aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

GHSA-wp73-mwgf-4jq9: OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent

mediumvulnerability
security
May 18, 2026
CVE-2026-45676

OpenTelemetry eBPF Instrumentation (OBI) has a vulnerability where its ELF parser (a tool that reads executable file formats) blindly trusts offsets and metadata from binary files without checking if they're valid. A malicious or corrupted executable can cause OBI to crash when it tries to analyze what programming language a process uses, disrupting monitoring for other applications on the system.

GitHub Advisory Database

GHSA-jgg6-4rpr-wfh7: Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp

lowvulnerability
security
May 18, 2026

Three Mistral AI npm packages (@mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp) were compromised in a supply chain attack (where malicious code is inserted into legitimate software dependencies) between May 11-12. However, the malicious code, called a dropper (a program designed to download and execute harmful payloads), was broken and failed to run because it referenced the wrong filename. The affected versions have been removed from npm.

GHSA-wx9m-wx4f-4cmg: Malicious dropper in mistralai 2.4.6 PyPI package

criticalvulnerability
security
May 18, 2026

Version 2.4.6 of the mistralai package on PyPI contained malicious code that runs when the package is imported on Linux systems. The malicious code downloads and executes a file from a remote server, and versions 2.4.5 and earlier are not affected.

GHSA-jxx9-px88-pj69: n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

highvulnerability
security
May 18, 2026
CVE-2026-45707

In n8n-mcp (a tool that bridges AI agents to n8n workflow automation) running in multi-tenant mode, requests missing tenant identification headers would fall back to using the operator's own n8n credentials, allowing an authenticated tenant to access or modify the operator's workflows and data instead of their own. This only affects shared multi-tenant deployments, not single-tenant setups.

Elon Musk lost his case against Sam Altman

infonews
policy
May 18, 2026

This article reports on a legal case between Elon Musk and Sam Altman, where a jury decided that Musk's claims were invalid either because the statute of limitations (the legal deadline for filing a lawsuit) had expired or due to case dismissals. The jury's decision was advisory (meaning it was only a recommendation to the judge), but the presiding judge accepted their verdict anyway.

What to expect from Google this week

infonews
industry
May 18, 2026

Google is attending its annual I/O developer conference as the third-place competitor in the foundation model (large AI systems trained on broad data) race, having fallen behind Anthropic's Claude and OpenAI's systems, particularly in coding capabilities. The article previews expected announcements in three areas: a potential comeback attempt in AI coding tools, continued strength in AI for science (where Google won a Nobel Prize), and moves in health and medicine AI. While Google's internal teams reportedly needed to use competitors' tools to stay productive, major breakthroughs at the conference are unlikely.

CVE-2026-45829: A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un

criticalvulnerability
security
May 18, 2026
CVE-2026-45829

ChromaDB (a Python project for storing AI embeddings) versions 1.0.0 and later contain a code injection vulnerability that lets unauthenticated attackers run arbitrary code on the server by sending a malicious model repository with a specific setting enabled to a particular API endpoint. The vulnerability has a CVSS score (a 0-10 severity rating) of 10.0, marking it as critical.

AI cyberattackers are getting better faster

infonews
securityresearch

Amazon Alexa Plus can now create AI-generated podcasts

infonews
industry
May 18, 2026

Amazon has added a new feature to Alexa Plus (its upgraded AI assistant) that lets users generate podcasts on nearly any topic by simply describing what they want. The AI creates two AI-generated hosts that discuss the chosen topic, and users can preview and customize the podcast before it's created.

Anthropic to share Mythos cyber flaw findings with global finance watchdog

infonews
securitypolicy

ROSE: Extended Evaluation of RObust and SEcure Black-Box DNN Watermarking

inforesearchPeer-Reviewed
security

Enhancing Cloud Network Resilience via a Robust LLM-Empowered Multi-Agent Reinforcement Learning Framework

inforesearchPeer-Reviewed
research

Intelligent Penetration Testing Through Integrated Knowledge Graph and Historical Decision Enhancement

inforesearchPeer-Reviewed
research

GCP: Guarded Collaborative Perception With Spatial-Temporal Aware Malicious Agent Detection

inforesearchPeer-Reviewed
security

Principled Uncertainty Decomposition With Bayesian Ensemble Transformers for Trustworthy Intrusion Detection

inforesearchPeer-Reviewed
research

FaceReclaim: Deep Traceability of Face-Swapped Images Through Feature Decoupling

inforesearchPeer-Reviewed
research

Perfect Privacy for Discriminator-Based Byzantine-Resilient Federated Learning

inforesearchPeer-Reviewed
research

Data-Efficient Cross-Domain Few-Shot Website Fingerprinting With Unsupervised Domain Adaptation

inforesearchPeer-Reviewed
research

Toward More Practical Label Inference Attacks Against Graph-Based Vertical Federated Learning

inforesearchPeer-Reviewed
security

PVDI: Preserving Vital and Disrupting Irrelevant Latent Attentions for Robust Backdoor Defense

inforesearchPeer-Reviewed
security
Previous223 / 486Next

Fix: 1. Stop using the affected package versions immediately (2.2.2, 2.2.3, 2.2.4 for @mistralai/mistralai; 1.7.1, 1.7.2, 1.7.3 for @mistralai/mistralai-azure and @mistralai/mistralai-gcp). 2. Clean systems where these packages were installed. Check your installed versions using 'npm ls' or by searching your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock) for the affected version numbers. Also check build artifacts, container images, and package caches for the malicious files: router_init.js, tanstack_runner.js, or @tanstack/setup package.json.

GitHub Advisory Database

Fix: Pin mistralai to version 2.4.5 or earlier. The source text states: 'Pin mistralai to 2.4.5 or earlier. While the PyPI project is quarantined, install from this repository at a known-good tag, e.g. git+https://github.com/mistralai/client-python.git@v2.4.5.' Additionally, on affected Linux hosts, rotate every credential reachable from the importing process and review host and cloud audit logs for activity from approximately 2026-05-12 00:05 UTC onward.

GitHub Advisory Database

Fix: Fixed in n8n-mcp 2.51.2. The fix rejects requests without proper tenant headers at the HTTP edge with a 400 error before processing, prevents the system from using fallback operator credentials when in multi-tenant mode, and blocks secondary leaks in health checks and other handlers. Upgrade via 'npx n8n-mcp@latest' (NPM) or 'docker pull ghcr.io/czlonkowski/n8n-mcp:latest' (Docker). Workarounds if upgrading immediately is not possible: disable multi-tenant mode and run separate instances per tenant, use a proxy to reject requests missing both tenant headers, or restrict the operator API key to minimum required permissions if your n8n supports scoping (Enterprise or compatible Community Edition builds).

GitHub Advisory Database
The Verge (AI)
MIT Technology Review
NVD/CVE Database
May 18, 2026

AI models are rapidly improving at performing multi-stage penetration tests (simulated attacks where attackers try to break into systems through multiple steps), with the difficulty of tasks they can complete doubling every 4.7 months as of early 2025. The UK government's AI Security Institute measured this by comparing how well AI models could replicate tasks that human cybersecurity experts can complete, finding that the latest AI systems are now showing even greater capability and posing real security risks to organizations with weak defenses.

CSO Online
The Verge (AI)
May 18, 2026

Anthropic is briefing global financial regulators on Claude Mythos, an AI model with advanced capabilities in finding previously unknown cybersecurity flaws that hackers could exploit. Rather than releasing Mythos publicly, Anthropic has restricted access to selected tech companies and banks to help identify weaknesses, while the UK's AI Security Institute has found the latest version shows a significant capability jump, even completing a difficult autonomous hacking test that no prior model had solved.

Fix: UK regulators and the Treasury released guidance directing firms to 'double down' on 'core cyber hygiene,' which includes reviewing legacy systems, implementing good detection mechanisms, establishing proper governance, planning recovery procedures, and considering insurance coverage.

The Guardian Technology
research
May 18, 2026

ROSE is a black-box watermarking method (a technique to prove ownership of AI models by embedding hidden triggers that only the owner can activate) for protecting deep neural networks (DNNs, large AI models that learn patterns from data) in machine learning services. The method uses secret trigger-label pairs connected through a hash function to verify ownership while resisting attacks like fine-tuning, pruning, and other model modifications, while maintaining the model's performance on its original task.

IEEE Xplore (Security & AI Journals)
security
May 18, 2026

This paper presents CyberOps-Bots, a system that combines Large Language Models (LLMs, which are AI models trained on text) with reinforcement learning (RL, a type of AI that learns by trial and error) to defend cloud networks against attacks. The system uses a two-layer approach where an upper LLM agent handles planning and human input, while lower RL agents execute specific defense actions, and testing shows it maintains network availability much better than existing methods without needing to retrain when network conditions change.

IEEE Xplore (Security & AI Journals)
May 18, 2026

Penetration testing (PT, a security technique where experts simulate attacks to find weaknesses in networks) is traditionally slow and expensive because it relies heavily on manual expert work. This research proposes an automated and intelligent PT method using a knowledge graph (a structured database of relationships between network components) and historical decision data to create realistic test environments and make smarter attack decisions, achieving a 69% reduction in repeated testing attempts.

IEEE Xplore (Security & AI Journals)
research
May 18, 2026

Connected autonomous vehicles share sensor data to improve driving safety, but this collaboration is vulnerable to adversarial message attacks (malicious input designed to fool AI systems) from bad actors that can degrade performance. The paper describes a new blind area confusion attack that bypasses existing defenses, then proposes GCP, a framework that detects malicious agents by checking both spatial consistency (whether sensor readings from different vehicles agree) and temporal anomalies (unusual patterns over time) using statistical testing methods.

Fix: The paper proposes GCP (Guarded Collaborative Perception), which maintains spatial consistency through a confidence-scaled spatial concordance loss while examining temporal anomalies by reconstructing historical bird's eye view motion flows in low-confidence regions, and employs a joint spatial-temporal Benjamini-Hochberg test (a statistical method for detecting anomalies across multiple data streams) to synthesize results for malicious agent detection.

IEEE Xplore (Security & AI Journals)
security
May 18, 2026

This research presents a new AI framework for network intrusion detection systems (IDS, which are tools that identify unauthorized access attempts on computer networks) that provides both accurate threat detection and reliable confidence levels in its predictions. The framework combines transformer models (a type of neural network architecture) with ensemble methods (combining multiple AI models for better results) to break down prediction uncertainty into two types: epistemic uncertainty (uncertainty from the model itself) and aleatoric uncertainty (uncertainty from noisy or incomplete data). Testing on four benchmark datasets shows the system achieves strong detection rates (77.55% to 97.00% F1-scores, a measure of accuracy) while maintaining good calibration (accurate confidence estimates) and remaining resilient to adversarial attacks (attempts to fool the AI with specially crafted malicious inputs).

IEEE Xplore (Security & AI Journals)
security
May 18, 2026

Face-swapping deepfakes (AI-generated videos or images where one person's face is replaced with another) are widely misused for fraud and misinformation, and while detection tools exist, there has been little work on tracing and recovering the original face that was replaced. This paper presents FaceReclaim, a new AI method that uses diffusion models (neural networks trained to gradually refine noisy images into clear ones) to restore the original face from a deepfaked image by separating facial attributes like expressions from identity information.

IEEE Xplore (Security & AI Journals)
security
May 18, 2026

This research proposes ByITFL and LoByITFL, two new federated learning (FL, a method where multiple computers train an AI model together without sharing raw data) schemes that protect user privacy while defending against Byzantine users (participants who send corrupted or malicious data). ByITFL uses Lagrange coded computing (a technique that spreads data across multiple servers to protect it) and re-randomization to achieve perfect privacy but requires significant communication overhead, while LoByITFL reduces communication costs but requires a Trusted Third Party (TTP, an external organization that users must trust) for one-time setup before training begins.

IEEE Xplore (Security & AI Journals)
security
May 18, 2026

Website fingerprinting (WF) attacks identify which websites users visit on Tor, a privacy network, but struggle when traffic patterns differ between training and real-world scenarios. This research presents UDA-WF, a new method using unsupervised domain adaptation (a machine learning technique that helps models work across different data distributions) to identify websites more efficiently with less training data. UDA-WF reduces the auxiliary data needed by 95% while maintaining 97.37% accuracy.

IEEE Xplore (Security & AI Journals)
research
May 18, 2026

This research paper describes a new attack called Knowledge Transfer Attack (KTA) that can steal private labels (the correct answers or classifications) from graph-based vertical federated learning (GVFL, a system where multiple parties collaborate on machine learning while keeping their data private). Unlike previous attacks that required unrealistic access to training data or labeled examples, KTA only needs auxiliary graphs from unrelated domains to infer the private labels, making it a more practical threat to real-world GVFL systems.

IEEE Xplore (Security & AI Journals)
research
May 18, 2026

Backdoor attacks (hidden triggers that manipulate AI model predictions while keeping normal performance intact) are a serious security threat to deep neural networks (machine learning models with many layers). This paper presents PVDI, a defense method that removes backdoors by selectively preserving important attention patterns (the AI's focus on relevant input features) while disrupting irrelevant ones, successfully reducing attack success rates without hurting the model's normal performance.

IEEE Xplore (Security & AI Journals)