All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Flowise, a tool for building custom AI workflows with a visual interface, had a vulnerability before version 3.1.2 where any user with API access could submit malicious JavaScript code to a function node. When a security key (E2B_APIKEY) wasn't set up (the typical case), this code could break out of its sandbox (a restricted execution environment) and run system commands on the server hosting Flowise.
Fix: Upgrade to version 3.1.2, which patches this vulnerability.
NVD/CVE DatabaseFlowise, a tool for building customized AI workflows through a drag-and-drop interface, has a mass assignment vulnerability (a bug where attackers can modify fields they shouldn't be able to change) in versions before 3.1.2 that lets authenticated users reassign assistants to different workspaces by manipulating the workspaceId field, breaking the isolation between separate user workspaces in multi-user environments.
Flowise is a tool with a drag-and-drop interface for building customized AI workflows. Before version 3.1.2, the checkBasicAuth endpoint (a part of the system that checks user login credentials) had a security flaw where it validated passwords in plaintext (unencrypted text) without rate limiting (restrictions on how many attempts someone can make) and compared them directly, making it vulnerable to attacks.
Google is upgrading NotebookLM, an AI-powered note-taking app, to use Gemini 3.5, a newer and more advanced version of its AI model that will provide more accurate answers. The update lets users start research projects by simply asking questions, and NotebookLM will automatically search the web to find relevant sources rather than requiring users to manually import materials.
This item is not AI/LLM-related and does not describe a technical security issue, vulnerability, or problem. It is a corporate legal announcement about a confidential S-1 filing (a registration statement for going public) with the SEC (Securities and Exchange Commission), noting that the company expects the document to leak and is making a preemptive announcement while deciding on timing for a public offering.
Microsoft's AI chief Mustafa Suleyman discusses how Microsoft has restructured its AI division to independently pursue superintelligence (AI systems that could surpass human capabilities across all domains), following a renegotiated partnership with OpenAI in October that allows both companies to develop models separately. The interview covers Microsoft's new approach to training frontier models (cutting-edge AI systems at the limits of current technology), the company's relationship with OpenAI, and how AI is being perceived by the public and in politics.
This article presents 15 strategic questions that CISOs (chief information security officers, the leaders responsible for an organization's security) should regularly ask themselves to ensure their security programs stay effective and aligned with business needs. The questions cover areas like demonstrating security's value to the business, protecting critical processes, understanding impact of breaches, detection speed, and keeping pace with modern threats. The article emphasizes that security programs must continuously adapt rather than remain static, especially in an AI-enabled threat environment where the focus should shift from finding every vulnerability to protecting the most critical business processes and ensuring rapid incident response.
OpenAI is expanding two security features for ChatGPT accounts. Lockdown Mode helps prevent data exfiltration (unauthorized data theft) from prompt injection attacks (tricking an AI by hiding instructions in its input) by limiting outbound network requests, though it disables features like web browsing and file downloads. Active Sessions lets users see where their account is logged in and log out of unrecognized sessions.
Fix: Update to version 3.1.2, where this issue has been patched.
NVD/CVE DatabaseFix: Update to version 3.1.2, which patches this vulnerability.
NVD/CVE DatabaseResearchers developed a new membership inference attack (MIA, a method to determine whether specific data was used to train an AI model) called MU-MIA that uses machine unlearning (a technique to make a model forget specific training samples) to track how a model forgets information about individual samples. The attack works by monitoring changes in the model's behavior as it unlearns each sample and uses a BiLSTM classifier (a type of neural network that analyzes sequences of data) to distinguish between samples that were in the training data versus those that weren't.
This research paper analyzes how networked control systems (computer systems where multiple sensors share information across a network) behave when under attack from false data injection, or FDI (inserting fake sensor readings to disrupt the system). Using game theory (a mathematical framework for analyzing competing strategies), the researchers model the conflict between legitimate system operators trying to keep data accurate and attackers trying to corrupt it, then prove that both sides will reach a stable strategic equilibrium (a predictable outcome where neither side can improve by changing tactics alone).
This paper introduces MFA-DPRF, a new multi-factor authentication (MFA, a security method requiring multiple forms of proof like a password and a code) scheme designed to handle two problems that existing systems ignore: password recovery when users forget their login credentials, and fine-grained access control (letting administrators set specific rules about which users can access which resources). The system works by requiring users to provide both a valid password and attributes that match an access policy, and it includes a dynamic password recovery method using secret questions and secret sharing (splitting a secret into pieces so no single piece reveals the secret).
A study in Sierra Leone tested whether AI (specifically Google's Gemini) could help students learn math better by acting as a teaching partner rather than replacing teachers. The AI was designed using a 'Socratic' approach, asking guiding questions instead of giving direct answers, and students who used it showed significant learning gains equivalent to 1.2 to 2.5 years of typical progress in just eight weeks, while maintaining high engagement and shifting their own questions toward understanding rather than just seeking solutions.
This newsletter covers multiple AI and tech developments, including OpenAI's plans to transform ChatGPT into a 'super app' (an all-in-one application combining multiple tools and services) before going public, Google's $30 billion deal with SpaceX for AI computing power, and concerns about AI's rising energy costs and environmental impact. It also reports on facial recognition tools being deployed by immigration enforcement, fears about 'recursive self-improvement' (AI systems automatically improving their own capabilities), and how machine learning is helping historians analyze historical records while introducing risks of bias and errors.
Anthropic launched Project Glasswing in April to help companies find software vulnerabilities (weaknesses that attackers can exploit) using their AI model, though claims about its superiority over other models are unverified. A status report shows the project is finding many vulnerabilities, including dangerous ones, but almost none have been patched, and Anthropic has not released detailed information about the findings.
Most enterprise security teams are unprepared for real cyberattacks because they treat cybersecurity as a compliance requirement rather than an operational capability that requires constant practice. The military achieves rapid, coordinated responses to cyber incidents through regular, realistic exercises and by assuming attacks are inevitable, while businesses rely on outdated annual tabletop exercises and focus on prevention rather than detection, containment, and recovery.
Fix: OpenAI provides two explicit mitigations: (1) Enable Lockdown Mode in Settings > Security > Advanced Security to limit outbound network requests during prompt injection attacks, and (2) use Active Sessions in Settings > Security to review and log out of unrecognized account sessions. Additionally, OpenAI offers Advanced Account Security, which disables password-based login in favor of physical security keys or passkeys, replaces email/SMS account recovery with backup passkeys and recovery keys, and shortens sign-in sessions to reduce account takeover risk.
SecurityWeekAnthropic is calling for AI companies worldwide to coordinate and create a system to pause or slow development of advanced AI if risks become too serious, warning that AI is improving so rapidly that humans could lose control, particularly through recursive self-improvement (where an AI designs its own successor). The company proposes a verification mechanism to ensure all labs comply with any slowdown, though OpenAI disagrees and argues that democratic governments, not private companies, should make decisions about AI development pace.
Fix: Anthropic proposes that advanced AI labs should establish a coordinated global mechanism to verify that rivals have actually stopped or slowed their work and that "a bad actor could not use the auspices of a coordinated slowdown to jump ahead in secret." The source also mentions that collaboration between companies, government agencies, and academic researchers is needed to develop countermeasures against AI-powered hacking tools.
SecurityWeekThis academic paper describes a new encryption method designed to let multiple people search through encrypted medical data while protecting privacy and controlling who has access. The scheme uses lattice-based cryptography (a type of math-hard encryption based on complex grid structures) and allows for selective disclosure (sharing only certain information with specific people) and user revocation (removing someone's access rights). This addresses the challenge of keeping medical information secure while still making it searchable and shareable in healthcare systems.
This academic paper describes a method for securely sharing secret images among multiple people using the Chinese Remainder Theorem (a mathematical technique for solving certain types of equations) and polynomials (mathematical expressions with variables). The scheme includes a certification process to verify that the shared image pieces are authentic and haven't been tampered with.
This academic paper proposes TMAS, a threshold multi-auditor auditing scheme designed to verify data integrity and security in cloud-fog computing environments (distributed systems where data processing happens both in the cloud and at edge devices closer to users) where trust between parties is limited. The scheme uses multiple independent auditors working together so that no single auditor needs to be completely trusted, addressing the challenge of maintaining security when collaborating systems don't fully trust each other.
STAFF is a research tool for testing firmware (the low-level software that runs on hardware devices) by using fuzzing (automated testing that feeds random or specially crafted inputs to find bugs). The tool uses stateful taint analysis (tracking how untrusted data flows through a program) to improve the fuzzing process and find security vulnerabilities more effectively in full systems.