aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

Anthropic set to hit $10.9 billion in revenue during second quarter, source says

infonews
industry
May 20, 2026

Anthropic, an AI company known for its Claude models, is on track to generate $10.9 billion in revenue during the second quarter of 2026, which would mark its first profitable quarter and more than double its first-quarter revenue of $4.8 billion. The company has experienced explosive growth driven by enterprise demand, consumer usage, and government interest, though it faces intense competition from other AI companies like OpenAI.

CNBC Technology

Nvidia’s revenue blows past Wall Street expectations as AI boom accelerates

infonews
industry
May 20, 2026

Nvidia's financial results exceeded Wall Street predictions, driven by continued demand for AI infrastructure and datacenters. CEO Jensen Huang emphasized that the expansion of AI computing facilities is accelerating rapidly, and that agentic AI (AI systems that can independently plan and execute tasks to accomplish goals) is now being deployed across businesses and generating measurable value.

‘Solve all diseases,’ you say?

infonews
industry
May 20, 2026

At Google I/O, DeepMind CEO Demis Hassabis announced that Google aims to use AI to transform drug discovery and eventually solve all diseases. The article appears to be a critical analysis examining the feasibility and implications of this ambitious claim.

Why Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflows

infonews
securitypolicy

FARO-Droid: Reliability-aware fusion for obfuscation-resilient Android malware detection

inforesearchPeer-Reviewed
security

Defensive Cybersecurity Behavior in Hospitals: The Role of Leadership, Human-Centric Capabilities, and Compliance

inforesearchPeer-Reviewed
security

FastPoS: An efficient proof of storage scheme with polynomial commitments for fog-cloud IoT systems

inforesearchPeer-Reviewed
research

Cheap AI could derail OpenAI and Anthropic's IPOs

infonews
industry
May 20, 2026

OpenAI and Anthropic's expected IPO valuations (both projected over $800 billion) depend on maintaining high pricing power, but cheaper AI alternatives are rapidly emerging and becoming competitive. Chinese AI labs like DeepSeek and Kimi charge a fraction of what OpenAI and Anthropic do for comparable work, and enterprises are adopting cost-reduction strategies like "advisor models" (where a cheap open-source model handles most tasks and only calls expensive frontier models when needed), causing usage of Chinese models on some platforms to jump from 1% to 60% in just one year.

OpenAI to confidentially file for IPO as soon as Friday: Source

infonews
industry
May 20, 2026

OpenAI is preparing to confidentially file documents for an IPO (initial public offering, when a private company becomes publicly traded) as soon as this week, working with major investment banks like Goldman Sachs and Morgan Stanley. The company, valued at over $850 billion, is planning this public debut as part of normal strategic planning, though leadership hasn't confirmed a specific timeline.

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

infonews
securityresearch

You can now remix other people’s YouTube Shorts with AI

infonews
industry
May 20, 2026

Google has introduced a new YouTube Shorts Remix feature that uses Gemini (Google's AI model) to let users restyle or modify other people's videos. Users can transform clips into different art styles like pixel art or anime, or digitally alter content by changing appearances, adding people, or inserting themselves into videos. Creators can choose whether to allow or block others from remixing their videos.

Google Search’s AI evolution includes more ads

infonews
industry
May 20, 2026

Google is integrating its Gemini AI model into search ads, which will now display recommended products with AI-generated explanations of why you should buy them. This update is part of Google's broader shift toward AI-powered search results, including a new conversational search box and AI-generated content alongside traditional search results.

GitHub admits major source code leak after 3,800 internal repositories breached

highnews
security
May 20, 2026

GitHub confirmed that attackers compromised an employee's device through a poisoned VS Code extension (a malicious add-on program for a code editor), leading to the theft of code from around 3,800 internal repositories. The breach was detected and contained quickly, and GitHub is investigating the incident while validating that no customer data was affected, only internal GitHub code.

GHSA-c2c9-mfw7-p8hw: Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows

mediumvulnerability
security
May 20, 2026

Flowise has a security flaw in its `/api/v1/chatflows/apikey` endpoint that allows a user with a valid API key to view chatflow configurations (including system prompts, workflow graphs, and credential IDs) from other workspaces, as long as those chatflows don't have an API key assigned. The endpoint returns both the user's own chatflows and all unprotected chatflows across the entire system without filtering by workspace, breaking the isolation between workspaces.

GHSA-59fh-9f3p-7m39: Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification

mediumvulnerability
security
May 20, 2026

Flowise has a mass assignment vulnerability in its PUT /api/v1/user endpoint that lets authenticated users directly change their password hash without verifying their old password. An attacker with a stolen session token can send a crafted request that overwrites the credential field, bypassing password verification, hashing enforcement, and policy validation, which gives them permanent access to the account.

GHSA-m837-xvxr-vqwg: Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage

mediumvulnerability
security
May 20, 2026

Flowise, an AI tool, has a hardcoded setting that allows any webpage on the internet to make requests to its text-to-speech (TTS, a feature that converts written text into spoken audio) endpoint using your stored credentials. This bypasses the server's normal cross-origin request protection (CORS, which controls what websites can access a server's data), letting malicious webpages secretly generate speech on your behalf.

GHSA-mw8f-w6p8-xrf4: wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None

highvulnerability
security
May 20, 2026

Wger, a fitness tracking application, has a security flaw where gym staff members with `gym.manage_gym` permission but no assigned gym (gym = None) can delete, deactivate, or reactivate any other users who also have no assigned gym. This happens because the authorization check uses a comparison that treats two `None` values as equal, bypassing the intended access control. Three views in the application were not fixed when this bug was patched elsewhere.

Google I/O, Gemini Spark, Antigravity

infonews
securitysafety

GHSA-7wx4-6vff-v64p: Diffusers: TOCTOU Trust Remote Code Bypass

highvulnerability
security
May 20, 2026
CVE-2026-45804

The `diffusers` package has a TOCTOU (time-of-check-time-of-use, where a security check happens at one moment but the actual data used comes from a different moment) vulnerability in its `DiffusionPipeline.from_pretrained` function that loads models from HuggingFace Hub. An attacker can bypass the `trust_remote_code` security check by updating a repository between two separate download calls, allowing arbitrary code to execute without the user explicitly approving it.

GHSA-fvvm-949w-qj4w: RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM

mediumvulnerability
security
May 20, 2026
CVE-2026-45792

RTK (Rust Token Killer, a tool that filters sensitive data before showing command output to an LLM) had a vulnerability where it automatically loaded filter configuration files from a project directory without asking the user first, allowing attackers to secretly modify what an LLM sees. An attacker could place a malicious filter file in a repository to hide or alter command output (like file contents or security scan results) without any warning, potentially concealing malicious code during development.

Previous216 / 486Next
The Guardian Technology
The Verge (AI)
May 20, 2026

AI agents (autonomous systems using LLMs to solve problems) create security risks because LLMs are unpredictable and vulnerable to prompt injection (tricking an AI by hiding instructions in its input), so they can make harmful decisions with confidence. The solution is to place authorization controls (decisions about which actions are allowed) at the boundary where the agent calls external tools, rather than relying on hard-coded workflows or human approval alone. Amazon Bedrock AgentCore uses Cedar, an open-source authorization policy language, to centralize and enforce these controls outside the LLM where they cannot be bypassed.

Fix: Amazon Bedrock AgentCore Gateway sits between the agent and the tools it calls. When you associate a Policy (written in Cedar) with a Gateway, it blocks everything by default and selectively allows only specified tool invocations under defined conditions. Cedar is an open source authorization policy language developed by AWS that is purpose-built for authorization, readable by humans, and analyzable by machines using automated reasoning.

AWS Security Blog
May 20, 2026

FARO-Droid is a new system that uses AI to detect malware (malicious software) on Android phones by analyzing multiple types of code features and combining them intelligently, even when attackers try to hide the malware through obfuscation (code transformation techniques that make programs harder to read and analyze). The system is designed to be reliable and resistant to these hiding techniques.

Elsevier Security Journals
May 20, 2026

This academic article examines how hospital staff adopt defensive cybersecurity practices, focusing on the influence of leadership, human-centered skills, and rule-following requirements. The research explores organizational and behavioral factors that help healthcare workers protect systems and data from security threats, rather than technical fixes alone.

Elsevier Security Journals
May 20, 2026

This academic paper describes FastPoS, a new security method for verifying that data is actually stored in fog-cloud IoT systems (networks of internet-connected devices distributed between local edge servers and central cloud storage). The method uses polynomial commitments (a cryptographic technique that lets someone prove they're storing data without revealing the data itself) to make verification faster and more efficient than existing approaches.

Elsevier Security Journals
CNBC Technology
CNBC Technology
May 20, 2026

Microsoft released two open-source tools to help developers test AI agent security during development. RAMPART is a testing framework (built on PyRIT, an earlier tool) that lets developers write test cases to find safety problems like cross-prompt injections (when untrusted data reaches an AI indirectly through sources like emails or files) and data exfiltration (unauthorized data leakage). Clarity is a planning tool that guides developers through design decisions early in a project, before coding begins, so potential issues can be addressed cheaply rather than fixed later.

Fix: Microsoft provides RAMPART and Clarity as open-source tools. According to the source: RAMPART is 'a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents' that 'evaluates the outcome of those tests and reports the results.' Clarity helps developers 'arrive at the right approach even before writing a single line of code' by 'guiding them through problem clarification, solution exploration, failure analysis, and decision tracking.' Microsoft states that using these tools 'move[s] AI safety from a one-time review to a set of living artifacts that developers can use throughout the lifecycle.'

The Hacker News
The Verge (AI)
The Verge (AI)
CSO Online
GitHub Advisory Database
GitHub Advisory Database

Fix: Remove the hardcoded CORS wildcard headers from the TTS endpoint. Specifically, delete these lines from `packages/server/src/controllers/text-to-speech/index.ts` at line 83: `res.setHeader('Access-Control-Allow-Origin', '*')` and `res.setHeader('Access-Control-Allow-Headers', 'Cache-Control')`. This allows the server's standard CORS middleware to handle access control instead.

GitHub Advisory Database

Fix: The maintainer's suggested patch is to replace the vulnerable `userprofile.gym_id !=` comparisons in `wger/core/views/user.py` (affecting UserDeactivateView at line 405, UserActivateView at line 442, and the delete view at line 131) with the `is_same_gym()` helper function that explicitly excludes `None` comparisons (`gym_a is not None and gym_a == gym_b`). This helper was already successfully applied to views in `wger/gym/views/{admin_notes,document,contract,gym}.py` but must also be applied to the three unpatched views in `wger/core/views/user.py`.

GitHub Advisory Database
May 20, 2026

Google announced Gemini Spark, an upcoming AI agent product that connects with Google apps like Gmail and Drive, which runs on Gemini 3.5 Flash and a tool called Antigravity. To address prompt injection risks (tricking an AI by hiding instructions in its input), Google stated that Spark operates in isolated virtual environments with encrypted credentials, data loss prevention policies, and a secure gateway, though the author expresses concern about whether these protections are sufficient given the sensitive data users may process through it.

Fix: According to Google's documentation, Gemini Spark implements the following security measures: 'Spark operates in a fully managed, secure runtime on Google Cloud' with 'every task executes in a fresh, strictly isolated, ephemeral VM to help ensure data never overlaps between sessions.' Additionally, 'all traffic routes through our secure Agent Gateway that enforces Data Loss Prevention (DLP) policies, while user credentials remain fully encrypted and are never exposed directly to the agent.'

Simon Willison's Weblog
Hugging Face Security Advisories

Fix: Fixed in v0.32.0 (PRs #623, #625): the `.rtk/filters.toml` file is now blocked by default with a visible warning stating '[rtk] WARNING: untrusted project filters — Filters NOT applied. Run rtk trust to review and enable.' The patch also adds SHA-256 hash verification (a cryptographic check ensuring the file hasn't changed) to re-block filters if the file is modified after being trusted, and introduces new `rtk trust` and `rtk untrust` commands to let users explicitly approve configuration files.

GitHub Advisory Database