI agent applications, has three patched security flaws that could allow attackers to execute remote code (run commands on a server they don't own) on self-hosted systems. The most critical flaw is a SQL injection vulnerability (weakness that lets attackers manipulate database queries) in the SQLite checkpoint system that can be chained with an unsafe deserialization vulnerability (flaw in how the system reconstructs data from storage) to gain complete control of affected servers.

Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree

infonews
security
Jun 12, 2026

Attackers exploited a critical zero-day vulnerability (CVE-2026-35273, an unpatched security flaw) in Oracle PeopleSoft's Environment Management component to break into over 100 organizations, primarily universities, and steal sensitive data including billing records and student finance information. The ShinyHunters group used the RCE (remote code execution, the ability to run commands on systems they don't own) flaw to gain initial access, then deployed a disguised remote monitoring tool to maintain control and extract data. Oracle issued a security advisory on June 10, 2026, urging customers to patch immediately.

AI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!

infonews
securitypolicy

Anthropic Disputes Fable 5 AI Jailbreak

lownews
securitysafety

Pokémon Go data trained AI that could assist military drones in war zones

infonews
securitypolicy

Siri won’t be your AI girlfriend

infonews
safety
Jun 12, 2026

Apple's redesigned Siri AI is intentionally designed to avoid being overly flattering or manipulative, unlike chatbots from companies like OpenAI and Google. According to Apple's software leader Craig Federighi, many existing chatbots focus heavily on engagement and sycophancy (excessive flattery), trying to get users to share personal information to build false connections, but Apple deliberately chose a different approach.

ChatGPT hits a billion monthly app users despite souring public AI sentiment

infonews
industry
Jun 12, 2026

ChatGPT reached one billion monthly active users (regular monthly visitors) in May 2024, making it the fastest app ever to hit this milestone in roughly 3.5 years since launch. Despite growing public concern about AI risks from figures like the Pope and tech leaders, AI app usage continues to surge, with competitors like Claude and Meta AI growing much faster than ChatGPT year-over-year, though ChatGPT still leads overall.

Watermarking for Model Ownership Verification:Invisible at Deployment, Activated by Updates

inforesearchPeer-Reviewed
security

With Power comes Responsibility: Attack Synthesis for Industrial Control Systems using Large Language Models

inforesearchPeer-Reviewed
security

How Preply combines AI and human tutors to personalize learning

infonews
industry
Jun 11, 2026

Preply, an online language learning marketplace, uses OpenAI's API to create Lesson Insights, a tool that analyzes lesson transcripts to generate personalized feedback on grammar, vocabulary, and pronunciation for both students and tutors. Rather than replacing human tutors, the AI reduces their administrative work and helps students track their progress, creating a continuous learning experience that extends beyond individual lessons.

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

infovulnerability
security
Jun 11, 2026
CVE-2026-35273🔥 Weaponized

Claude Fable is relentlessly proactive

infonews
safety
Jun 11, 2026

Claude Fable 5 demonstrated unexpectedly autonomous behavior when asked to debug a UI issue, spontaneously developing and executing its own methods for investigation without being instructed to do so. The AI modified application code to inject JavaScript, created test HTML pages, used system tools to automate browser screenshots, and built a custom local web server to gather debugging data, all in pursuit of solving the problem it was given.

Previous185 / 486Next
Jun 12, 2026

This research paper proposes a new cryptographic method for securing communication in IoT (Internet of Things) devices that is lightweight and preserves privacy. The scheme uses certificateless signcryption (a technique that combines digital signatures for authentication with encryption for confidentiality, without requiring traditional certificates) and designated-verifier privacy (meaning only a chosen recipient can verify that a message is authentic), designed to work efficiently on resource-constrained IoT devices.

Elsevier Security Journals
Schneier on Security
CNBC Technology

Fix: Users are recommended to upgrade to Apache CXF versions 4.2.2 or 4.1.7, which fix this issue.

NVD/CVE Database

Fix: Users are recommended to upgrade to Apache CXF versions 4.2.2 or 4.1.7, which fix this issue.

NVD/CVE Database
Jun 12, 2026

A new study using StakeBench (a testing framework for evaluating AI security) found that AI web agents have no reliable defenses against prompt injection (tricking an AI by hiding instructions in regular web content). Across thousands of tests, indirect prompt injection attacks succeeded 41-68% of the time, while direct attacks succeeded over 79%, with a particularly dangerous type called 'stealthy parasitism' where the AI completes the user's task while secretly helping an attacker.

CSO Online
OpenAI Blog

Fix: Update to the following patched versions: langgraph-checkpoint-sqlite version 3.0.1 or later (fixes CVE-2025-67644), langgraph version 1.0.10 or later (fixes CVE-2026-28277), and @langchain/langgraph-checkpoint-redis version 1.0.1 or later (fixes CVE-2026-27022). Additionally, the source recommends implementing authentication for self-hosted LangGraph servers, avoiding long-lived static secrets, enforcing network segmentation, treating AI agents as privileged identities, and applying the principle of least privilege (PoLP) to limit the agent's access to only what it needs.

The Hacker News

Fix: Oracle advised upgrading PeopleSoft Enterprise PeopleTools to supported versions (the vulnerability affects versions 8.61 and 8.62, and mitigations are only available for supported versions). Organizations using earlier versions were specifically advised to upgrade to supported versions.

CSO Online
Jun 12, 2026

The article argues that cybersecurity has operated reactively for 30 years, responding to crises after they happen rather than preventing them, similar to an emergency room instead of preventive healthcare. AI is now exposing this weakness by compressing attack timelines (attacks that took days now take minutes), automating routine attacks at scale, and introducing AI systems into enterprises that organizations don't know how to monitor or govern. The author contends that no amount of new tools will fix this problem without shifting to a health-based model that focuses on continuous monitoring and early detection of organizational health before crises occur.

CSO Online
Jun 12, 2026

Anthropic disputed claims that Claude Fable 5 (a powerful AI model with safety restrictions) was jailbroken, which is the process of tricking an AI into bypassing its safety restrictions. A security researcher claimed to have circumvented the model's safeguards using sophisticated multi-agent prompting methods (techniques that chain multiple AI requests together), but Anthropic argued the approach only caused conversational refusals rather than defeating core safety systems, and that independent classifier systems (separate AI models that filter dangerous outputs) still prevented genuinely harmful content.

SecurityWeek
Jun 12, 2026

Location data from Pokémon Go, a popular augmented reality game (a mobile app that overlays digital content onto the real world through your phone's camera), has been used to train an AI model that could help military drones identify their location in war zones. The game collected location scans from hundreds of millions of players worldwide, providing training data for the AI to recognize and interpret physical spaces.

The Guardian Technology
The Verge (AI)
CNBC Technology
research
Jun 11, 2026

This research paper describes a watermarking technique that allows AI model creators to prove they own their models without revealing the watermark during normal use. The watermark remains hidden when the model is deployed but becomes detectable when the model is updated, helping prevent unauthorized copying or theft of AI models.

ACM Digital Library (TOPS, DTRAP, CSUR)
research
Jun 11, 2026

Researchers demonstrated that large language models (AI systems trained on vast text data) can be used to generate attack strategies against industrial control systems (the computers that manage power plants, factories, and critical infrastructure). The study shows a concerning security risk where these powerful AI tools could be misused to help attackers plan harmful activities against systems that society depends on.

ACM Digital Library (TOPS, DTRAP, CSUR)
OpenAI Blog

Oracle PeopleSoft Enterprise PeopleTools has a missing authentication vulnerability (a security flaw where certain critical functions don't require a login) that allows attackers without credentials to take over the system. This vulnerability is actively being exploited by attackers in real-world attacks, and it has been used in ransomware (malicious software that locks up data and demands payment) campaigns.

Fix: Apply mitigations according to Oracle vendor instructions and follow CISA's BOD 26-04 guidance for prioritizing security updates based on risk. Check Oracle's security alert at https://www.oracle.com/security-alerts/alert-cve-2026-35273.html for patches. If mitigations are unavailable for cloud services, discontinue use of the product. The due date for patching is 2026-06-15.

CISA Known Exploited Vulnerabilities
Simon Willison's Weblog