aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

FastBOC: Toward Efficient Covert Communication Merging Blockchain and Onion Networks

inforesearchPeer-Reviewed
security
May 15, 2026

FastBOC is a covert communication system (a method for secretly transmitting data) that combines blockchain (a distributed ledger technology) and onion networks (systems that route data through multiple layers to hide user identity). The system uses the blockchain only to send small signal messages while using onion networks for the actual secret data, which reduces costs and prevents permanent exposure of sensitive information on the blockchain.

IEEE Xplore (Security & AI Journals)

Thinking carefully before adopting agentic AI

inforegulatory
safetypolicy

‘I didn’t want to be the guinea pig’: inside tech’s AI-fueled manager purge

infonews
industry
May 15, 2026

Tech companies are using AI as justification to cut middle management positions, claiming that AI enables them to accomplish more work with fewer employees and less management overhead. Workers report that these AI-driven restructurings are damaging mentorship, employee support, and career advancement opportunities across the industry, with companies like Amazon, Meta, Block, and Coinbase laying off thousands of employees specifically targeting management layers.

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

highnews
security
May 15, 2026

OpenAI disclosed that two employee devices were compromised through the Mini Shai-Hulud supply chain attack on TanStack (a software dependency library), resulting in limited credential theft from internal code repositories but no user data or production systems were affected. Because the compromised repositories contained signing certificates (digital credentials that verify software authenticity) for macOS apps, OpenAI revoked the old certificates and requires macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas to update to the latest versions before June 12, 2026, when the old certificates will be blocked by macOS protections.

OpenAI Hit by TanStack Supply Chain Attack

highnews
security
May 15, 2026

OpenAI disclosed that two employee devices were infected during a supply chain attack on TanStack, a web development framework, which allowed attackers to steal credential material from internal source code repositories. The stolen credentials gave attackers access to code-signing certificates (digital keys used to verify that software is authentic) for OpenAI's applications on iOS, macOS, Windows, and Android. OpenAI confirmed that no customer data or intellectual property was compromised, but took steps to prevent further risk.

How Forza Horizon took on Japan with deep research – and 360-degree cameras

infonews
industry
May 15, 2026

Forza Horizon, an open-world driving simulation game, is expanding to Japan after the developer spent years researching the country to ensure authenticity. The team faces a unique challenge because gamers worldwide have strong expectations about what Japan should look like in games, shaped by decades of stylized portrayals in other video games, so the developers must balance accurate recreation with matching these ingrained mental images.

Autonomous systems are finally working. Security is next

infonews
security
May 15, 2026

Security teams are falling behind attackers because they spend too much time investigating alerts rather than responding to them. While detection systems generate plenty of data, analysts must manually piece together information across multiple tools, which takes hours—far longer than the 29 minutes attackers need to move through a network. Modern security systems can compress investigation by automatically assembling relevant context (identity information, access paths, system changes) before presenting alerts to analysts, allowing teams to move from spotting a problem to deciding on a response much faster.

CVE-2026-2652: A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when

highvulnerability
security
May 14, 2026
CVE-2026-2652

MLflow (an open-source platform for managing machine learning workflows) versions 3.9.0 and earlier have a security flaw where certain API endpoints don't require authentication even when the server is set up with authentication enabled. This happens because the authentication check only protects `/gateway/` routes, leaving other endpoints like the Job API and trace ingestion API unprotected, allowing attackers to submit jobs, view results, and inject fake data without logging in.

datasette-llm-limits 0.1a0

infonews
industry
May 14, 2026

datasette-llm-limits is a plugin that works with Datasette (a tool for exploring databases) to set spending limits on how much money users can spend on LLM API calls. The plugin lets administrators configure daily or rolling limits per user or globally, for example restricting one user to $1.00 of LLM usage per 24-hour period.

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

infovulnerability
security
May 14, 2026
CVE-2026-42897🔥 Actively Exploited

Databricks brings GPT-5.5 to enterprise agent workflows

infonews
industry
May 14, 2026

Databricks has made GPT-5.5 available for enterprise AI agent workflows, where the model achieved a new benchmark record by reaching 50% accuracy on OfficeQA Pro (a test measuring how well AI systems handle complex business document tasks like parsing scanned PDFs and legacy files). Compared to the previous GPT-5.4 model, GPT-5.5 reduced errors by 46% and showed major improvements in parsing old documents and managing multi-step tasks without unnecessary detours.

A new personal finance experience in ChatGPT

infonews
industry
May 14, 2026

OpenAI is launching a new personal finance feature in ChatGPT that lets Pro users in the U.S. securely connect their bank accounts and ask the AI questions about their spending and financial goals. The feature uses improved AI reasoning (GPT-4.5) to analyze your real financial data alongside your goals, helping you spot spending patterns and plan major decisions, though it is not a replacement for professional financial advice.

The EU AI Act’s transparency rules: A practical guide to Article 50

inforegulatory
policy
May 14, 2026

Article 50 of the EU AI Act requires organizations to inform users when they interact with AI systems or encounter AI-generated content, with a deadline of August 2026. These transparency obligations apply broadly to any AI system used in four situations: direct interaction with people, synthetic content generation, emotion recognition or biometric categorization, and deepfake or AI-generated text on public matters. Providers must design systems to disclose AI involvement and mark outputs in machine-readable formats, while deployers must inform individuals affected by emotion recognition systems and disclose artificially generated or manipulated content.

High-stakes courtroom drama of Musk v OpenAI hears closing arguments

infonews
policy
May 14, 2026

Elon Musk is suing OpenAI and its leader Sam Altman, with closing arguments recently heard in federal court in Oakland, California. A nine-person jury will decide whether OpenAI improperly took money or benefits from Musk and enriched itself unfairly. The case has revealed private communications between the two tech leaders and details about OpenAI's internal history.

AI agent finds 18-year-old remote code execution flaw in Nginx

highnews
securityresearch

TeamPCP hackers advertise Mistral AI code repos for sale

highnews
security
May 14, 2026

Hackers from the TeamPCP group stole source code from Mistral AI (a French company that builds large language models, or LLMs) through a supply-chain attack (where attackers compromise software used by many projects) and are now demanding $25,000 to sell it rather than leak it publicly. Mistral confirmed the breach affected some of their SDK (software development kit, tools developers use to build with their platform) packages, but stated that core code, user data, and research systems were not compromised.

Gemini surges after Winklevoss Capital Fund invests $100 million in the crypto exchange

infonews
industry
May 14, 2026

Gemini, a crypto exchange founded by the Winklevoss brothers, received a $100 million investment from the founders' venture capital fund, causing its stock price to surge. The company reported better-than-expected financial results for the first quarter, with a smaller loss and higher revenue than analysts predicted, though it has faced challenges since its public debut in September including executive departures and a class-action lawsuit.

Closing time

infonews
security
May 14, 2026

N/A -- This article covers closing arguments in a legal trial between Elon Musk and OpenAI's leadership, focusing on the quality of the lawyers' presentations rather than an AI/LLM technical issue, security vulnerability, or system problem.

CVE-2026-44673: libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an

highvulnerability
security
May 14, 2026
CVE-2026-44673

libyang is a library for working with YANG (a data modeling language used in network configuration). Before version 5.2.15, the lyb_read_string() function had an integer overflow vulnerability (where a number calculation wraps around and causes unexpected behavior), which could lead to a heap buffer overflow (writing data past the end of allocated memory) when processing malicious LYB binary data. An attacker who can send LYB data to systems using libyang could crash the program or corrupt memory.

Behold, the Elon Musk jackass trophy

infonews
security
May 14, 2026

This article describes a courtroom moment in a lawsuit between Elon Musk and Sam Altman where OpenAI employees presented a trophy to researcher Josh Achiam inscribed with 'Never stop being a jackass,' commemorating an incident when Musk allegedly called Achiam a jackass after Achiam questioned whether racing ahead of Google on AI development was a good idea.

Previous227 / 486Next
May 15, 2026

Agentic AI tools (AI systems that can plan, make decisions, and take actions without constant human supervision) are becoming more common in organizations but introduce significant security risks beyond traditional AI systems. These risks include broader system access, unpredictable behavior, and difficulty explaining AI actions. The NCSC and international partners recommend organizations adopt agentic AI carefully by starting with low-risk tasks, deploying incrementally with tight controls, maintaining human oversight, and ensuring clear human accountability before connecting agents to real systems or data.

Fix: The source explicitly recommends several mitigation approaches: (1) 'deploy agentic AI incrementally, starting with tightly bounded pilots using clearly defined tasks, and build confidence in the system before you expand the scope'; (2) 'Think about what could happen if an agent misunderstood its task, exceeded its intended scope or was manipulated, and never grant an agent unrestricted access to sensitive data or critical systems'; (3) 'Ensure you maintain ongoing visibility of the system's operation, and understand how to retain meaningful human oversight and control'; (4) 'If you cannot understand, monitor or contain an agent's actions, it is not ready for deployment'; and (5) define clear human accountability for deployment decisions, granted access, safeguards, and the ability to stop the system before connecting it to real systems or data.

UK NCSC
The Guardian Technology

Fix: OpenAI isolated impacted systems and identities, revoked user sessions, rotated all credentials across impacted repositories, temporarily restricted code-deployment workflows, audited user and credential behavior, and revoked the compromised signing certificates while issuing new ones. macOS users must update ChatGPT Desktop, Codex App, Codex CLI, and Atlas to the latest versions before June 12, 2026.

The Hacker News

Fix: OpenAI rotated credentials across all affected repositories, revoked user sessions, temporarily restricted code-deployment workflows, revoked the compromised code-signing certificates, and re-signed all applications with new certificates. The company also coordinated with platform providers to stop new notarizations (a verification process that confirms software is safe) and prevent misuse of the stolen certificates. macOS users must update their OpenAI apps to the latest versions by June 12, 2026, after which date the old apps will no longer receive updates.

SecurityWeek
The Guardian Technology
CSO Online

Fix: This vulnerability is fixed in version 3.10.0. Users should upgrade mlflow to version 3.10.0 or later.

NVD/CVE Database
Simon Willison's Weblog

Microsoft Exchange Server has a cross-site scripting vulnerability (XSS, a security flaw where attackers inject malicious code into web pages) in Outlook Web Access that allows arbitrary JavaScript (code that runs in a user's browser) to execute when certain conditions are met. This vulnerability is currently being exploited by attackers in real-world attacks.

Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. See Microsoft's Security Response Center update guide and Exchange Emergency Mitigation Service for specific steps.

CISA Known Exploited Vulnerabilities
OpenAI Blog
OpenAI Blog

Fix: The EU Commission has published draft Guidelines on the scope and application of Article 50, and a Code of Practice on AI-generated content is being developed to provide practical solutions on marking and labelling. Additionally, a standardized EU label is being developed for marking AI-generated outputs in machine-readable format to make them detectable as artificially generated or manipulated.

EU AI Act Updates
The Guardian Technology
May 14, 2026

Researchers using an AI model discovered a critical 18-year-old flaw in Nginx (a web server that powers about one-third of all websites) called a heap buffer overflow (a type of memory corruption bug where data overwrites adjacent memory). The vulnerability, tracked as CVE-2026-42945 with a 9.2 severity score, can crash servers or potentially allow attackers to run malicious code, especially on systems with ASLR (Address Space Layout Randomization, a security feature that randomizes memory locations) disabled.

Fix: Upgrade to patched versions: Nginx 1.31.0 or 1.30.1 for the open-source version, or Nginx Plus versions R36 P4, R32 P6, or 37.0.0 for the commercial product. The source notes that users should 'upgrade to a patched version as soon as possible' since exploit code has been published publicly and past Nginx vulnerabilities have been actively exploited by attackers.

CSO Online

Fix: OpenAI (which was also affected by the same supply-chain attack) responded by rotating code-signing certificates (digital keys that verify software authenticity) and warned macOS users that they must update their OpenAI desktop apps before June 12, or the software may fail to launch and stop receiving updates.

BleepingComputer
CNBC Technology
The Verge (AI)

Fix: This vulnerability is fixed in SO 5.2.15. Update libyang to version 5.2.15 or later.

NVD/CVE Database
The Verge (AI)