All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
A US Commerce Department report criticizes NIST (National Institute of Standards and Technology) for a growing backlog of unprocessed vulnerabilities in the NVD (National Vulnerability Database, a catalog of known security flaws). The backlog has worsened due to budget cuts, increased vulnerability discoveries from AI tools, and inefficient coordination between NIST and CISA (Cybersecurity and Infrastructure Security Agency), including duplicated work and failure to share data despite having access to the same public information.
Fix: The report states that 'NIST must improve the efficiency of enrichment processes to ensure sustainability' and notes that 'before system updates and subsequent process changes were completed in March 2025, NIST refused to use CISA's data.' The source indicates technical updates to the NVD system were needed 'to incorporate CISA's enrichment data because the system lacked the capability to attribute data to specific sources,' and these updates were completed in March 2025, allowing NIST to leverage CISA's data to expedite backlog reduction.
CSO OnlineCVE-2026-47644 is an injection vulnerability (a flaw where specially crafted input is not properly filtered before being used by another part of the system) in Microsoft Edge's Copilot Chat that allows an attacker to disclose information over a network without authorization. The vulnerability involves improper neutralization of special elements in output, meaning the system doesn't properly clean or validate data before passing it to other components.
CVE-2026-45497 is a command injection (a flaw where special characters in user input are not properly filtered, allowing an attacker to insert and run unintended commands) vulnerability in Microsoft Copilot that lets an authorized attacker execute code over a network. The vulnerability has not yet received a CVSS score (a 0-10 rating of how severe a vulnerability is) from NIST.
CVE-2026-42824 is a command injection vulnerability (a flaw where an attacker inserts malicious commands into user input that gets executed by the system) in Microsoft 365 Copilot that allows an unauthorized attacker to disclose information over a network. The vulnerability stems from improper neutralization of special elements in commands. A CVSS score (a 0-10 rating of how severe a vulnerability is) has not yet been assigned by NIST.
OpenMeter has a SQL injection vulnerability (a flaw that lets attackers insert malicious database commands) in its meter creation endpoint. An authenticated tenant can inject arbitrary SQL through the `valueProperty` or `groupBy` fields, bypassing validation and executing commands against the shared ClickHouse database (the system that stores event data for all tenants), allowing any tenant to read or modify other tenants' metering data.
This article is about a political dispute, not an AI or LLM security issue. It discusses UK Prime Minister Keir Starmer criticizing Elon Musk for posts on X (a social media platform) related to a murder case, but contains no technical content about artificial intelligence, large language models, cybersecurity, or software vulnerabilities.
OpenAI has proposed a federal governance framework for frontier AI (the most advanced AI systems) that requires mandatory evaluations by a government body before public release, but stops short of giving regulators the power to block deployments. The proposal also includes broader requirements like third-party audits, transparency reports, incident reporting, and whistleblower protections for frontier AI developers, arguing that voluntary commitments alone are insufficient as AI systems become more capable.
A vulnerability exists in Milvus (a vector database software) versions up to 2.6.13 where the Grantee ID Hash Handler component uses weak hash (a cryptographic function that is easy to break). An attacker would need local access to the system and would face high complexity in exploiting it, though the vulnerability details have been publicly disclosed.
A security flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack repositories by opening a single malicious GitHub issue that exploited a broken permission check and indirect prompt injection (tricking an AI by hiding instructions in its input). The vulnerability let attackers steal credentials needed to gain write access to code and workflows, potentially poisoning the Claude Code Action itself for downstream projects that use it.
This security bulletin covers multiple threats: Cisco released patches for a high-severity SSRF vulnerability (server-side request forgery, where attackers trick a server into making unwanted requests) in Unified Communications Manager that could let unauthenticated attackers write files and gain root access; Russia's FSB reported foreign intelligence services deployed spyware on officials' mobile devices to steal data and conduct surveillance; threat actors are using social engineering to distribute VIP Keylogger through JavaScript, batch, and VBS loaders disguised as business communications; and the U.S. Treasury sanctioned Iran's largest cryptocurrency exchange for facilitating payments linked to terrorist activities and ransomware actors.
This article discusses a podcast interview about Elon Musk's planned SpaceX IPO (initial public offering, when a private company sells shares to become publicly traded) and the state of X (formerly Twitter). The interview explores how Musk may be bending corporate governance rules (the systems that keep companies accountable to shareholders and investors) to make the SpaceX IPO happen, and examines whether Musk's 2022 purchase of Twitter has damaged his reputation and businesses as predicted.
SolarWinds Serv-U has a vulnerability that allows attackers to crash the service by sending specially crafted requests with a specific header (Content-Encoding: deflate) without needing to log in first. This flaw is currently being exploited by attackers in the real world.
Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. See SolarWinds security advisories and release notes (Serv-U 15.5.4 Hotfix 1) for specific patching details.
CISA Known Exploited VulnerabilitiesCrowdStrike CEO George Kurtz stated that growing concerns about AI-powered cyber threats are creating business opportunities for his company, as enterprises seek security solutions to safely deploy AI across their organizations. He noted that demand for CrowdStrike's AI Detection and Response platform (a tool that finds and responds to AI-related security attacks) is accelerating, with the company's second quarter pipeline exceeding $50 million and growing 250% sequentially. Kurtz argued that AI is actually increasing the need for cybersecurity by making attackers more sophisticated, rather than reducing it.
Anthropic co-founder Jack Clark warns that AI is advancing so rapidly it could soon develop without human control, and he calls for a regulatory 'brake pedal' (a way to slow or pause AI progress) to keep society in control of these increasingly powerful systems. He notes that Anthropic's Claude chatbot already writes 80% of its own code, and reaching 100% is possible within two years, which would have major implications for society.
Gartner analysts warn about four critical threats where attackers currently have an advantage, including deepfakes (AI-generated fake videos or images) and prompt injection (tricking an AI by hiding malicious instructions in its input). The analysts are urging organizations to strengthen their security defenses against these emerging threats.
Microsoft's AI Red Team updated their taxonomy of failure modes in agentic AI systems (AI systems that can autonomously perform tasks) from v1.0 to v2.0 based on 12 months of real-world security testing. The update added seven new failure mode categories, including agentic supply chain compromise (injecting malicious instructions into tool registries), goal hijacking (redirecting an agent's objectives through disguised commands), and inter-agent trust escalation (one compromised agent deceiving others about its permissions). The revision was driven by rapid adoption of open-source agentic frameworks, widespread vulnerabilities in tool ecosystems, and the emergence of computer-use agents that interact with graphical interfaces.
Fix: Replace `fmt.Sprintf` string interpolation with `sb.Var()`, which appends the value to the builder's args list and emits a `?` placeholder. Specifically, change: `sb.Select(fmt.Sprintf("JSON_VALUE('{}', '%s')", sqlbuilder.Escape(d.jsonPath)))` to `sb.Select(fmt.Sprintf("JSON_VALUE('{}', %s)", sb.Var(d.jsonPath)))`.
GitHub Advisory DatabaseFix: Apply the patch identified as 3d932f1c3e065351c4440c27abe1e6479752544d to fix this issue.
NVD/CVE DatabaseFix: Update to claude-code-action v1.0.94 or later. Then audit any workflow that lets users without write access or bots trigger Claude: if it takes untrusted input, limit secrets to only the Anthropic API key and GITHUB_TOKEN, and remove tools and permissions that could be used for stealing data.
The Hacker NewsAgentic AI (AI systems that can take independent actions across networks) is being deployed in U.S. defense networks, but security risks are growing just as fast, especially after an unauthorized group reportedly accessed Anthropic's Claude Mythos model within hours. The article emphasizes that AI is only as trustworthy as the data it uses, the networks it connects to, and the security controls protecting it, requiring careful attention to what data enters the model, who can access it, and where the AI sends requests.
Offroad, a new startup, uses agentic AI (AI systems that can take autonomous actions) to help organizations find and fix identity risks across their systems. The company addresses a growing problem where identities (human users, machines, and AI agents) are spreading across many systems, making it difficult for security teams to manually manage access and permissions, especially as AI agents operate at scales and speeds humans cannot match.
Fix: Offroad's approach, as described in the source, is to 'use its own autonomous agents to find the issue, gather the context necessary to understand the problem, and then fix it.' The system either reports details to a human for review or takes autonomous action wherever safe. Additionally, Offroad has launched ohauth.ai, described as 'A community catalog of OAuth apps (third-party applications with delegated access) with over-privileged scopes, dead publisher domains, and silent permission drift' to help organizations identify risky applications.
SecurityWeekWillow, an Israeli startup, launched a platform that manages identity and access for AI agents (autonomous systems that perform tasks independently) in enterprises, securing tools like Claude and ChatGPT through centralized control. The platform assigns verified identities to each AI agent, restricts which systems they can reach using least-privilege access (allowing only the minimum permissions needed), and detects unauthorized AI usage across a company's network. With $7 million in funding, Willow aims to let companies safely deploy AI agents without giving them unrestricted access to sensitive systems and data.
AI is making it faster for attackers to turn newly discovered vulnerabilities into working exploits, with exploitation timelines shrinking from days or weeks to just hours. Security teams are overwhelmed with too many vulnerability alerts to handle, so they need to focus on identifying which exposures actually matter by evaluating reachability (can attackers access it?), exploitability (can it be compromised?), and business impact. To address this, organizations should use AI-powered scanning tools to find complex attack chains and prioritize vulnerabilities based on real-world risk rather than just volume.
Fix: The source mentions that organizations should use Wiz Attack Surface Management (ASM), which combines external visibility of internet-facing assets with internal cloud context to help identify and reduce critical exposures. However, the text is cut off and does not provide specific implementation details or complete mitigation steps beyond recommending this tool approach.
Wiz Research BlogFix: Cisco has addressed the SSRF vulnerability in Unified CM and Unified CM SME Release versions 14SU6 and 15SU5.
The Hacker News