aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

Gmail is going to start talking to you

infonews
industry
May 19, 2026

Google is launching Gmail Live, a new AI-powered voice mode feature that lets users speak questions aloud in Gmail instead of typing them. The feature pulls relevant information from a user's inbox to answer questions, such as details about school events or travel plans.

The Verge (AI)

Google Search is getting its biggest changes ever

infonews
industry
May 19, 2026

Google Search is being redesigned to better integrate AI features, including AI Overviews (AI-generated summaries at the top of search results) and AI Mode (a chatbot-like search experience). The new search box, powered by Gemini 3.5 Flash model, expands for longer queries and includes AI-powered autocomplete to help refine questions.

Google Pics is a new app that tries to fix AI image editing

infonews
industry
May 19, 2026

Google is launching Pics, a new AI image generation app for Workspace that uses Gemini and Google's Nano Banana 2 image model to make editing easier. Instead of rewriting entire prompts to change small details, users can click on specific parts of an image and leave notes describing what they want to change, similar to commenting in Google Docs.

Would you let robots spend your money? Google is betting on it

infonews
industry
May 19, 2026

Google is expanding its AI shopping tools by introducing a 'Universal Cart' that lets users add products from different retailers while browsing Google Search and chatting with Gemini (Google's AI assistant), then checkout directly through Google. The cart will also track prices, notify users about stock availability, suggest discounts, and flag potential problems with selected items.

Google is trying to make deepfake detection more accessible for everyone

infonews
safety
May 19, 2026

Google is making it easier for people to detect deepfakes (synthetic media created by AI to look real) by adding detection tools to Chrome and Search. The tools will check for SynthID, which is invisible watermarking technology that marks images made with Google's AI tools, and C2PA content credentials (metadata that shows how content was created or changed), helping users understand whether online content is authentic or manipulated.

Anthropic hires OpenAI co-founder Andrej Karpathy, former Tesla AI leader

infonews
industry
May 19, 2026

Andrej Karpathy, an AI researcher who co-founded OpenAI and later led Tesla's computer vision team, has joined Anthropic as a senior hire. At Anthropic, he will build a team focused on using Claude (the company's LLM, or large language model, a type of AI trained on text) to improve pretraining research, which helps AI models learn their core knowledge and abilities. This hire is part of Anthropic's ongoing competition with OpenAI to attract top talent in the AI field.

GHSA-jwp7-wg77-3w9v: Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

mediumvulnerability
security
May 19, 2026
CVE-2026-46341

A domain allowlist (list of approved websites) in the Apify Model Context Protocol server is bypassed because it uses simple string prefix matching instead of proper URL validation. An attacker can create a fake subdomain like `https://docs.apify.com.evil.com/` that passes the check, allowing the tool to fetch arbitrary content from attacker-controlled servers and return it to the AI, which can lead to prompt injection (tricking the AI by hiding instructions in fetched content) and potential account compromise.

GHSA-fhvh-vw7h-9xf3: libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case

highvulnerability
security
May 19, 2026

This advisory describes a vulnerability in libcrux-ml-dsa (a cryptographic library) where signature verification produces incorrect results on AVX2 platforms (processors with a specific instruction set for fast computation) in certain edge cases. The content provided focuses on explaining how security vulnerabilities are rated and scored, but does not describe the actual technical details of the bug itself.

GHSA-4gph-2hhr-5mwg: Envoy AI Proxy - MCP Message Smuggling Vulnerability

mediumvulnerability
security
May 19, 2026

Envoy AI Gateway has a vulnerability where it improperly parses JSON-RPC messages (a protocol for remote procedure calls) in a case-insensitive way, even though the specification requires case-sensitive matching. This allows attackers to send messages with duplicate fields using different capitalization (like 'name' and 'Name'), causing the gateway to alter and forward a different request than what was originally sent, potentially bypassing security checks in systems that use this gateway.

GHSA-3875-8gcx-7v46: n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

mediumvulnerability
security
May 19, 2026

A security flaw in n8n (a workflow automation tool) allowed authenticated users to bypass restrictions on which websites could receive sensitive credentials, potentially exposing them. The vulnerability was in an endpoint (a URL that accepts requests) that didn't properly check the intended security rules before sending data to external servers.

Musk v Altman: tech bros at war over OpenAI – The Latest

infonews
industry
May 19, 2026

Elon Musk and Sam Altman, two tech billionaires, have been involved in a lengthy legal dispute over OpenAI (an AI company), with Altman winning the case so far. Musk has indicated he plans to appeal the verdict. The trial raised questions about how major technology companies operate and their involvement in the global competition to develop advanced AI systems.

GHSA-2vx9-7wpg-88jq: n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

mediumvulnerability
security
May 19, 2026

A vulnerability in n8n's `ExecuteWorkflow` node allowed authenticated users to read arbitrary files from the server by bypassing file access restrictions through the REST API (a web-based interface for controlling the software). An attacker could discover if files exist on the server or potentially load and execute workflow files, affecting connected systems.

GHSA-x5w9-xh9r-mvfc: Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

mediumvulnerability
security
May 19, 2026
CVE-2026-45692

Caddy has an authorization bypass vulnerability in its `/config` API where the authorization layer and the traversal layer disagree on which object a path refers to. An admin client restricted to `/config/apps/http/servers/srv/routes/0` can access a different array element by requesting `/config/apps/http/servers/srv/routes/01` because the authorization layer uses string prefix matching while the traversal layer parses array indices numerically, causing the request to actually target `routes[1]` instead of `routes[0]`.

GHSA-hv85-774v-26fg: auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs

highvulnerability
security
May 19, 2026

The `download_media` and `auth_fetch` tools in auth-fetch-mcp accept any URL without validation, allowing an attacker (via prompt injection or a malicious MCP client) to make the server fetch from private or internal services like cloud metadata endpoints or localhost, and then exfiltrate the response data. The `download_media` tool makes this worse by saving fetched content to disk where it can be read and stolen.

GHSA-xmpw-2vmm-p4p6: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

criticalvulnerability
security
May 19, 2026
CVE-2026-45758

An attacker published malicious code in guardrails-ai version 0.10.1 on PyPI (a package repository where developers download Python libraries), but PyPI removed it within 2 hours and found no evidence that user data was stolen through this compromise. This is an example of a supply chain attack, where someone tries to harm users by corrupting a widely-used software package.

GitHub scales back bug bounties, reminds users security is their responsibility too

infonews
securityindustry

GHSA-27f5-xjrr-q9ff: Malware in @opensearch-project/opensearch

criticalvulnerability
security
May 19, 2026

An attacker gained unauthorized access to the OpenSearch Project's CI infrastructure (the automated system that builds and releases code) and injected malware into four versions of the `@opensearch-project/opensearch` package released on May 12, 2026. Any computer that installed these compromised versions between 00:00-10:00 UTC on May 12, 2026 should be considered fully compromised.

Hard-Label Black-Box Attacks on 3D Point Clouds

inforesearchPeer-Reviewed
research

Lightweight Privacy-Preserving and Fault-Tolerant Truth Discovery for Mobile Crowdsensing Systems

inforesearchPeer-Reviewed
security

Palladium: Guarding Neural Network Training With Confidential Computing

inforesearchPeer-Reviewed
security
Previous220 / 486Next
The Verge (AI)
The Verge (AI)
The Verge (AI)
The Verge (AI)
CNBC Technology
GitHub Advisory Database
GitHub Advisory Database
GitHub Advisory Database

Fix: The issue has been fixed in n8n version 2.20.0. Users should upgrade to this version or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should restrict n8n access to fully trusted users only and limit credential sharing to users who genuinely require access to those credentials, though these workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

GitHub Advisory Database
The Guardian Technology

Fix: Upgrade to n8n version 2.20.0 or 2.19.3 or later. If upgrading is not immediately possible, administrators can temporarily restrict workflow creation and editing permissions to trusted users only, and restrict network access to the n8n REST API to trusted users only. However, these workarounds do not fully remediate the risk and should only be used as short-term measures.

GitHub Advisory Database
GitHub Advisory Database

Fix: The source text describes the fix shape but does not provide an explicit implementation or version update: 'after URL parsing, resolve to IP, reject if private/loopback/link-local. Same defense as the well-known SSRF-guard pattern shipped by other MCP fetchers in the ecosystem (e.g., `Akitaroh/scraper-mcp` `src/security/url-guard.ts`).' However, no patched version, release number, or completed code fix is provided in the source.

GitHub Advisory Database

Fix: Downgrade to guardrails-ai==0.10.0, which is unaffected. Alternatively, install from GitHub using `pip install git+https://github.com/guardrails-ai/guardrails.git@v0.10.0`. If you installed 0.10.1, rotate all credentials accessible from that machine (GitHub PATs, cloud provider keys, package registry tokens, API keys) and audit your GitHub account for unauthorized workflows or repositories. Snowglobe and Guardrails Hub users should rotate API keys before 2:00 PM Pacific on May 13, 2026, when all existing keys will be invalidated.

GitHub Advisory Database
May 19, 2026

GitHub is replacing cash bounties with swag rewards for low-impact bug reports and asking researchers to stop submitting low-quality reports, because AI tools have flooded the platform with submissions that don't represent real security risks. The company clarified that many rejected reports describe scenarios where users must actively engage with malicious content (like cloning a malicious repository), which means the security boundary lies with the user's decision to trust that content rather than with GitHub's security controls.

Fix: GitHub requires that all AI-generated submissions must be reviewed and validated by a human first, a rule that applies to any tool used to help with bug hunting. The company also publishes a list of submission types that are ineligible for rewards, which it uses to screen out reports without proof of concept and theoretical attack scenarios that don't hold up under scrutiny.

CSO Online

Fix: Immediately rotate all secrets and keys (like passwords and authentication tokens) from an alternate, uncompromised system. Remove the affected packages from the compromised computer, though this may not eliminate all malicious software already installed. Any computer running the affected versions during the compromise window should be considered fully compromised and handled accordingly.

GitHub Advisory Database
security
May 19, 2026

Researchers developed a new method to attack 3D point cloud models (AI systems that process 3D sensor data) using only the final prediction label, without needing access to the model's internal details or calculations. Their technique uses a spectrum-aware decision boundary algorithm to create adversarial examples (slightly modified inputs that fool the AI) that are harder to detect and more practical to deploy in real-world scenarios than existing attack methods.

IEEE Xplore (Security & AI Journals)
May 19, 2026

Mobile crowdsensing (MCS, a system where mobile users contribute data to solve problems) needs ways to verify that the collected data is truthful while protecting people's privacy. This paper proposes two new truth discovery schemes: RsAnonTD for systems with a stable group of users, and McFeKDeTD for systems where workers join and leave dynamically. Both schemes use cryptographic techniques (ring signature, perturbation, and functional encryption with zero-knowledge proofs, which are mathematical ways to verify information without revealing details) to keep data private and defend against attacks like data forgery and tampering, while also reducing computational overhead by up to 98% compared to existing approaches.

Fix: The paper proposes two fault-tolerant and privacy-preserving truth discovery solutions: (1) RsAnonTD, which integrates ring signature with the perturbation technique for stable user groups, and (2) McFeKDeTD, a multi-client inner product functional encryption scheme with a lightweight zero-knowledge proof protocol, designed for systems with dynamically changing workers. Both schemes are designed to preserve privacy of sensory data, weights, and estimated truths while resisting active attacks.

IEEE Xplore (Security & AI Journals)
research
May 19, 2026

Palladium is a system that protects private training data and model parameters when training deep neural networks (DNNs, AI systems with many layers that learn patterns from data) on remote cloud servers with GPUs. The system uses TEEs (trusted execution environments, secure areas of a processor that are isolated from the rest of the system) combined with a "Cloak" strategy to hide sensitive information while still allowing most computations to run on untrusted accelerators, achieving both privacy protection and reasonable performance.

IEEE Xplore (Security & AI Journals)