aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

AI chatbots are giving out people’s real phone numbers

mediumnews
privacysafety
May 13, 2026

AI chatbots like Google's Gemini and ChatGPT are accidentally revealing people's real phone numbers in their responses, sometimes giving out correct personal information and sometimes generating plausible-sounding but wrong numbers that still reach innocent people. Experts believe this happens because of personally identifiable information (PII, real details about people) in the training data (the information used to teach the AI), though the exact mechanism is unclear. The problem appears widespread and difficult to stop, with privacy removal companies reporting a 400% increase in requests about AI-related privacy concerns over the last seven months.

MIT Technology Review

CVE-2026-45033: GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulne

highvulnerability
security
May 13, 2026
CVE-2026-45033

GitHub Copilot CLI (an AI tool that helps developers write code from the command line) has a security vulnerability in versions before 1.0.43 where a malicious bare git repository (a special type of git storage folder with no working files) hidden in a project can trick the tool into running harmful commands. An attacker can exploit git's automatic discovery of these repositories and use configuration keys like core.fsmonitor (settings that tell git what commands to run during normal operations) to execute arbitrary code without the user knowing.

CVE-2026-44479: Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI ru

mediumvulnerability
security
May 13, 2026
CVE-2026-44479

In Vercel CLI versions 50.16.0 to 52.0.0, when running in non-interactive mode (a mode where the tool runs without user interaction, often used in CI/CD systems or with AI agents), authentication tokens (secret credentials that prove your identity) could be accidentally included in plain text within JSON suggestions that the tool outputs. This means the token could be exposed in logs or agent records where it shouldn't be visible.

CVE-2026-44470: The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side

highvulnerability
security
May 13, 2026
CVE-2026-44470

Claude Desktop for Windows had a security flaw in versions before 1.3834.0 where the CoworkVMService component (a background service running with high system privileges) did not properly check if directories were real folders or directory junctions (shortcuts that point to other locations) before creating files in them. An attacker with basic user access could trick this service into creating files in any location on the computer, potentially allowing them to gain administrator-level control of the system.

CVE-2026-44467: The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side

highvulnerability
security
May 13, 2026
CVE-2026-44467

The Claude Desktop app's SSH remote development feature (versions 1.2581.0 to before 1.4304.0) had a security flaw where it only checked if a hostname was in the ~/.ssh/known_hosts file without verifying that the server's actual host key matched the stored one. This allowed a network attacker (someone who could intercept traffic through methods like ARP spoofing or rogue Wi-Fi) to perform a man-in-the-middle attack (secretly intercepting and potentially altering communications between two parties) on remote development sessions, as long as the hostname was already in the victim's known_hosts file.

Microsoft doesn’t want any of this

infonews
security
May 13, 2026

N/A -- This article is about Microsoft's legal positioning in the Musk v. Altman trial and does not discuss any AI/LLM technical issues, vulnerabilities, or security concerns.

GHSA-3644-q5cj-c5c7: LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

highvulnerability
security
May 13, 2026
CVE-2026-45134

LangSmith SDK (a tool for managing prompts in LangChain applications) had a vulnerability where pulling public prompts by owner/name would deserialize (convert from stored format into executable code) untrusted manifest files without warning users about the trust risk. An attacker could publish a malicious prompt that, when pulled and deserialized, would execute with attacker-controlled settings, potentially redirecting API requests to steal secrets or injecting malicious instructions into the AI's behavior.

Chinese court awards compensation to sacked worker replaced by AI

infonews
policy
May 13, 2026

A Chinese court ruled that a company wrongfully fired a worker who had been replaced by AI, awarding him over £28,000 in compensation. The case reflects China's attempt to balance rapid AI adoption with worker protections, especially as youth unemployment remains high. Legal experts suggest that while companies can adopt AI technology, they cannot simply fire employees without considering the workers' interests or providing alternatives like retraining.

Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’

infonews
securityindustry

Altman details Musk's OpenAI fallout, says nonprofit was 'left for dead'

infonews
policy
May 13, 2026

This article covers testimony from OpenAI CEO Sam Altman in a lawsuit brought by Elon Musk over OpenAI's conversion from a nonprofit to a for-profit structure. Altman argued that Musk abandoned the company rather than Altman stealing it, testifying that negotiations between the co-founders in 2017-2018 over corporate structure collapsed and Musk left OpenAI's board in February 2018. The dispute centers on whether Altman and other executives broke promises to keep OpenAI as a nonprofit and use Musk's roughly $38 million donation only for charitable purposes.

Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

infonews
securityindustry

What happens when China’s AI catches up to Mythos?

infonews
securitypolicy

A Study of the Removability of Speaker-Adversarial Perturbations

inforesearchPeer-Reviewed
security

Enhancing Stereo Matching Domain Generalization With Adversarial Domain Alignment

inforesearchPeer-Reviewed
research

Optimizing the Weight Stable Set Attack With Budget Constraint

inforesearchPeer-Reviewed
research

Enhancing Blockchain Proof of Stake With Active Weighted Signatures: The ADAPT Framework

inforesearchPeer-Reviewed
research

RD-PCN: A Secure Role-Differentiated Payment Channel Network for Heterogeneous Nodes

inforesearchPeer-Reviewed
security

The General Data Protection Regulation Goes to School: Proportional Versus Top-Down Regulation in Primary and Secondary Institutions

inforesearchPeer-Reviewed
policy

Beyond Stop Signs: Why Evasion Attacks Matter Even More

inforesearchPeer-Reviewed
security

Reducing Noise: Hybrid Static Application Security Testing–Large Language Model Pipeline for Code Security

inforesearchPeer-Reviewed
security
Previous232 / 486Next

Fix: Update GitHub Copilot CLI to version 1.0.43 or later, where this vulnerability is fixed.

NVD/CVE Database

Fix: This vulnerability is fixed in version 52.0.1.

NVD/CVE Database

Fix: Update Claude Desktop to version 1.3834.0 or later, which includes a fix for this vulnerability.

NVD/CVE Database

Fix: Update Claude Desktop to version 1.4304.0 or later.

NVD/CVE Database
The Verge (AI)

Fix: Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. The updated SDK now blocks pulling public prompts by `owner/name` by default and requires callers to explicitly pass `dangerously_pull_public_prompt=True` (Python) or `dangerouslyPullPublicPrompt: true` (JavaScript/TypeScript) to acknowledge the trust boundary risk. This flag should only be set after reviewing and trusting the actual prompt contents, not just the publishing account.

GitHub Advisory Database
The Guardian Technology
May 13, 2026

The 'Mythos Moment' refers to when the speed and volume of AI-assisted cyberattacks exceeded what human security teams could handle. Sweet Security launched Sweet Attack, an agentic AI system (an AI that can plan and execute tasks autonomously) that performs continuous red teaming (security testing where an AI simulates attacker behavior) by maintaining detailed, real-time knowledge of each client's actual infrastructure, rather than relying on theoretical models.

Fix: Sweet Security provides Sweet Attack, which "automatically provides and maintains the full context necessary for Sweet Attack to operate" by continuously indexing runtime data directly from customers' environments, including topology, exposed systems, deployed code, identity paths, and application behavior. The system reevaluates potential attack paths "as soon as any new component appears in the runtime environment," enabling security teams to prioritize which vulnerabilities to fix based on actual exploitability rather than theoretical risk.

SecurityWeek
CNBC Technology
May 13, 2026

Microsoft developed MDASH (multi-model agentic scanning harness), an AI system that uses over 100 specialized AI agents working together to find and validate security vulnerabilities in complex software like Windows. MDASH successfully discovered 16 vulnerabilities that were patched in May 2026, including two critical flaws that could allow remote code execution (running commands on a system without permission) in Windows networking components.

The Hacker News
May 13, 2026

Anthropic's Mythos is an AI system that can autonomously find and exploit zero-day vulnerabilities (previously unknown security flaws) in major software, and both the US and China are racing to develop similar capabilities. While the US has maintained a lead in AI development, the performance gap is rapidly closing, and the real danger may be less about which superpower dominates and more about these capabilities leaking into criminal groups or ransomware operations that governments cannot control. The US and China are exploring diplomatic channels to establish guardrails around powerful AI systems.

Fix: Anthropic has launched Project Glasswing and committed $100 million in usage credits to help defenders secure critical infrastructure before similar capabilities become widely available. Additionally, both the US and China are weighing conversations focused on establishing guardrails covering AI models behaving unexpectedly, autonomous military systems, and nonstate actors using powerful open-source tools.

CSO Online
research
May 13, 2026

This research studies whether adversarial perturbations (small, intentional noise added to audio that tricks speaker recognition systems into misidentifying who is speaking) can be removed from speech. The study tested three scenarios based on how much information a defense system has about the attack: knowing nothing about it, having partial information, and having complete information. The results showed that removing these perturbations is only possible when the defense system has full knowledge of how the attack was generated, while partial or no knowledge makes complete removal difficult or impossible.

IEEE Xplore (Security & AI Journals)
May 13, 2026

This paper addresses a challenge where stereo-matching networks (AI systems that estimate depth by comparing two images) perform well on synthetic training data but struggle with real-world images due to domain gap (the difference between training and real-world data). The researchers propose ADASM, a method using adversarial domain alignment (exposing the model to worst-case scenarios during training to improve robustness) to make these networks generalize better to unseen real-world data without requiring fine-tuning.

IEEE Xplore (Security & AI Journals)
May 13, 2026

This research paper presents algorithms for solving the weight stable set attack problem, which involves removing nodes from a social network while staying within a budget constraint to minimize the remaining network's influence potential. The authors develop a 2α-approximation algorithm (an algorithm guaranteed to find solutions within twice the optimal answer) for networks without odd cycles and extend it to general networks, comparing it against a genetic algorithm (a problem-solving technique inspired by natural evolution) through experiments on both artificial and real-world networks.

IEEE Xplore (Security & AI Journals)
May 13, 2026

This paper presents ADAPT, a framework that improves blockchain Proof of Stake (PoS, a method where validators secure the network based on how much cryptocurrency they own) systems by allowing dynamic changes to voting power without requiring trusted intermediaries or system downtime. The solution uses Generalized Lagrange Interpolation (GLI, a mathematical technique that encodes voting weights as polynomial calculations) applied to the FROST threshold signature scheme (a cryptographic method where multiple parties must cooperate to sign transactions), achieving faster weight and threshold adjustments compared to existing approaches.

IEEE Xplore (Security & AI Journals)
May 13, 2026

This research paper addresses scalability problems in blockchain payment systems by proposing RD-PCN, a payment channel network (PCN, a system that allows cryptocurrency transactions without recording every transaction on the main blockchain) designed for nodes with different capabilities. The solution uses multi-party payment channels (MPCs, channels that connect multiple users together) and privacy-preserving routing (sending payments through the network while hiding transaction details) to improve payment success rates and fund utilization in real-world blockchain networks.

IEEE Xplore (Security & AI Journals)
May 13, 2026

The General Data Protection Regulation (GDPR, a European law that controls how organizations collect and use personal data) was created to control large tech companies but also applies to smaller organizations like schools. A research study in Italian schools found tension between following strict top-down rules and making practical decisions based on actual risks to protect data.

IEEE Xplore (Security & AI Journals)
research
May 13, 2026

Evasion attacks (methods where attackers trick AI systems into ignoring safety rules by manipulating input data) have been researched for more than ten years, but most real-world examples remain theoretical and academic. Because these demonstrations seem more like intellectual exercises than practical threats, people have largely dismissed evasion attacks as unimportant in actual security situations.

IEEE Xplore (Security & AI Journals)
research
May 13, 2026

Researchers created a hybrid system that combines SAST (static application security testing, which automatically scans code for vulnerabilities) with LLMs (large language models) to better filter and prioritize security alerts. The system reduced false positives (incorrect security warnings) by 91% in real deployments by using AI to intelligently triage findings and generate automated exploit examples.

IEEE Xplore (Security & AI Journals)