All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
This research paper proposes E2E-PP, a system that protects privacy in mobile crowdsensing (collecting data from many mobile devices) by combining compressive sensing (a technique that reduces data size while preserving important information) with personalized differential privacy (a method that adds customized noise to data to prevent identifying individuals). The system aims to let mobile devices share sensor data for collective purposes while keeping personal information private.
OpenAI's Codex, an AI tool that helps developers write and manage code, has been recognized as a Leader by Gartner in enterprise coding agents. Codex goes beyond simple autocomplete (where an AI completes code as you type) by letting developers delegate complex tasks like understanding large codebases, running tests, and preparing work for human review while maintaining security and governance controls. The recognition highlights Codex's strengths in enterprise features like approval gates, RBAC (role-based access control, which limits what different users can do), sandboxing (isolating code in a safe environment), and audit trails.
Network-AI v5.4.4 has a critical authentication bypass where the MCP server (a tool that lets AI models call external functions) defaults to an empty secret, causing all authentication checks to pass unconditionally. Additionally, the server allows requests from any origin (CORS wildcard), so an attacker can trick a user into visiting a malicious website that sends commands to their localhost Network-AI server without needing any password, potentially invoking dangerous tools like config_set and agent_spawn.
Boxlite, a sandbox service for running containers, has a path traversal vulnerability (a security flaw where attackers can access files outside intended boundaries) in how it extracts container images. When processing tar files (compressed archives), Boxlite doesn't validate symlink targets (shortcuts to files or directories), allowing an attacker to create a malicious container image that writes files anywhere on the host system, potentially leading to remote code execution (running unauthorized commands on the computer).
BoxLite is a sandbox service that runs untrusted code in lightweight virtual machines (VMs, which are isolated computing environments). It claims to protect host files by mounting directories in read-only mode (preventing writes), but the vulnerability bypasses this: BoxLite tells the underlying VM system (libkrun) to mount directories without actually enforcing read-only restrictions, and it doesn't limit container capabilities (special permissions), so malicious code can remount directories as read-write and modify files that should be protected.
Pydantic AI had a security flaw where attackers could bypass protections against accessing cloud-metadata endpoints (special internal servers that store sensitive credentials) by encoding the IP address in IPv6 transition forms (IPv4-mapped IPv6, 6to4, or NAT64, which are ways to represent IPv4 addresses using IPv6 format). This flaw only affects applications that explicitly allow local file downloads with the `force_download='allow-local'` setting on URLs that could be influenced by untrusted users.
Twig (a template engine) versions 3.24.0 and later had a vulnerability where object-destructuring assignment (a syntax for extracting values from objects) bypassed the sandbox security feature (a restriction system that controls what properties and methods templates can access). An attacker who could write to a sandboxed template could read any public property or call any public method, defeating the security restrictions that should have prevented this.
ChromaDB, a popular vector database used in AI applications, has a critical vulnerability (CVE-2026-45829) that allows unauthenticated attackers to run arbitrary code on servers. The flaw exists because ChromaDB checks authentication after it has already downloaded and executed a malicious model from Hugging Face, meaning attackers can trick the system into running their code by uploading a malicious model and requesting ChromaDB to use it.
Twig (a PHP template engine) has a vulnerability where template names in `{% use %}` tags aren't properly escaped, allowing attackers to inject arbitrary PHP code that executes when the template cache loads. This bypasses Twig's security sandbox, giving attackers remote code execution (the ability to run commands on the server).
LiteLLM versions before 1.83.10 have a vulnerability where users can change their own role to proxy_admin (an administrative role) through the /user/update endpoint, giving them full control over the system including all users, teams, and API keys. Even users with org_admin privileges can exploit this flaw without needing to chain it with other attacks.
LiteLLM versions before 1.83.14 have a privilege escalation vulnerability (a security flaw that lets someone gain higher-level permissions than they should have) where authenticated internal users can create API keys (credentials for accessing the system) that grant access to admin-only routes without proper verification. This allows attackers to bypass role-based access controls (the system that restricts what different users can do) and gain full admin privileges.
This is a discussion panel about how AI companies are working to build systems that understand the physical world, moving beyond the current limitations of LLMs (large language models, which are AI systems trained on text). The conversation explores recent developments in world models, which are AI systems designed to understand and predict how the physical world works.
The `mcp-server-kubernetes` tool had a security flaw where access control settings (environment variables that limit which Kubernetes operations are available) only worked when listing tools, but not when actually running them. This meant an attacker or misconfigured AI agent could bypass these restrictions and run any Kubernetes command, like deleting pods or accessing containers, even if they were supposed to be blocked.
Microsoft is negotiating to supply its custom Maia AI chips to Anthropic, a company that makes Claude, a popular AI assistant. This deal would help Microsoft compete with Amazon and Google in providing specialized AI hardware to clients, while Anthropic seeks to address its computing capacity challenges after experiencing rapid growth in demand for its AI tools.
Amazon SageMaker Python SDK has a vulnerability where it stores an HMAC signing key (a cryptographic secret used to verify that model files haven't been tampered with) in plaintext as an environment variable that can be read by anyone with access to certain AWS APIs. An attacker with the right permissions could steal this key, use it to forge valid model files, and run malicious code on the system running the model.
LMDeploy, a model serving tool, hardcodes `trust_remote_code=True` (a setting that allows executing custom Python code from downloaded models) when loading models from HuggingFace. An attacker who can control which model path the system loads could point it to a malicious model repository, causing arbitrary code execution (running any commands they want) with the privileges of the LMDeploy server process. This affects LMDeploy version 0.12.3 and earlier.
Wiz has integrated with Anthropic's Claude Compliance API to give organizations visibility into how Claude Enterprise is being used across their environment. The integration lets security teams see Claude users, projects, permissions, and connected datasets mapped into Wiz's Security Graph (a centralized system for tracking and connecting all resources), helping with compliance audits and governance.
This academic paper analyzes how Internet of Things devices (smart devices connected to the internet, like security cameras or smart home systems) receive and install software updates. The research examines the mechanisms these devices use to stay current with security patches and new features. The publication appears in a peer-reviewed security journal and was made available online in May 2026.
Drupal Core has a SQL injection vulnerability (a flaw where attackers insert malicious database commands into user input) that could allow attackers to gain higher privileges and execute remote code through specially crafted requests to the database API. This vulnerability is actively being exploited in the wild, with a deadline of May 27, 2026 to address it.
Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. More details are available at https://www.drupal.org/sa-core-2026-004.
CISA Known Exploited VulnerabilitiesFix: Upgrade to Pydantic AI version 1.99.0 or later, which extends the blocklists to cover IPv6 transition forms that route to blocked IPv4 endpoints and adds protection for additional IANA-reserved IP ranges. For unpatched versions, avoid using `force_download='allow-local'` on URLs influenced by untrusted input, or resolve hostnames manually and validate them against your own blocklist including IPv6-encoded forms before creating the FileUrl.
GitHub Advisory DatabaseFix: The destructuring compiler was updated to correctly forward the active sandbox flag to the getAttribute() function so that property and method allowlists are enforced during destructuring operations.
GitHub Advisory DatabaseFix: Until a patch becomes available, researchers advise: (1) deploy ChromaDB using the Rust implementation instead of the Python FastAPI server, as the Rust version is not affected, and (2) restrict network access to the ChromaDB port to trusted IP addresses only.
CSO OnlineFix: `Compiler::string()` now escapes single quotes in addition to the characters it previously escaped, preventing template names from breaking out of the surrounding PHP string context.
GitHub Advisory DatabaseFix: Update LiteLLM to version 1.83.10 or later.
NVD/CVE DatabaseFix: Update LiteLLM to version 1.83.14 or later.
NVD/CVE DatabaseThis article discusses how security leaders (CISOs, or Chief Information Security Officers) should prepare for AI systems that can take independent actions (agentic AI). The key challenge is creating an AI bill of materials (AI BOM, a detailed list of all components and dependencies in an AI system) that documents both what components make up the AI system and how those components actually behave when running.
Fix: The fix applies the same filtering logic from the tool listing layer to the tool execution layer in the `CallToolRequestSchema` handler, so that restricted tools return an error when called directly. This was fixed in v3.6.0.
GitHub Advisory DatabaseFix: Upgrade to Amazon SageMaker Python SDK v2.257.2 or v3.8.0. According to the source: 'AWS recommend upgrading to the latest version and rebuilding any models previously created with ModelBuilder using the updated SDK.' As a temporary workaround if upgrading is not immediately possible: 'users can manually remove the SAGEMAKER_SERVE_SECRET_KEY environment variable from existing SageMaker models by recreating the model without this variable in the container environment configuration.'
GitHub Advisory Database