All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.5 where it only checked the first URL a user submitted but didn't check where that URL redirected to (HTTP redirects are automatic forwards to different addresses). This meant authenticated users could trick the system into accessing internal addresses like 127.0.0.1 or 169.254.169.254 (special private IP addresses) and read sensitive data from those internal systems.
Fix: This vulnerability is fixed in 0.9.5.
NVD/CVE DatabaseArXiv, a platform where researchers share academic papers before formal publication, is implementing new rules to reduce AI slop (low-quality or unreliable AI-generated content). Authors who submit papers with clear evidence they didn't check their AI outputs, such as hallucinated references (false citations made up by the AI) or leftover comments from an LLM (large language model, an AI trained on massive amounts of text), will be banned from the platform for one year and must have future papers accepted at a reputable peer-reviewed venue.
Open WebUI, a self-hosted AI platform that runs offline, had a vulnerability before version 0.9.0 where certain API endpoints (like /api/generate and /api/embeddings) accepted any model name from users and sent requests to the backend without checking if those users had permission to use that model. The endpoints only verified that a user was logged in and that the model existed, but skipped the access control check (AccessGrants.has_access(), which determines what resources a user is allowed to access).
Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.0 where the /responses endpoint allowed any logged-in user to access any model on the system without proper permission checks. While the main chat endpoint verified that users had the right to use specific models through ownership, group membership, and access grants, the /responses proxy skipped these checks and only confirmed the user was logged in, letting attackers use models they shouldn't have access to.
A previous security fix for CVE-2026-43884 in AVideo was incomplete. The fix patched two files to use a safer URL function, but six or more other parts of the code still don't properly use the `$resolvedIP` parameter (a value returned by the safety check that locks in which server to connect to), leaving the application vulnerable to DNS-rebinding TOCTOU attacks (time-of-check-time-of-use exploits where an attacker changes which IP address a domain points to between when the code checks it and when it actually connects).
AVideo has a command injection vulnerability in `plugin/Live/on_publish.php` where user-controlled stream keys are inserted into a shell command using literal single quotes instead of proper escaping. An attacker can break out of the quotes by including a single quote character in the stream key, allowing them to inject and execute arbitrary shell commands on the server.
OpenAI reorganized its leadership structure to focus on developing AI agents (AI systems that can independently perform multiple tasks and make decisions). The company plans to merge ChatGPT and Codex (a code-generation AI tool) into a single unified platform designed around this agentic approach, with president Greg Brockman now overseeing all product decisions.
Budibase's AI Extract File automation step has a server-side request forgery vulnerability (SSRF, a type of attack where a server makes requests to internal addresses it shouldn't access) because it uses `fetch()` directly without IP blacklist validation. Every other automation step in the same codebase properly uses `fetchWithBlacklist()` to block requests to internal networks like 127.0.0.1 and 169.254.169.254, but the AI step bypasses these protections, allowing authenticated users to access cloud metadata, scan internal networks, and potentially steal credentials.
Microsoft APM is a tool that manages dependencies for AI agents, and versions before 0.13.0 have a security flaw on Windows systems. When installing a bundle (a package of code) from a .tar.gz file (a compressed archive format), the tool extracts files without properly checking if any file paths could escape the intended folder, potentially allowing an attacker to place files anywhere on the system by using absolute paths like D:/.
Microsoft APM, a dependency manager for AI agents, had a vulnerability in versions 0.5.4 to 0.12.4 where symbolic links (shortcuts that point to other files) in downloaded packages were followed without checking, potentially allowing attackers to read or write arbitrary files on a developer's machine. The vulnerability went undetected by security checks because the resulting files were not flagged by the package hash verification, security scans, or audit tools.
Microsoft APM is a tool that manages dependencies (external code libraries) for AI agents. Before version 0.8.12, it had a path traversal vulnerability (a security flaw where an attacker can access files outside the intended directory) that allowed malicious plugins to copy arbitrary files from a user's computer during installation by using absolute paths or '../' sequences to escape the plugin directory.
Andon Labs ran an experiment where four different AI models (Claude, ChatGPT, Gemini, and Grok) were each given $20 to run their own radio station independently, with instructions to develop a personality and make a profit. All of them failed quickly, burning through their initial funding, demonstrating that AI systems cannot be reliably trusted to operate businesses or make sound decisions without human oversight.
Pipecat's development runner has a path traversal vulnerability (a flaw that lets attackers access files outside the intended directory) in its `/files` endpoint. An attacker can use URL-encoded slashes (`%2F` instead of `/`) to bypass Starlette's (the web framework) security checks and read any file accessible to the Pipecat process, such as SSH keys or system files, without needing credentials.
Fix: According to ArXiv's Code of Conduct, authors must not submit papers with incontrovertible evidence that they failed to review LLM-generated results. Those found in violation face a one-year ban from ArXiv and must have subsequent submissions accepted at a reputable peer-reviewed venue before resubmission.
The Verge (AI)Fix: The vulnerability is fixed in version 0.9.0.
NVD/CVE DatabaseFix: This vulnerability is fixed in 0.9.0.
NVD/CVE DatabaseFix: The source text references a correct implementation pattern in `plugin/YPTWallet/YPTWallet.php:1071-1098` that shows how to properly use the `$resolvedIP` out-param with `curl_setopt($ch, CURLOPT_RESOLVE, ...)` for DNS pinning. However, the source does not explicitly state what developers should do to fix the six+ vulnerable call sites.
GitHub Advisory DatabaseThis academic paper, published in July 2026, presents research on laconic attribute-based PSI (private set intersection, a technique that lets two parties find common items in their datasets without revealing the full datasets to each other) applied to authenticated inputs. The work appears to focus on theoretical cryptographic methods for secure data comparison while maintaining privacy and verifying that the data being compared is legitimate.
This research paper examines how well attack mitigations (security protections built into code) actually work in Rust and Go, two programming languages designed to be memory-safe (meaning they prevent common memory-related bugs that attackers often exploit). The study analyzes real compiled programs to see whether these language protections hold up against real-world attacks.
The AWS AI Security Framework is a structured approach that helps organizations secure AI systems by applying the right security controls across three layers (infrastructure, identity/data, and AI application), three use cases (question-answering AI, data-connected AI like RAG, and autonomous agents), and three phases (prototype, production, and scale). The framework addresses unique AI security challenges like prompt injection (tricking AI systems by hiding malicious instructions in user input) and non-deterministic outputs by implementing input validation, content filtering, and continuous monitoring from day one of development.
Fix: The framework recommends implementing controls across three phases: Phase 1 (Foundational) involves extending existing controls to AI, establishing identity management and fine-grained access controls, and adding content filtering and guardrails; Phase 2 (Enhanced) adds threat detection, data classification, and AI-specific monitoring for production; Phase 3 (Advanced) automates governance, compliance, and incident response at scale. AWS also offers a no-cost SHIP engagement to baseline security posture and build a prioritized roadmap.
AWS Security BlogFix: This vulnerability is fixed in version 0.13.0.
NVD/CVE DatabaseFix: This vulnerability is fixed in version 0.13.0.
NVD/CVE DatabaseFix: This vulnerability is fixed in version 0.8.12. Users should update Microsoft APM to 0.8.12 or later.
NVD/CVE DatabaseGoogle updated its spam policy to classify attempts to manipulate its AI search results as spam, including tactics like biased listicles or recommendation poisoning (injecting false information to trick an LLM into giving preferred answers). This rule applies to Google Search's AI features like AI Overview and AI Mode.
OpenAI announced a new preview feature that will let ChatGPT connect directly to users' bank accounts through Plaid, a platform that links banking apps to third-party services. This integration would give the chatbot access to detailed financial information, including credit card debt and account balances, to help answer users' finance questions.
This cybersecurity news roundup covers several significant incidents and developments, including a data breach at Nvidia's GeForce NOW service in Armenia that exposed user personal information, extended security update timelines for foreign-made routers and drones, and OpenAI's offer to give EU regulators access to a specialized version of GPT-5.5 for monitoring cyber security risks. The roundup also highlights an active malware campaign targeting developers with fake Claude Code installers, an Iran-linked group breaching South Korean electronics manufacturers, and Google's Android 17 release introducing AI-driven security features like verified financial calls and real-time threat detection.
Fix: For the fake Claude Code installer campaign, the source explicitly mentions the discovery but does not provide a stated mitigation. For Android 17, the source describes the security upgrades included in the update itself (verified financial calls, Live Threat Detection, post-quantum cryptography, automatic OTP hiding, and default-on theft protections), which function as built-in protections rather than external mitigations. For the FCC router waiver, the solution is the extended update window allowing security patches and firmware updates until at least January 1, 2029. No other explicit mitigations or patches are discussed in the source for the remaining incidents.
SecurityWeekThis paper addresses the problem that trusted execution environments (TEEs, like TrustZone, which are isolated secure areas in processors that protect sensitive data from untrusted software) typically have poor support for device drivers. The researchers propose a "twin driver" approach where matching drivers run in both the TEE and the untrusted operating system, supported by analysis tools and a sandbox environment that keeps the TEE minimal and secure while allowing efficient driver operation.