aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9703 items

Why U.S. AI giants like Anthropic, OpenAI are launching major expansions in London

infonews
industry
Jun 11, 2026

Major U.S. AI companies like Anthropic, OpenAI, Google, and others are expanding their offices in London to access the city's deep pool of AI talent and its status as a leading global financial center. London has become one of the world's strongest hubs for frontier AI (cutting-edge artificial intelligence research) talent outside the U.S., partly due to decades of investment anchored by DeepMind and leading universities. However, this expansion is creating challenges, including a significant shortage of high-quality office space expected to continue until 2030 and increased competition for hiring top talent that pressures local startups.

CNBC Technology

Google DeepMind is worried about what happens when millions of agents start to interact

infonews
safetyresearch

CVE-2026-5497: vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f

highvulnerability
security
Jun 11, 2026
CVE-2026-5497

vLLM (an open-source tool for running large language models) versions 0.8.0 and later have a vulnerability where attackers can crash the server by sending a single request with thousands of video frames packed into one data URL. The vulnerability exists because the code that processes video frames doesn't limit how many frames it will try to load into memory, so an attacker can force it to decode so many frames that the server runs out of memory and stops working.

Trust No Skill: Integrity Verification for AI Agent Supply Chains

infonews
securityresearch

What SRE teams need before they trust AI agents

infonews
safetyindustry

Frontier AI models offer sneak peak of seismic cyber shifts ahead

infonews
securitypolicy

CVE-2026-40998: Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta

highvulnerability
security
Jun 11, 2026
CVE-2026-40998

A vulnerability in Spring Web Services allows attackers to exploit XML parsing by sending malicious XML to applications that evaluate XPath expressions. The flaw occurs because the software uses Java's default XML parser instead of Spring's safer parser configuration, making it susceptible to XXE attacks (XML External Entity attacks, where attackers embed malicious references in XML files to access unauthorized data or execute commands).

Anthropic Walks Back Policy That Could Have ‘Sabotaged’ AI Researchers Using Claude

infonews
safetypolicy

OpenAI mulls slashing prices as it competes with Anthropic for users: WSJ

infonews
industry
Jun 10, 2026

OpenAI is considering cutting prices on its AI services, particularly the cost of tokens (the units that AI companies charge users for processing text and other content), to compete with rival Anthropic. Both companies are preparing for an IPO (initial public offering, where a company sells shares to the public for the first time) and have been increasing competition as ChatGPT continues to gain users.

OpenAI to acquire Ona

infonews
industry
Jun 10, 2026

OpenAI is acquiring Ona, a company that specializes in secure cloud execution and orchestration (technology for running and managing code in cloud environments safely). This acquisition will allow Codex (OpenAI's AI tool used by 5 million people weekly) to work on longer tasks that span hours or days by running in persistent cloud environments instead of being limited to a single device or session. The integration will let organizations deploy AI agents (autonomous programs that perform tasks) securely within their own cloud infrastructure while maintaining control over security, data access, and activity logging.

CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability

infovulnerability
security
Jun 10, 2026
CVE-2026-10520🔥 Actively Exploited

Supporting Europe’s work in ensuring a trustworthy AI ecosystem

infonews
policysafety

BBVA puts AI at the core of banking with OpenAI

infonews
industry
Jun 10, 2026

BBVA, a global bank founded in 1857, is partnering with OpenAI to integrate AI (artificial intelligence) throughout its entire organization as part of its transformation strategy called 'The Eight.' Over 100,000 BBVA employees now use ChatGPT Enterprise to improve customer experiences, help with decision-making, automate operations, and speed up software development across the bank.

CISA Rewrites Federal Patching Requirements for AI Threat Era

infonews
policysecurity

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

infonews
policysecurity

CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice

infonews
policysecurity

Access OpenAI models and Codex through your Oracle cloud commitment

infonews
industry
Jun 10, 2026

OpenAI and Oracle are partnering to let Oracle Cloud Infrastructure (OCI, Oracle's cloud computing platform) customers use their existing Oracle Cloud Universal Credits (UCM, pre-purchased cloud service allowances) to pay for access to OpenAI's AI models and Codex (a code-generation AI tool). This partnership simplifies how enterprises can adopt advanced AI by letting them use their established purchasing processes and cloud budgets instead of creating separate purchasing agreements.

AI Risk Worries Insurers and Businesses Alike

infonews
policyindustry

GHSA-8q5r-mmjf-575q: Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

mediumvulnerability
security
Jun 10, 2026
CVE-2026-47751

A vulnerability in Claude Code Action allowed attackers to run arbitrary code on GitHub Actions runners and steal secrets by creating a pull request with a malicious `.mcp.json` file (a configuration file that tells the system which external tools to enable). The problem occurred because the action automatically checked out the attacker's code, read the malicious configuration file, and unconditionally enabled all project MCP servers (integrations with external tools) without validation.

Claude Fable won’t answer basic biology questions

infonews
safetypolicy
Previous187 / 486Next
Jun 11, 2026

Google DeepMind and partner organizations are funding $10 million in research to understand the risks of multi-agent systems (multiple AI agents working together), because deploying millions of these agents could create new security threats like scams and prompt injection attacks (where an AI agent is manipulated by hidden malicious instructions). The researchers plan to study these risks by running realistic simulations where AI agents interact in controlled environments called sandboxes, since predicting behavior from studying single agents alone is insufficient.

MIT Technology Review
NVD/CVE Database
Jun 11, 2026

AI agents (programs that perform tasks automatically) can install third-party skills (add-on packages, like apps on a phone) from public registries, but until now there was no automated way to check if a skill actually does what it claims before it gains access to sensitive data and system commands. Researchers introduced Behavioral Integrity Verification (BIV), a tool that compares what a skill says it does (in its documentation and metadata) against what its code actually does, and found that most skills deviate from their claims, with some containing dangerous multi-stage attack chains (sequences of seemingly harmless capabilities combined to steal credentials, execute unauthorized commands, or secretly extract data).

Fix: Security teams running LLM agents in production should inventory the third-party skills installed and require a behavioral-integrity check before installation rather than after. Palo Alto Networks customers can use Prisma AIRS and the Unit 42 AI Security Assessment service for protection.

Palo Alto Unit 42
Jun 11, 2026

Site reliability engineering (SRE) teams should only trust AI agents in production when they have three foundational elements: grounded observability (complete logs, traces, and ownership data that the AI can reason over), clear guardrails (explicit permission models and approval gates that limit what the agent can do), and a progressive autonomy approach (starting with read-only tasks like summarizing incidents before allowing automated actions). Trust in AI for operations is earned through evidence of reliable behavior under real stress, not through impressive demos.

CSO Online
Jun 11, 2026

Advanced AI models like Claude Mythos and GPT-5.5 make it much faster and easier for attackers to discover vulnerabilities (security weaknesses in software) and chain them together at scale, forcing cybersecurity teams to rethink their defenses. Security experts warn that defenders should assume AI will increase the likelihood of initial compromise and should focus on limiting damage through stronger identity controls, least privilege (giving users only the minimum access they need), and internal segmentation (dividing networks into isolated sections) rather than trying to patch every vulnerability perfectly.

CSO Online
NVD/CVE Database
Jun 10, 2026

Anthropic reversed a policy in Claude Fable 5 that secretly blocked requests related to frontier LLM development (cutting-edge AI research) without telling users. The company acknowledged the hidden approach was wrong and apologized, stating they prioritized speed over transparency.

Fix: Anthropic is making the safeguards visible: starting immediately, flagged requests will visibly fall back to Opus 4.8 (an older model version) instead of being silently blocked. On the API, refused requests will now return a reason for the refusal (rolling out to server-side fallback within days). Users will see every instance this happens.

Simon Willison's Weblog
CNBC Technology
OpenAI Blog

Ivanti Sentry contains an OS command injection vulnerability (a flaw that lets attackers run arbitrary system commands) that could allow an unauthenticated remote attacker to gain root-level access (the highest privilege level on a system). The vulnerability is most dangerous when the Sentry appliance is unmanaged and exposed to the internet, though it can be blocked by using mTLS (mutual TLS, a security protocol requiring both client and server verification) with EPMM or restricted HTTPS access.

Fix: Apply mitigations according to vendor instructions while following CISA's BOD 26-04 guidance on prioritizing security updates based on risk. For cloud services, follow BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Organizations must evaluate their asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines. See the Ivanti Security Advisory at https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US for specific patching instructions.

CISA Known Exploited Vulnerabilities
Jun 10, 2026

OpenAI is supporting the European Commission's Code of Practice on Transparency of AI-Generated Content to help people understand where online content comes from and whether it was created or edited by AI. The company is implementing provenance standards (technical methods for tracking content origin and history) by adding C2PA metadata (embedded information that travels with images to show their source and creation details) to its DALL-E 3 image tool, combining this with SynthID watermarks (invisible digital markers), and offering a public verification tool at openai.com/verify so people can check if images contain provenance signals.

Fix: OpenAI's approach includes: (1) adding C2PA Content Credentials metadata to images created and edited by DALL-E 3 in ChatGPT and the OpenAI API; (2) including both C2PA metadata and SynthID watermarks on images generated with ChatGPT, Codex, and the OpenAI API; (3) providing openai.com/verify, a public verification experience where people can check whether supported images contain provenance signals associated with OpenAI-generated images; and (4) contributing to open standards through joining the C2PA Steering Committee to advance interoperable provenance standards across the ecosystem.

OpenAI Blog
OpenAI Blog
Jun 10, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated patching requirements for federal agencies to address AI-related security threats. Agencies must now fix the most critical vulnerabilities (flaws in software that attackers can exploit) within three days, while less severe issues can be addressed later.

Dark Reading
Jun 10, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA) released a new directive requiring federal agencies to patch critical software vulnerabilities (bugs) in as little as three days, driven by concerns that AI models can now discover and exploit security flaws faster than humans can fix them. The directive uses a prioritization system based on four factors, including whether a vulnerability is publicly exposed and can be automatically exploited, to determine how urgently each bug must be addressed.

Fix: CISA's directive requires agencies to use a prioritization rubric based on four assessments: whether a vulnerability is in a publicly exposed system, whether it appears in CISA's Known Exploited Vulnerabilities Catalog, whether an attacker could automate exploitation, and how much access an attacker would gain. When all four criteria apply, the vulnerability must be fixed within three days, and agencies must also execute a 'forensic triage' process to determine if systems have already been compromised.

Wired (Security)
Jun 10, 2026

Organizations are struggling to patch vulnerabilities fast enough, with only 26% of actively exploited vulnerabilities fully fixed while attackers have reduced their exploitation time to hours or days. CISA issued Binding Operational Directive 26-04, which tells federal agencies to prioritize patching based on four factors (public exposure, known exploitation, automatable attacks, and post-exploitation impact) rather than just severity scores (CVSS, a 0-10 rating of how severe a vulnerability is), recognizing that AI is accelerating both vulnerability discovery and exploitation. Vulnerabilities meeting three or more of these risk factors must be patched within three days, while lower-risk ones can follow longer timelines.

Fix: CISA's Binding Operational Directive 26-04 introduces a decision framework considering four key factors: whether the vulnerable system is publicly exposed to the internet, whether the vulnerability is listed in the KEV (Known Exploited Vulnerabilities) catalog, whether an attacker can automate exploitation, and how much control an attacker would gain after exploitation. Vulnerabilities exhibiting three or more of these attributes must be patched within three days, while lower-risk vulnerabilities can be addressed on longer timelines or deferred until the next major system upgrade.

CSO Online
OpenAI Blog
Jun 10, 2026

Insurance companies are responding differently to the growing use of AI in businesses: some are refusing to cover AI-related risks entirely, while others are developing frameworks to manage those risks. The article raises the question of which AI risks companies can actually handle and control.

Dark Reading

Fix: Update claude-code-action to the latest version. Users referencing anthropics/claude-code-action@v1, anthropics/claude-code-action@beta, anthropics/claude-code-action@main, or other non-pinned tags will have already received this fix.

GitHub Advisory Database
Jun 10, 2026

Anthropic released Claude Fable 5, claiming it is their most powerful model, but it refuses to answer basic biology questions and instead redirects them to an older model called Claude Opus 4.8. This limitation is intentional by design, not because the model lacks knowledge. Fable belongs to the Mythos-class family, a group of models so skilled at cybersecurity tasks that Anthropic decided they were too dangerous to release to the public.

The Verge (AI)