aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9703 items

CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /a

criticalvulnerability
security
Jun 8, 2026
CVE-2026-46442

Flowise, a tool for building custom AI workflows with a visual interface, had a vulnerability before version 3.1.2 where any user with API access could submit malicious JavaScript code to a function node. When a security key (E2B_APIKEY) wasn't set up (the typical case), this code could break out of its sandbox (a restricted execution environment) and run system commands on the server hosting Flowise.

Fix: Upgrade to version 3.1.2, which patches this vulnerability.

NVD/CVE Database

CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass

highvulnerability
security
Jun 8, 2026
CVE-2026-46441

Flowise, a tool for building customized AI workflows through a drag-and-drop interface, has a mass assignment vulnerability (a bug where attackers can modify fields they shouldn't be able to change) in versions before 3.1.2 that lets authenticated users reassign assistants to different workspaces by manipulating the workspaceId field, breaking the isolation between separate user workspaces in multi-user environments.

CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che

mediumvulnerability
security
Jun 8, 2026
CVE-2026-46440

Flowise is a tool with a drag-and-drop interface for building customized AI workflows. Before version 3.1.2, the checkBasicAuth endpoint (a part of the system that checks user login credentials) had a security flaw where it validated passwords in plaintext (unencrypted text) without rate limiting (restrictions on how many attempts someone can make) and compared them directly, making it vulnerable to attacks.

NotebookLM’s Gemini 3.5 upgrade adds a cloud computer and help finding sources

infonews
industry
Jun 8, 2026

Google is upgrading NotebookLM, an AI-powered note-taking app, to use Gemini 3.5, a newer and more advanced version of its AI model that will provide more accurate answers. The update lets users start research projects by simply asking questions, and NotebookLM will automatically search the web to find relevant sources rather than requiring users to manually import materials.

Confidential submission of draft S-1 to the SEC

infonews
industry
Jun 8, 2026

This item is not AI/LLM-related and does not describe a technical security issue, vulnerability, or problem. It is a corporate legal announcement about a confidential S-1 filing (a registration statement for going public) with the SEC (Securities and Exchange Commission), noting that the company expects the document to leak and is making a preemptive announcement while deciding on timing for a public offering.

Microsoft’s AI chief says superintelligence is near, but won’t take your job

infonews
industry
Jun 8, 2026

Microsoft's AI chief Mustafa Suleyman discusses how Microsoft has restructured its AI division to independently pursue superintelligence (AI systems that could surpass human capabilities across all domains), following a renegotiated partnership with OpenAI in October that allows both companies to develop models separately. The interview covers Microsoft's new approach to training frontier models (cutting-edge AI systems at the limits of current technology), the company's relationship with OpenAI, and how AI is being perceived by the public and in politics.

MU-MIA: Machine Unlearning for Membership Inference Attacks

inforesearchPeer-Reviewed
security

Game-Theoretic Analysis of Multi-Source Information Freshness Under False Data Injection

inforesearchPeer-Reviewed
security

UC-Secure Multi-Factor Authentication With Dynamic Password Recovery and Fine-Grained Access Control

inforesearchPeer-Reviewed
security

Measuring the impact of learning with AI in Sierra Leone and beyond

inforesearchIndustry
research

The Download: how the World Cup ball will fly and OpenAI’s “super app”

infonews
industrypolicy

Anthropic’s Project Glasswing Update

infonews
safetysecurity

Why most enterprise security teams would fail a military readiness test

infonews
securitypolicy

15 tough cybersecurity questions every CISO must answer

infonews
security
Jun 8, 2026

This article presents 15 strategic questions that CISOs (chief information security officers, the leaders responsible for an organization's security) should regularly ask themselves to ensure their security programs stay effective and aligned with business needs. The questions cover areas like demonstrating security's value to the business, protecting critical processes, understanding impact of breaches, detection speed, and keeping pace with modern threats. The article emphasizes that security programs must continuously adapt rather than remain static, especially in an AI-enabled threat environment where the focus should shift from finding every vulnerability to protecting the most critical business processes and ensuring rapid incident response.

OpenAI Rolling Out ChatGPT Account Security Controls

infonews
security
Jun 8, 2026

OpenAI is expanding two security features for ChatGPT accounts. Lockdown Mode helps prevent data exfiltration (unauthorized data theft) from prompt injection attacks (tricking an AI by hiding instructions in its input) by limiting outbound network requests, though it disables features like web browsing and file downloads. Active Sessions lets users see where their account is logged in and log out of unrecognized sessions.

Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow

infonews
safetypolicy

A lattice-based fine-grained multi-keyword searchable encryption scheme for medical data sharing with user revocation and selective disclosure

inforesearchPeer-Reviewed
security

An essential secret image sharing scheme with certification based on the Chinese Remainder Theorem and polynomials

inforesearchPeer-Reviewed
security

TMAS: A threshold multi-auditor auditing scheme for weakly trusted cloud–fog collaboration

inforesearchPeer-Reviewed
security

STAFF: Stateful taint-assisted full-system firmware fuzzing

inforesearchPeer-Reviewed
security
Previous193 / 486Next

Fix: Update to version 3.1.2, where this issue has been patched.

NVD/CVE Database

Fix: Update to version 3.1.2, which patches this vulnerability.

NVD/CVE Database
The Verge (AI)
OpenAI Blog
The Verge (AI)
research
Jun 8, 2026

Researchers developed a new membership inference attack (MIA, a method to determine whether specific data was used to train an AI model) called MU-MIA that uses machine unlearning (a technique to make a model forget specific training samples) to track how a model forgets information about individual samples. The attack works by monitoring changes in the model's behavior as it unlearns each sample and uses a BiLSTM classifier (a type of neural network that analyzes sequences of data) to distinguish between samples that were in the training data versus those that weren't.

IEEE Xplore (Security & AI Journals)
Jun 8, 2026

This research paper analyzes how networked control systems (computer systems where multiple sensors share information across a network) behave when under attack from false data injection, or FDI (inserting fake sensor readings to disrupt the system). Using game theory (a mathematical framework for analyzing competing strategies), the researchers model the conflict between legitimate system operators trying to keep data accurate and attackers trying to corrupt it, then prove that both sides will reach a stable strategic equilibrium (a predictable outcome where neither side can improve by changing tactics alone).

IEEE Xplore (Security & AI Journals)
Jun 8, 2026

This paper introduces MFA-DPRF, a new multi-factor authentication (MFA, a security method requiring multiple forms of proof like a password and a code) scheme designed to handle two problems that existing systems ignore: password recovery when users forget their login credentials, and fine-grained access control (letting administrators set specific rules about which users can access which resources). The system works by requiring users to provide both a valid password and attributes that match an access policy, and it includes a dynamic password recovery method using secret questions and secret sharing (splitting a secret into pieces so no single piece reveals the secret).

IEEE Xplore (Security & AI Journals)
Jun 8, 2026

A study in Sierra Leone tested whether AI (specifically Google's Gemini) could help students learn math better by acting as a teaching partner rather than replacing teachers. The AI was designed using a 'Socratic' approach, asking guiding questions instead of giving direct answers, and students who used it showed significant learning gains equivalent to 1.2 to 2.5 years of typical progress in just eight weeks, while maintaining high engagement and shifting their own questions toward understanding rather than just seeking solutions.

DeepMind Safety Research
Jun 8, 2026

This newsletter covers multiple AI and tech developments, including OpenAI's plans to transform ChatGPT into a 'super app' (an all-in-one application combining multiple tools and services) before going public, Google's $30 billion deal with SpaceX for AI computing power, and concerns about AI's rising energy costs and environmental impact. It also reports on facial recognition tools being deployed by immigration enforcement, fears about 'recursive self-improvement' (AI systems automatically improving their own capabilities), and how machine learning is helping historians analyze historical records while introducing risks of bias and errors.

MIT Technology Review
Jun 8, 2026

Anthropic launched Project Glasswing in April to help companies find software vulnerabilities (weaknesses that attackers can exploit) using their AI model, though claims about its superiority over other models are unverified. A status report shows the project is finding many vulnerabilities, including dangerous ones, but almost none have been patched, and Anthropic has not released detailed information about the findings.

Schneier on Security
Jun 8, 2026

Most enterprise security teams are unprepared for real cyberattacks because they treat cybersecurity as a compliance requirement rather than an operational capability that requires constant practice. The military achieves rapid, coordinated responses to cyber incidents through regular, realistic exercises and by assuming attacks are inevitable, while businesses rely on outdated annual tabletop exercises and focus on prevention rather than detection, containment, and recovery.

CSO Online
CSO Online

Fix: OpenAI provides two explicit mitigations: (1) Enable Lockdown Mode in Settings > Security > Advanced Security to limit outbound network requests during prompt injection attacks, and (2) use Active Sessions in Settings > Security to review and log out of unrecognized account sessions. Additionally, OpenAI offers Advanced Account Security, which disables password-based login in favor of physical security keys or passkeys, replaces email/SMS account recovery with backup passkeys and recovery keys, and shortens sign-in sessions to reduce account takeover risk.

SecurityWeek
Jun 8, 2026

Anthropic is calling for AI companies worldwide to coordinate and create a system to pause or slow development of advanced AI if risks become too serious, warning that AI is improving so rapidly that humans could lose control, particularly through recursive self-improvement (where an AI designs its own successor). The company proposes a verification mechanism to ensure all labs comply with any slowdown, though OpenAI disagrees and argues that democratic governments, not private companies, should make decisions about AI development pace.

Fix: Anthropic proposes that advanced AI labs should establish a coordinated global mechanism to verify that rivals have actually stopped or slowed their work and that "a bad actor could not use the auspices of a coordinated slowdown to jump ahead in secret." The source also mentions that collaboration between companies, government agencies, and academic researchers is needed to develop countermeasures against AI-powered hacking tools.

SecurityWeek
Jun 8, 2026

This academic paper describes a new encryption method designed to let multiple people search through encrypted medical data while protecting privacy and controlling who has access. The scheme uses lattice-based cryptography (a type of math-hard encryption based on complex grid structures) and allows for selective disclosure (sharing only certain information with specific people) and user revocation (removing someone's access rights). This addresses the challenge of keeping medical information secure while still making it searchable and shareable in healthcare systems.

Elsevier Security Journals
Jun 8, 2026

This academic paper describes a method for securely sharing secret images among multiple people using the Chinese Remainder Theorem (a mathematical technique for solving certain types of equations) and polynomials (mathematical expressions with variables). The scheme includes a certification process to verify that the shared image pieces are authentic and haven't been tampered with.

Elsevier Security Journals
Jun 8, 2026

This academic paper proposes TMAS, a threshold multi-auditor auditing scheme designed to verify data integrity and security in cloud-fog computing environments (distributed systems where data processing happens both in the cloud and at edge devices closer to users) where trust between parties is limited. The scheme uses multiple independent auditors working together so that no single auditor needs to be completely trusted, addressing the challenge of maintaining security when collaborating systems don't fully trust each other.

Elsevier Security Journals
Jun 8, 2026

STAFF is a research tool for testing firmware (the low-level software that runs on hardware devices) by using fuzzing (automated testing that feeds random or specially crafted inputs to find bugs). The tool uses stateful taint analysis (tracking how untrusted data flows through a program) to improve the fuzzing process and find security vulnerabilities more effectively in full systems.

Elsevier Security Journals