All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
This research paper presents MPV, a method for restricting access to master keys in multi-user Paillier systems (a cryptographic system that allows certain calculations on encrypted data without decrypting it first) by using mixed ciphertexts (encrypted data created with different encryption methods combined). The approach aims to improve security by preventing unauthorized parties from decrypting sensitive information even if they gain access to the master key.
PraisonAI, an open-source framework for building multi-agent AI systems, has a critical authentication bypass vulnerability (CVE-2026-44338, a severity rating of 7.3 out of 10) where its default API server ships with authentication disabled, allowing anyone to access protected endpoints and trigger workflows without permission. Threat actors began exploiting this vulnerability within hours of its public disclosure, scanning internet-exposed instances to confirm they could access the vulnerable endpoints.
PraisonAI, an open-source AI orchestration framework (software that coordinates multiple AI components), had a critical flaw where authentication (verification of user identity) was disabled by default in its API server, allowing anyone on the internet to access AI workflows without permission. Attackers began scanning for vulnerable systems within less than four hours of the vulnerability being publicly disclosed, prompting urgent calls for affected organizations to update immediately.
Elon Musk and Sam Altman, former cofounders of OpenAI, are in a legal dispute over whether Altman and another executive deceived Musk about converting the organization from non-profit to for-profit structure. The article argues that focusing on this personal conflict distracts from deeper problems with AI itself.
PraisonAI, a framework for deploying autonomous AI agents, had a critical authentication bypass vulnerability (CVE-2026-44338) in versions 2.5.6 to 4.6.33 where a legacy Flask API server shipped with authentication disabled by default, allowing unauthenticated attackers to access agent configurations and trigger workflows. Hackers began scanning for and testing this vulnerability within less than four hours of its public disclosure, demonstrating how quickly AI tools are enabling rapid exploitation of newly disclosed security flaws.
OpenAI updated ChatGPT to better recognize warning signs of harm by analyzing context within and across conversations, particularly for suicide, self-harm, and harm-to-others scenarios. The system now uses safety summaries (short notes about earlier safety-relevant context) and improved training to distinguish between safe interactions and rare high-risk situations, allowing ChatGPT to respond more carefully through de-escalation, refusal, or redirection to support resources. These improvements were developed in collaboration with mental health experts over more than two years.
Two brothers fired from a hosting company that served 45+ US government agencies used an AI chatbot to help them delete customer databases and cover their tracks, asking it questions like how to clear system logs from SQL servers. The incident highlights that organizations need stronger controls to prevent insider attacks (damage from current or former employees) and must implement better safeguards to prevent AI tools from being misused for destructive purposes.
Microsoft CEO Satya Nadella worried that OpenAI could become more dominant than Microsoft itself, similar to how Microsoft once overtook IBM in the 1980s. Court testimony revealed that Microsoft invested over $100 billion in OpenAI through investments, infrastructure, and hosting costs, and by the end of 2025, about 45% of Microsoft's cloud business obligations were tied to OpenAI, showing how dependent the company had become on its AI partner.
SQLBot is a Text-to-SQL system (software that converts natural language questions into database queries) that uses large language models and RAG (retrieval-augmented generation, where the AI pulls in external documents to answer questions). Before version 1.8.0, it had an IDOR vulnerability (insecure direct object reference, where an attacker can access resources belonging to other users by manipulating request parameters), allowing attackers to access and modify database schemas and data from other workspaces or organizations.
Microsoft Edge is updating its Copilot AI chatbot to access information from all your open browser tabs, letting you ask questions about tab content, compare products, and summarize articles. Users can choose which features to enable or disable, and Microsoft is replacing the older Copilot Mode (which had agentic features like booking reservations) with this new tab-aware version.
In Strapi versions before 5.33.3, resetting a user's password did not automatically cancel existing refresh tokens (credentials that allow generating new access tokens without re-logging in), so an attacker with a stolen refresh token could continue accessing the account even after the legitimate user changed their password. This vulnerability affected the admin and users-permissions components and had a CVSS score (a 0-10 rating of how severe a vulnerability is) of 2.1, indicating low severity.
Fix: The vulnerability has been patched in version 4.6.34. Additionally, users are advised to apply the latest fixes as soon as possible, audit existing deployments, review model provider billing for suspicious activity, and rotate credentials referenced in 'agents.yaml.'
The Hacker NewsFix: Sysdig urged organizations to immediately upgrade to PraisonAI version 4.6.34 or later, which removes the vulnerable legacy API behavior and introduces stronger authentication protections. The researchers also recommended discontinuing use of the legacy "api_server.py" entrypoint entirely. Until an upgrade is possible, defenders were advised to monitor network traffic for requests containing the "CVE-Detector/1.0" user-agent string and suspicious requests targeting /agents, /chat, /api/agents, and related endpoints.
CSO OnlineAI hallucinations are confident but factually incorrect outputs that pose serious security risks, especially in cybersecurity where they can drive automated decisions. Since AI models generate responses based on statistical patterns rather than verified facts, they may cite nonexistent sources or fabricate data while sounding authoritative, potentially leading to missed threats, false alarms, or flawed security decisions. A 2025 benchmark found that most AI models tested were more likely to give a confident wrong answer than a correct one on difficult questions.
Modern AI systems like Anthropic's Claude Mythos Preview are becoming very good at finding software vulnerabilities (weaknesses in code that attackers can exploit), which creates both serious risks and benefits. Attackers could use these AI systems to automatically discover and exploit vulnerabilities in critical systems worldwide, but defenders can use the same technology to find and patch those vulnerabilities before attackers do, ultimately making software more secure long-term.
Fix: The vulnerability was resolved in PraisonAI version 4.6.34. Organizations should update their deployments as soon as possible.
SecurityWeekDeepfake pornography increasingly uses adult content creators' bodies without consent, either by placing other people's faces onto their bodies or by using their work as training data for AI-generated nude images (synthetic sexual imagery created by artificial intelligence). This practice threatens creators' livelihoods, mental health, and safety, as their digital doubles may perform sex acts they never agreed to or be used in scams, while society largely ignores the harm to the bodies being exploited.
AI agents (software systems that can plan and take actions over time) that retain memory between sessions create a security risk called Memory & Context Poisoning, where attackers can inject malicious instructions into persistent storage that the agent continues to trust and follow in future interactions. Researchers found a vulnerability called MemoryTrap in Claude Code where a developer could unknowingly approve a malicious dependency that would persist in the agent's memory and configuration files, poisoning the agent's behavior across multiple projects and sessions. The core problem is that agents treat stored memory, configuration files, and hooks as trustworthy guidance without validating whether they contain attacker-controlled content.
Fix: Anthropic released Claude Code v2.1.50, which removed user memories from the system prompt (the core instructions that guide the AI's behavior) to reduce the specific attack path that MemoryTrap exploited.
OWASP GenAI SecurityThis academic publication discusses PUF (physically unclonable functions, unique fingerprints built into hardware chips that are nearly impossible to copy) optimization methods for authenticating IoT devices (internet-connected devices like smart home sensors). The research focuses on improving how these hardware-based security features can be used to verify that IoT devices are genuine and trustworthy.
This academic paper presents a method using AI to extract entities (named items like organizations or IP addresses) and relationships between them from threat intelligence data about APT (advanced persistent threat, a type of sophisticated cyberattack) attacks. The researchers developed a system to help security analysts automatically identify and organize complex attack patterns from unstructured text documents.
This research paper presents a method for optimally placing honeypots (decoy systems designed to attract and monitor attackers) in networks where multiple attackers operate simultaneously, using Bayesian Stackelberg Games (a mathematical framework for strategic decision-making under incomplete information). The approach aims to help defenders allocate honeypots more effectively by predicting attacker behavior and making strategic placement decisions.
Fix: OpenAI implemented safety summaries, which are short, factual notes about earlier safety-relevant context created by a model trained for safety reasoning tasks. These summaries are narrowly scoped, kept only for a limited time, and used only when relevant to serious safety concerns. Additionally, ChatGPT was trained to use this context more carefully to recognize when added caution is needed and respond appropriately by de-escalating, refusing harmful details, or redirecting toward safer alternatives and crisis resources.
OpenAI BlogA critical flaw in Cisco Catalyst SD-WAN Controller allows attackers who haven't logged in to bypass authentication (the process of verifying identity) and gain administrative privileges (full control) on affected systems. This vulnerability is currently being exploited in real attacks.
Fix: CISA (the US Cybersecurity and Infrastructure Security Agency) requires organizations to follow Emergency Directive 26-03 to assess exposure and mitigate risks, and to use CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices. Organizations must also follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. The due date for compliance is 2026-05-17.
CISA Known Exploited VulnerabilitiesFix: This vulnerability is fixed in version 1.8.0. Users should upgrade SQLBot to 1.8.0 or later.
NVD/CVE DatabasePalo Alto Networks warns that hackers are increasingly using AI models to find and exploit software vulnerabilities (weaknesses in code that attackers can use), and companies have only 3-5 months to strengthen their defenses before AI-driven attacks become common. Security teams are under pressure as more sophisticated AI models make it easier for attackers to discover previously unknown vulnerabilities faster than companies can fix them.
Fix: Palo Alto Networks announced it will roll out 'virtual patching capabilities' (temporary security measures that block attacks without changing the underlying code) 'very soon.' Additionally, Anthropic limited early access to its Mythos model to a select group of companies, including Palo Alto Networks, CrowdStrike, Amazon, Apple, and JPMorgan, to test and fix vulnerabilities before hackers can exploit them. OpenAI also launched its GPT-5.5-Cyber model and Daybreak cyber initiative to address these threats.
CNBC TechnologyFix: Immediately update Strapi to version 5.33.3 or later. The patch invalidates all refresh tokens associated with a user whenever their password is changed or reset, regardless of device identification.
GitHub Advisory Database