aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9703 items

OpenAI Help: Lockdown Mode

infonews
securitysafety
Jun 5, 2026

OpenAI has released Lockdown Mode, a security feature that prevents the final stage of data exfiltration (stealing and sending sensitive information) from prompt injection attacks (tricking an AI by hiding malicious instructions in its input) by blocking outbound network requests. However, Lockdown Mode does not stop prompt injections from appearing in the content ChatGPT processes, meaning attackers can still manipulate the AI's responses through cached web content or uploaded files.

Fix: Enable Lockdown Mode, which is rolling out to eligible personal accounts (Free, Go, Plus, and Pro tiers) and self-serve ChatGPT Business accounts. According to the source, Lockdown Mode uses deterministic mechanisms (fixed, rule-based processes) to restrict exfiltration vectors, rather than relying on AI systems to detect attacks.

Simon Willison's Weblog

GHSA-pr2w-4gpj-cpq4: Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

highvulnerability
security
Jun 5, 2026
CVE-2026-47732

Twig's sandbox (a security feature that restricts what templates can do) had multiple vulnerabilities where certain language constructs could bypass security checks and call `__toString()` methods (special functions that convert objects to strings) on objects without permission. Attackers could exploit this through conditional expressions, comparison operators, tests, and several other Twig features to access object data that should have been blocked.

Trump administration, OpenAI discussing possible government stake in the AI startup

infonews
policyindustry

Amazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins

highvulnerability
security
Jun 5, 2026

Amazon Q Developer and AWS Kiro, which are AI tools that help developers write code, have security vulnerabilities related to prompt injection (tricking the AI by hiding malicious instructions in files or suggestions). Attackers could potentially execute commands or steal sensitive information without the developer's knowledge. AWS has released multiple software updates that require human confirmation before executing risky commands.

CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper

highvulnerability
security
Jun 5, 2026

A vulnerability (CVE-2026-0830) in Kiro IDE, a desktop application that helps developers with code tasks, allows attackers to run arbitrary commands (command injection, where an attacker executes unauthorized code) on a user's computer by tricking them into opening a workspace with specially crafted folder names. This bug affects Kiro versions before 0.6.18.

Security Findings in SageMaker Python SDK

highvulnerability
security
Jun 5, 2026

AWS discovered two security vulnerabilities in the SageMaker Python SDK (a library for machine learning on Amazon's platform). The first flaw exposes HMAC keys (cryptographic secrets that verify data hasn't been tampered with) through an API, allowing attackers to forge fake data in cloud storage. The second flaw disables SSL certificate verification (the security check that confirms you're connected to a legitimate server), affecting all encrypted connections when a certain model component is used.

CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 - runc container issues

highvulnerability
security
Jun 5, 2026

Three security vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) were found in runc, a component used by container management systems (tools that package and run isolated software environments). AWS says these issues don't create cross-customer risk because AWS doesn't rely on containers as a security boundary (a protective barrier between different users). AWS customers using containers to isolate their own internal workloads should contact their operating system vendor for updates.

Microsoft identifies seven new ways AI agents can be hacked

infonews
securitysafety

Model routing is a fix for AI overspending. That's a problem for OpenAI and Anthropic

infonews
industry
Jun 5, 2026

Companies are implementing model routing, a technique that directs simple tasks to cheaper AI models and complex tasks to expensive ones, to control skyrocketing AI costs. This shift is forcing major AI providers like OpenAI and Anthropic to reconsider their business models, since they previously earned revenue from all queries regardless of task complexity, but now may only get paid for the most difficult work that requires their most powerful models.

Apple's WWDC: Tim Cook's AI legacy at stake in his final developer conference as CEO

infonews
industry
Jun 5, 2026

Apple is preparing to unveil major improvements to Siri, its voice assistant, at its upcoming developer conference, with the goal of finally delivering the AI experience it promised two years ago. The improvements are expected to include a more powerful standalone chatbot-style app, personal context awareness, and the ability to handle multi-step commands, potentially routing to outside AI models like Google's Gemini. However, Apple faces a critical challenge: Siri must become reliably agentic (able to independently execute complex tasks across multiple apps) to justify Apple's current stock valuation, which depends on developers adopting Apple's App Intents system (the framework that lets Siri perform actions inside third-party apps) before consumers have proven they will actually use the improved features.

Securing CI/CD in an agentic world: Claude Code Github action case

highnews
securitysafety

GHSA-x9f6-9rvm-mmrg: Improper Access Control in vantage6 node

mediumvulnerability
security
Jun 5, 2026

A security flaw in vantage6 node (a distributed computing platform) allows malicious algorithms (computational programs) to improperly access input and output files that belong to other algorithms running on the same node. This is an access control vulnerability, meaning the system fails to properly restrict who can view what data.

This is your laptop… on AI

infonews
industry
Jun 5, 2026

Major technology companies like Nvidia, Microsoft, and Google are promoting AI as a transformative force that will fundamentally change how we use laptops and computing devices, with new hardware and software being announced at developer conferences. However, the article questions whether users actually want or need these AI-focused products and changes.

GHSA-7p8g-6c6g-h9w7: praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

highvulnerability
security
Jun 5, 2026
CVE-2026-47419

PraisonAI Platform has an IDOR (insecure direct object reference, a flaw where users can access resources they shouldn't by guessing object IDs) vulnerability in its agent management endpoints. A user who belongs to any workspace can read, modify, or delete agents from other workspaces by guessing their agent IDs, because the code checks if the user belongs to *some* workspace but never verifies the agent actually belongs to that workspace.

LinkedIn co-founder Reid Hoffman is leaving Microsoft's board after almost a decade

infonews
industry
Jun 5, 2026

Reid Hoffman, co-founder of LinkedIn and a long-time member of Microsoft's board, is stepping down after almost a decade to focus on Manas, an AI-native biopharmaceutical company he co-founded. Hoffman previously left OpenAI's board in 2023 to avoid potential conflicts of interest as Microsoft invested heavily in OpenAI, and he is now transitioning to focus on his founder roles rather than board positions.

GHSA-6mx4-4h42-r8vh: MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration

mediumvulnerability
security
Jun 5, 2026
CVE-2026-47250

The `kubectl_generic` tool in `mcp-server-kubernetes` accepts any kubectl flags without validation, allowing an attacker to inject flags like `--server=https://attacker.com` and `--insecure-skip-tls-verify=true`. When a privileged operator uses the MCP server and an AI agent follows injected instructions in logs, kubectl sends the operator's Kubernetes bearer token (authentication credential) to the attacker's server, which can then be replayed to gain full cluster access.

Anthropic says the world should have option to ‘pause’ on AI

infonews
policysafety

GHSA-wv8c-6mx2-xf4j: Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService

highvulnerability
security
Jun 5, 2026
CVE-2026-45726

Omni (a cluster management tool) creates a resource called ImportedClusterSecrets when importing standalone Talos clusters. This resource contains the CA (certificate authority, the foundational keys that verify identities in a system) secrets for that cluster. If these secrets are not rotated by the user who imported the cluster, any authenticated user with Reader-level access can read this resource and obtain full control over the cluster's Kubernetes, Talos, and etcd APIs, even outside Omni's security controls.

GHSA-c66c-vq6w-fvh5: Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic

lowvulnerability
security
Jun 5, 2026
CVE-2026-45723

A vulnerability in Omni's CreateSchematic API allows an authenticated Operator (administrator) to perform path traversal (accessing files or endpoints outside the intended directory) on the image-factory server by embedding unsanitized user input into a URL path. An attacker can use sequences like '../' to navigate to unintended endpoints and receive back error messages that may leak sensitive information from the image-factory server.

GHSA-5x9f-6vg5-qg4m: Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token

highvulnerability
security
Jun 5, 2026
CVE-2026-45720

Omni has a TOCTOU race condition (a timing bug where two operations that should be atomic happen separately, allowing a race between them) in its SAML authentication system. An attacker who intercepts a single-use SAML session token can send multiple concurrent requests with that token, and because the system checks if the token is used and then marks it used in two separate steps rather than one atomic operation, both requests can pass validation, allowing the attacker to authenticate as the victim multiple times.

Previous195 / 486Next

Fix: The sandbox was fixed by wrapping every child node that will be converted to a string at runtime. A new `Twig\Node\CoercesChildrenToStringInterface` allows nodes to declare which children need protection, core nodes now implement this interface, spread arguments are checked via `SandboxExtension::ensureSpreadAllowed()`, and dynamic attribute names are checked at runtime inside `CoreExtension::getAttribute()`.

GitHub Advisory Database
Jun 5, 2026

OpenAI CEO Sam Altman and the White House are discussing a possible government stake in OpenAI, with talks ongoing for over a year. As part of the potential agreement, OpenAI could donate equity to create a 'Public Wealth Fund' that would invest in long-term assets and allow citizens to share in the financial benefits of AI growth. No official investment terms have been decided, and all details remain subject to change.

CNBC Technology

Fix: For Amazon Q Developer: upgrade to Language Server v1.22.0 or later (released July 17, 2025) to require human confirmation for find, grep, and echo commands; upgrade to Language Server v1.24.0 or later (released July 29, 2025) to require human confirmation for ping and dig commands. For AWS Kiro: upgrade to version 0.1.42 or later (released August 1, 2025), which requires human confirmation for risky actions when configured in Supervised mode.

AWS Security Bulletins

Fix: Update to Kiro version 0.6.18 or later.

AWS Security Bulletins

Fix: Update SageMaker Python SDK to v3.2.0 or later for the HMAC vulnerability, or v2.256.0 or later if using v2. Update to v3.1.1 or later for the TLS vulnerability, or v2.256.0 or later if using v2.

AWS Security Bulletins

Fix: AWS recommends applying all security patches and software version updates as a best practice. Customers using containers to isolate workloads within their own environments should contact their operating system vendor for any updates or instructions necessary to mitigate these issues.

AWS Security Bulletins
Jun 5, 2026

Microsoft has identified seven new ways that agentic AI systems (AI programs that can take actions autonomously) can fail or be attacked, building on previous research. These vulnerabilities include attacks where adversaries manipulate agent behavior through natural language, redirect an agent's goals, trick agents communicating with each other, exploit visual interfaces, contaminate data to bias reasoning, abuse plugins and protocols, and cause agents to leak internal information.

Fix: Microsoft advises security teams to: inventory their supply chain and generate a software bill of materials (SBOM, a detailed list of all components in deployed agents); verify agent identity using cryptographic credentials issued at provisioning rather than relying on position or location; add the seven new failure modes to their red-team coverage matrix (security testing that simulates attacks); and audit the human-in-the-loop user experience (where humans review or approve agent actions) as a security control.

CSO Online

Fix: Model routing is presented as the emerging solution: according to the source, routing is a tool that matches the job to the model, sending hard problems to expensive frontier models (advanced, state-of-the-art AI systems) and easy ones to cheaper, faster alternatives. The article also mentions that Cognition announced an AI productivity guarantee, where if their Devin agent delivers less engineering value than a customer pays for, Cognition will fund usage up to $10 million until performance improves, framing this as a way to measure return on investment (value delivered) rather than just activity metrics like tokens consumed.

CNBC Technology
CNBC Technology
Jun 5, 2026

Microsoft Threat Intelligence found that Anthropic's Claude Code GitHub Action could expose sensitive credentials when AI agents process untrusted GitHub content (like issue descriptions and comments) because the Read tool wasn't properly sandboxed, allowing it to access /proc/self/environ and steal API keys. Attackers exploited this by hiding prompt injection (tricking an AI by hiding instructions in its input) attacks in HTML comments within GitHub issues to manipulate the AI agent into executing malicious operations like planting code into repositories.

Fix: Anthropic mitigated this issue in Claude Code version 2.1.128 by blocking access to sensitive /proc files. Microsoft also recommends that defenders treat AI workflows processing untrusted GitHub content as high-risk, especially when they have access to secrets, file-read tools, or external communication channels.

Microsoft Security Blog

Fix: Verify and restrict the algorithm containers (isolated software packages) that are allowed to run on your node, with instructions available in the vantage6 security documentation.

GitHub Advisory Database
The Verge (AI)
GitHub Advisory Database
CNBC Technology
GitHub Advisory Database
Jun 5, 2026

Anthropic, a US AI company, has proposed that the world consider a temporary pause on AI development and plans to bring together policymakers to discuss the risks of advanced AI. The company released details about its Claude model's progress toward recursive self-improvement (the ability for an AI to automatically create better versions of itself), which AI safety researchers worry could lead to superintelligent AI (an AI system far more intelligent than humans) with potentially serious consequences.

The Guardian Technology
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database