aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9703 items

Adaptive, Agentic AI Worms Loom as Next Enterprise Threat

infonews
securitysafety
Jun 5, 2026

Researchers warn that AI worms (self-replicating malicious programs that can adapt and move between systems on their own) represent a serious upcoming threat to businesses, with these intelligent threats expected to appear within the next year. Unlike traditional worms, these AI-powered versions can learn new environments, find security weaknesses on their own, and spread autonomously.

Dark Reading

NSA said to be readying Anthropic’s Mythos for use in cyber operations

infonews
policysecurity

AI is designing OpenAI's next model in a sign of 'superintelligence': SoftBank's Masayoshi Son to CNBC

infonews
industrysafety

CVE-2026-11330: A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObserv

lowvulnerability
security
Jun 5, 2026
CVE-2026-11330

A weakness was found in thedotmack claude-mem software (up to version 11.0.1) where the computeObservationContentHash function uses weak hash functions (cryptographic methods that are easy to break). The vulnerability can only be exploited by someone with local access to the system, and it requires significant technical skill to carry out an attack.

What 2026 DBIR Confirms: Attacks Are Living in the Browser

infonews
securitysafety

AI Worm

infonews
securityresearch

NCorr-FP: A Neighbourhood-Based Correlation-Preserving Fingerprinting Scheme for Intellectual Property Protection of Structured Data

inforesearchPeer-Reviewed
research

BAVote: Blockchain-Based Electronic Voting System With Privacy and Accountability

inforesearchPeer-Reviewed
security

CVE-2026-11329: A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key

lowvulnerability
security
Jun 5, 2026
CVE-2026-11329

A vulnerability exists in ONNX MLIR (a tool that converts machine learning models to code) versions up to 0.5.0.0 where the generate_hash_key function uses a weak hash (a simple algorithm for converting data into a fixed-length code that is easy to reverse or predict). The vulnerability requires local access to exploit and is difficult to execute in practice.

In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA

infonews
securitypolicy

The Download: AI hacking beyond Mythos, and chatbots’ impact on our brains

infonews
securitysafety

Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

infonews
industryresearch

The Tech Download: Anthropic’s IPO sets up first big test of AI boom valuations

infonews
industry
Jun 5, 2026

Anthropic, an AI company, has filed for an initial public offering (IPO, the process of selling company shares to the public for the first time) with a $965 billion valuation and $47 billion revenue run rate, setting up a major test of whether sky-high valuations for AI companies are justified. Analysts say the key metric determining Anthropic's success won't be its valuation but its gross margin (the percentage of revenue left after paying the costs to provide AI services), which the company has kept secret and will likely reshape how the entire industry is valued. The filing could have major impacts on competitors and how enterprises price AI services going forward.

The Meta hack shows there’s more to AI security than Mythos

infonews
securitysafety

Claude Code has an MCP security problem — and your developers are already using it

highnews
security
Jun 5, 2026

Claude Code, Anthropic's AI coding assistant, stores OAuth tokens (security credentials that prove access permission) in plaintext in a configuration file, and researchers discovered an attack where malicious npm packages (JavaScript libraries) can silently redirect these tokens to attacker-controlled servers before they reach legitimate services like GitHub or Jira. The attack is difficult to detect because the requests appear legitimate in audit logs, and Anthropic has not released a patch despite knowing about the vulnerability since April.

AI tools becoming hot commodities on ransomware marketplaces

mediumnews
securityindustry

New claimants seek to sue Elon Musk’s xAI after Labour MP’s test case

infonews
safetypolicy

China may move toward U.S. path on AI as firms poach employees

infonews
industry
Jun 5, 2026

A former OpenAI researcher is now leading AI development at Chinese tech company Tencent, aiming to build AGI (artificial general intelligence, or AI with human-level or above capabilities), marking a shift in how Chinese companies approach AI compared to the U.S. Previously, Chinese firms focused on practical applications while U.S. companies pursued AGI, but as China recruits top talent from Silicon Valley, the companies are adopting the same long-term AGI goals. This contrasts with caution emerging in the U.S., where companies like Anthropic are calling for slower AI development due to safety concerns.

3 Principles to Safely Scale Agentic AI

infonews
securitysafety

CVE-2026-11326: OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site s

mediumvulnerability
security
Jun 4, 2026
CVE-2026-11326

OpenAI Atlas versions before 1.2025.288.15 had a security flaw where privileged browser APIs (special functions that control browser features) were exposed to web content on OpenAI domains, and a cross-site scripting vulnerability (a type of attack where malicious code is injected into a website) on forum.openai.com could be exploited to access browser history and control tabs. The vulnerability was caused by improper access control (failing to properly restrict who can use certain functions).

Previous196 / 486Next
Jun 5, 2026

Anthropic has reportedly deployed engineers to the NSA to help the intelligence agency use Mythos, an AI model designed for cybersecurity tasks. This partnership is noteworthy because the Department of Defense previously banned the NSA from using Anthropic's technology, labeling the company a supply-chain risk after Anthropic refused to allow government use of its models for mass surveillance and autonomous weapons.

TechCrunch (Security)
Jun 5, 2026

OpenAI is using AI models to design its own next models, according to SoftBank CEO Masayoshi Son, which he describes as a step toward "superintelligence" (AI vastly smarter than humans). However, Anthropic warned that this recursive self-improvement (RSI, where an AI system can autonomously design and develop its own successor) could increase risks of humans losing control over AI systems.

Fix: Anthropic stated that a coordinated effort between AI labs to slow down the development of recursive self-improvement technology "would likely be a good thing," though no specific technical fixes or implementation details are provided in the source text.

CNBC Technology

Fix: Upgrading to version 12.0.0 is sufficient to fix this issue. The patch is identified as f32fda8b35e9fe9329f87da65c31149362a03f97.

NVD/CVE Database
Jun 5, 2026

The 2026 Verizon Data Breach Investigations Report reveals that attackers are increasingly operating through web browsers, where traditional security tools fail to detect them. Key risks include shadow AI (unauthorized use of services like ChatGPT with corporate data), credential theft in browsers (which accounts for 41% of browser-based attacks but goes undetected by network and endpoint security tools), and malicious browser extensions (13% classified as high or critical risk, often disguised as 'productivity' tools). The report shows that browser-layer attacks are largely invisible to conventional defenses like network proxies and DNS filters, creating a significant detection gap in enterprise security.

BleepingComputer
Jun 5, 2026

Researchers have created a prototype of an AI-powered internet worm, which is malware (malicious software that spreads itself) that carries its own LLM (large language model, a type of AI trained on text data) and runs it on computers it has broken into. This design closely matches the original concept of computer worms from 1975, but now enhanced with AI capabilities.

Schneier on Security
security
Jun 5, 2026

NCorr-FP is a data fingerprinting (embedding hidden recipient-specific marks into data to track ownership) technique designed to protect structured tabular data in shared environments. The method preserves the statistical quality of data while embedding fingerprints using local record similarity and density estimation, and can detect these fingerprints even after substantial data modification or deletion attacks.

IEEE Xplore (Security & AI Journals)
Jun 5, 2026

BAVote is a blockchain-based electronic voting system that uses cryptographic techniques to balance voter privacy (hiding voter identity) with accountability (ability to trace dishonest voters). The paper presents a new approach called ConsATS, a threshold signature scheme (a cryptographic method where multiple parties must cooperate to create a valid signature) that compresses all voters' public keys into a single key, reducing storage needs by over 90% and making verification 7 times faster than previous systems.

Fix: The paper proposes using a new threshold signature scheme named ConsATS that features a constant-size verification key. This scheme compresses all voters' public keys into a single verification key, allowing aggregated ballots to be verified without storing or processing individual voter public keys. BAVote additionally combines one-time addresses (temporary, single-use identifiers) and a commit-reveal mechanism (a two-phase protocol where voters first commit to their choice, then later reveal it) to protect intermediate voting data on the blockchain, with a tracing key enabling authorized auditors to identify malicious voters.

IEEE Xplore (Security & AI Journals)

Fix: Apply patch 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4 to resolve this issue.

NVD/CVE Database
Jun 5, 2026

This cybersecurity news roundup covers several major threats: attackers are poisoning AI chatbot search results to trick users into downloading malware that hijacks computer power for cryptocurrency mining; the Grandoreiro banking trojan continues targeting financial institutions despite being a decade old; and a ransomware group called The Gentlemen uses self-propagating malware to automatically encrypt entire networks. Additionally, Let's Encrypt is preparing to adopt Merkle Tree Certificates (a more efficient way to batch multiple digital certificates under one signature) to handle the larger file sizes of post-quantum cryptography, with a test environment launching in late 2026.

Fix: Disconnect Automatic Tank Gauge (ATG) systems from the public internet immediately, according to warnings from CISA, the FBI, the NSA, and other US agencies. For post-quantum cryptography concerns, Let's Encrypt plans to launch a staging environment for Merkle Tree Certificates in late 2026, followed by full production rollout in 2027.

SecurityWeek
Jun 5, 2026

Attackers exploited Meta's AI customer support agent by tricking it into linking Instagram accounts to email addresses they controlled, showing that AI security risks extend beyond sophisticated attacks to simple social engineering exploits. Psychologist Gloria Mark warns that relying on AI chatbots like ChatGPT and Claude may weaken human attention spans, critical thinking, and emotional intelligence by deferring cognitive work to machines.

MIT Technology Review
Jun 5, 2026

Despite rapid adoption of AI tools in security operations centers (SOCs, teams that monitor and respond to security threats), only 10% report excellent value from these investments. The problem is structural: most SOCs deploy off-the-shelf AI without customization or best practices, and individual AI tools don't share information with each other, so analysts still face fragmented workflows even though individual tasks run faster.

The Hacker News
CNBC Technology
Jun 5, 2026

Attackers exploited Meta's AI customer support agent by simply asking it to link Instagram accounts to email addresses they controlled, allowing them to steal accounts including a high-profile one. The hack shows that while AI security discussions often focus on powerful AI systems attacking computer infrastructure, the real vulnerability here was that the AI agent itself became a target through direct, straightforward manipulation that should have been caught before deployment.

Fix: The source explicitly mentions two mitigations: (1) Companies can use traditional software to build guardrails that make sure agents follow strict rules, such as always asking for answers to security questions before sending sensitive account information to a new email address. (2) Agents should undergo rigorous red-teaming, a process of testing systems by simulating attacks to find vulnerabilities before they're deployed to users.

MIT Technology Review
CSO Online
Jun 5, 2026

AI tools are being sold increasingly on underground ransomware marketplaces, with sales growing from 38 posts in December 2025 to 1,486 in February 2026. These tools include weaponized LLMs (large language models without safety protections), deepfakes for identity fraud, AI-enhanced malware, and stolen AI accounts, making it easier for criminals to launch attacks at scale. The source notes that while criminal security is weaker than it appears and criminals sometimes steal from each other, ransomware attacks have grown 20% since 2023 and become significantly more profitable.

CSO Online
Jun 5, 2026

A UK Labour MP has launched a legal case against Elon Musk's company xAI over harmful content created by their Grok AI tool (a chatbot), including fake sexual images and videos of her. Following this test case, other potential victims have contacted her lawyer to pursue similar legal action against the company.

The Guardian Technology
CNBC Technology
Jun 5, 2026

As AI systems evolve from simple assistants into autonomous agents (AI systems that can make decisions and execute tasks independently), organizations face new security risks because these agents access sensitive systems and data at speeds humans cannot match. The article outlines three principles for secure AI deployment: treat AI agents as privileged identities (accounts with special access permissions) requiring continuous monitoring, secure the entire AI lifecycle from development through production rather than just the initial build phase, and use AI-powered analytics to detect threats in real time across multiple systems.

CrowdStrike Blog

Fix: Users should upgrade to OpenAI Atlas version 1.2025.288.15 or later, which narrows access to these APIs to only the *.chatgpt.com domain.

NVD/CVE Database