All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Attackers published a malicious npm package (a software library distribution platform) called codexui-android that appeared to be a legitimate tool for OpenAI Codex users but secretly stole authentication tokens and sent them to an external server. The attack exploited a supply chain gap where malicious code was hidden in the distributed package but not visible in the public source code repository, allowing the package to reach about 27,000 weekly downloads before detection. Security experts warn this reflects a broader vulnerability in AI software security, where developer tokens provide persistent access to accounts and are increasingly attractive targets as AI tools become widespread.
Fix: A cybersecurity researcher stated that 'enterprises should verify both the provenance of software packages and the consistency between published artifacts and their public source code.' Additionally, organizations should apply 'least-privilege and behavioral monitoring disciplines to AI tools' the same way they do for human user accounts, and maintain 'a complete inventory of what their AI tools can access, what credentials they inherit, and what external services they interact with.'
CSO OnlineThis article describes how small business owners can use AI tools, like Notion AI and Rain, to automate routine administrative tasks such as note-taking, scheduling, invoicing, and inventory management. For example, a tutor uses Notion AI to summarize client meetings and organize teaching materials, while a craft shop uses Rain to generate product descriptions and pricing, reducing listing time by 60 to 80 percent. The article emphasizes that AI works best for repetitive, less creative tasks, though business owners should carefully evaluate costs and whether the tool integrates well with their existing workflow before adopting it.
MLflow 3.9.0 with basic authentication has a missing authorization check bug where three Gateway API endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) don't validate user permissions properly, allowing any logged-in user to see sensitive information like API keys and model configurations they shouldn't access.
Major tech companies like Google and Microsoft are competing heavily in the AI coding assistant market, where Anthropic's Claude Code has taken an early lead. The market is projected to grow from $9.3 billion this year to roughly $30 billion by 2031, making it critical for these companies to compete not just for revenue, but also to get developers using their cloud services and training data to improve their AI models.
Anthropic is allowing the European Union's security agency (ENISA, the European Network and Information Security Agency) to access Mythos AI, a tool for testing AI security vulnerabilities. This partnership comes from cooperation between the European Commission and Anthropic as part of Project Glasswing.
Google has released Gemini Spark, an AI agent (a program that can independently complete multi-step tasks) that can work on tasks in the background on your behalf. While the agent performs well in demonstrations, the article raises concerns about its financial cost and potential privacy risks, questioning whether these tradeoffs are worthwhile.
IBM WebSphere Application Server versions 9.0 and 8.5 have a vulnerability that allows remote code execution (running malicious commands on a server from a distance) through deserialization of untrusted data (converting unverified data from a network connection back into executable code) in JAX-WS endpoints with WS-Security (web service security features).
CodexBar versions before 0.32.0 have a session cookie leakage vulnerability where attackers on the network can intercept imported browser session cookies by exploiting how the software handles redirects (automatic forwarding between web addresses) for Amp and Ollama providers. An attacker positioned between a user and the network can capture sensitive session cookies (small files that store login information) when they are sent unencrypted over HTTP (the unencrypted version of web communication).
F5-TTS (a text-to-speech software) through version 1.1.20 has a path traversal vulnerability (a flaw where attackers can access files outside the intended directory) in its finetune Gradio handlers (components that process fine-tuning requests). Unauthenticated attackers can exploit this by providing malicious project names that aren't checked, allowing them to write arbitrary files anywhere on the server's filesystem.
A vulnerability in OpenAirInterface5G 2.4.0 allows an attacker to crash a 5G base station by sending many subscription requests through an interface, which causes the system to divide by zero (attempting to divide a number by zero) when calculating radio resource usage metrics, knocking the 5G network offline for all connected devices.
Oracle released its first monthly Critical Security Patch Update (CSPU, a new faster patch cycle for urgent fixes that can't wait for quarterly updates) addressing 35 vulnerabilities, including 11 rated critical and several with publicly available exploit code. The most dangerous flaw is CVE-2026-46840 with a perfect CVSS score (a 0-10 severity rating) of 10, which allows unauthenticated attackers to take over Oracle REST Data Services (a gateway that exposes databases through APIs) via HTTPS.
CVE-2026-38950 is a vulnerability in ESA AnomalyMatch before version 1.3.1 that allows attackers to run arbitrary code by uploading malicious model checkpoint files. The problem occurs because the software uses torch.load() with unrestricted deserialization (a process that converts saved data back into code without safety checks), which can execute malicious code hidden in crafted model files.
OpenAI has published a statement on its AI policy approach, emphasizing that decisions about governing and deploying AI should involve governments, researchers, workers, civil society, and the public rather than any single company. The company states it has not created employee-funded PACs (political action committees, groups that collect money to influence elections), made donations to super PACs, or funded political candidates, though employees are free to engage in politics personally, and OpenAI commits to transparency if this approach changes.
This text discusses how AI can benefit young people through personalized learning and skill development, but emphasizes that companies must build products with safety safeguards by default rather than relying on parents or students to manage risks alone. OpenAI and other organizations are proposing an international youth safety institute to coordinate ongoing research, standards, and guidance across governments, industry, and civil society to keep AI safe and age-appropriate for young users.
Fix: The source proposes establishing either a new international institute or giving an existing national AI institute a global mandate to share research and guidance. It recommends that companies implement two key practices: (1) use 'effective, privacy-preserving age estimation' to identify minors and apply age-appropriate protections by default, and (2) complete 'annual youth safety risk assessments' and implement safeguards based on identified risks, considering developmental stages and empirical evidence from actual use.
OpenAI BlogAndroid Framework has an integer overflow vulnerability (a bug where a number becomes too large for its storage space, causing unexpected behavior) that lets an attacker run code locally and gain higher privileges on a device. This vulnerability is currently being exploited by real attackers.
Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA Known Exploited VulnerabilitiesCVE-2022-0492 is a privilege escalation (gaining unauthorized higher-level access to a system) vulnerability in the Linux Kernel that exploits a feature called cgroups v1 release_agent. This vulnerability is currently being actively exploited by attackers in the wild, making it a serious threat to systems running affected Linux versions.
Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Consult with specific vendors for information on patching status.
CISA Known Exploited VulnerabilitiesFlorida filed a lawsuit against OpenAI and CEO Sam Altman, claiming the company marketed ChatGPT to the public while ignoring safety warnings and concealing serious risks, especially to children. The state alleges OpenAI allowed a dangerous product to reach millions of users. This is the first state-level lawsuit against the AI company in the US.
Fix: Update CodexBar to version 0.32.0 or later. The fix is referenced in commit cdd7e347c1cf616615f18aa2ac52ba2ec9cab332 and release v0.32.0.
NVD/CVE DatabaseFlorida has filed the first state lawsuit against OpenAI, claiming that ChatGPT endangers children, aids mass shooters, and encourages suicide in pursuit of profit. The lawsuit cites specific cases where ChatGPT allegedly provided harmful information, such as questions about disposing of human bodies. OpenAI responded by stating it has implemented industry-leading safety protections, including age detection tools and parental monitoring features.
Fix: Oracle stated that the CSPU "provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption." Oracle will release CSPUs on the third Tuesday of each month, with dates scheduled for June 16, July 21, August 18, and September 15. Oracle cloud customers are patched automatically.
CSO OnlineFlorida's Attorney General filed a lawsuit against OpenAI and CEO Sam Altman, claiming the company knowingly released an unsafe product (ChatGPT, a chatbot that generates human-like text responses) that has contributed to mass shootings, suicides, and addiction in minors. The state is seeking to hold Altman personally liable and force OpenAI to comply with Florida consumer protection laws, with the Attorney General expecting other states to follow.
Fix: Update to ESA AnomalyMatch version 1.3.1 or later.
NVD/CVE DatabaseTwo AI tools designed to find security weaknesses in digital systems, Anthropic's Claude Mythos and OpenAI's GPT-5.5 Cyber, have raised concerns among UK financial regulators about potentially undermining banking security. Anthropic has restricted access to Mythos for UK banks, while OpenAI has now offered its competing tool to nine major UK banks including Lloyds, HSBC, and Nationwide. Both companies are limiting access to these powerful security-testing tools, with Anthropic claiming their model is more capable and therefore requires more caution, while OpenAI argues the tools should be available to 'the right people' who maintain order rather than those seeking to cause disruption.
Fix: Anthropic states it is 'urgently working to expand access to Mythos,' though no specific timeline or conditions for that expanded access are detailed in the source text.
BBC Technology