aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9291 items

CVE-2026-93592: vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints,

highvulnerability
security
Sep 18, 2026
CVE-2026-93592

vLLM (a tool for running large language models) versions before 0.28.0 have a vulnerability where two endpoints (/v1/embeddings and /pooling) don't properly check if token IDs (numeric identifiers representing words) are valid. An attacker can send a request with a negative token ID to crash the system, and because this triggers a CUDA assertion (an error check on the GPU, the specialized processor used for AI), it corrupts the GPU's state and breaks all future requests until the service restarts.

Fix: Update vLLM to version 0.28.0 or later.

NVD/CVE Database

Researchers used Anthropic’s Claude to hack into OpenAI

highnews
security
Sep 18, 2026

Security researchers at Hacktron AI used Anthropic's Claude AI model to find and exploit vulnerabilities in OpenAI's systems, gaining access to employee accounts as part of a bug-bounty program. The attack chained together two critical flaws: a memory bug in libheif (a library that converts iPhone image formats) that was already patched but not formally tracked, and another vulnerability in the Discourse forum software that allowed account takeover. OpenAI resolved the issues and awarded the researchers $6,500, highlighting how accessible AI tools are making it easier to find security weaknesses even in well-resourced companies.

When Security Operations Can’t Keep Up:  4 Ways Agentic Network Security Management Improves Security Operations

infonews
securityindustry

The U.S. says China's AI progress is down to 'distillation.' But is it that clear cut?

infonews
policyindustry

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

criticalnews
security
Sep 18, 2026

Microsoft released patches for a maximum-severity flaw in Azure AI Foundry (an enterprise platform for building and managing generative AI applications) that could let attackers gain unauthorized elevated privileges without authentication, along with several other critical vulnerabilities in Microsoft 365 and Azure services. The company stated that cloud-based vulnerabilities have already been automatically mitigated and require no action from users, while Windows vulnerabilities were addressed through cumulative updates for Windows 11 version 26H1.

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

highnews
security
Sep 18, 2026

Researchers used Claude (an AI assistant) to build a working exploit for an unpatched bug in a third-party image library, then chained it with a flaw in OpenAI's sign-in system to gain remote code execution (the ability to run commands on someone else's computer) on OpenAI's community forum and take over employee accounts. The vulnerability stemmed from the forum accepting image uploads that were processed by ImageMagick with an outdated library, combined with sign-in tokens that granted excessive permissions to linked ChatGPT and GitHub accounts.

Introducing the Australian Youth Safety Blueprint

inforegulatory
policysafety

OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot

infonews
security
Sep 18, 2026

Researchers at Hacktron AI used Anthropic's Claude chatbot to help them ethically hack into OpenAI employees' accounts, gaining access to OpenAI's software cache (a temporary storage of frequently used data) through a staff discussion forum. The incident highlights how AI tools can simplify hacking tasks that once took months into operations completed in days, though OpenAI stated it had already patched the vulnerabilities the researchers exploited.

Are AIs Still Struggling with CAPTCHAs?

infonews
securityresearch

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

highnews
security
Sep 18, 2026

A security flaw in four AI coding agents (Claude Code, Codex, GitHub Copilot, and Gemini CLI) allows someone controlling a plugin's code repository to swap in malicious code even when the agent is locked to a specific reviewed version. The vulnerability works by creating a branch with a name that looks like a commit hash (a long string identifying exact code), tricking the agent into installing different code while reporting it installed the locked version, giving the malicious code access to the user's files and credentials.

Is Trump’s AI obsession walking the world into disaster? | Politics Weekly America

infonews
policy
Sep 18, 2026

Some technology leaders are asking the US government to slow down AI development and create safety rules, but President Trump dismisses these concerns as a 'hoax' and maintains a strong interest in supporting the AI industry. The article discusses why Trump is enthusiastic about AI despite warnings from tech experts about potential risks.

AI safety debate meets reality at Dreamforce as business leaders say last year's models are enough

infonews
industry
Sep 18, 2026

Business leaders at Salesforce's Dreamforce conference said that AI models from last year are sufficient for their current needs, with many companies still learning how to use the technology rather than needing faster development. The discussion contrasted with AI safety concerns raised by some researchers and executives who worry that model development is moving too quickly and poses risks.

Auditing in the age of (good enough) AI

infonews
securityresearch

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

highnews
security
Sep 18, 2026

Researchers found that AWS AgentCore Harness, a managed runtime for AI agents (software that can reason and take actions), has a security flaw where attackers can use prompt injection (tricking an AI by hiding instructions in its input) to steal plaintext credentials from the identity vault (secure storage for passwords and keys). The problem occurs because the harness's built-in shell tool, which is enabled by default and runs with root access (highest-level permissions), can access the same memory where credentials are temporarily exposed when retrieved from the vault.

Anthropic and OpenAI hunt for smaller data center deals, sources tell CNBC, in race to deploy AI capacity

infonews
industry
Sep 18, 2026

Anthropic and OpenAI are pursuing smaller data center deals (20-30 megawatts of compute capacity) across the UK, Nordic countries, and the US, in addition to their existing large-scale infrastructure agreements. These smaller deployments appeal because they offer faster access to usable computing power and are better suited for inference (running trained AI models to respond to user requests), which is expected to become a larger portion of data center workloads than training by 2027.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

highnews
security
Sep 18, 2026

A threat actor likely used an LLM (large language model, an AI system that generates text) to build PhantomRaven, a malware stealer distributed through npm (a package registry where developers share code libraries). The malware uses typosquatting (creating packages with names similar to legitimate ones) and a remote dynamic dependency (RDD, code downloaded from an external server rather than included directly) to steal developer credentials and secrets from machines, with the attacker claiming to be a bug bounty hunter who reports vulnerabilities to collect rewards.

Andrew Hastie says AI advised him to reply ‘congratulations!’ to man who planned to end life with assisted dying

infonews
safety
Sep 18, 2026

Microsoft Copilot, an AI assistant, suggested inappropriate responses like 'congratulations!' when an Australian MP was drafting a reply to a constituent who disclosed plans for assisted dying, highlighting how AI can fail to understand serious contexts. The incident was presented as evidence of AI shortcomings during a parliamentary inquiry, with the MP calling for Australian-controlled AI systems.

The specter of AI-enabled bioweapons is a wake-up call for biotech

infonews
safetypolicy

Strong fundamentals make next-gen security possible

infonews
security
Sep 18, 2026

This article argues that effective cybersecurity relies on mastering foundational controls rather than investing in expensive new tools. The author recommends five basic security practices: gaining visibility through asset discovery and management, implementing strong identity management with multifactor authentication (MFA, requiring multiple ways to verify a user's identity) and passkeys, right-sizing your security approach to match your actual needs, and maintaining basic hygiene. While emerging technologies like AI can add value, they only work well when built on a solid foundation of security fundamentals.

CVE-2026-89278: The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v

mediumvulnerability
security
Sep 18, 2026
CVE-2026-89278

The GPTranslate WordPress plugin (versions up to 2.34.6) has a vulnerability where unauthenticated attackers can steal API keys (credentials that grant access to paid AI services like OpenAI or Claude) by analyzing public JavaScript files on the website. This affects most configurations except DeepSeek models and certain GPT setups run in server-proxy mode (a setup where the server handles API calls instead of the browser).

Previous3 / 465Next

Fix: Discourse issued a fix on July 27 in response to the vulnerability. OpenAI says it has resolved the issues Hacktron uncovered.

TechCrunch (Security)
Sep 18, 2026

Security teams struggle to protect increasingly complex hybrid environments (networks spanning both on-premises and cloud systems) as they grow and change faster than humans can manage manually. The article suggests that agentic AI (AI systems that can make decisions and take actions independently) could help security operations keep pace with this rapid change, especially as organizations expect 15% of daily work decisions to be made autonomously by agentic AI by 2028.

Check Point Research
Sep 18, 2026

Distillation (training an AI model using outputs from a more advanced model) has become a focal point in U.S.-China AI competition, with American officials claiming Chinese labs use this technique to catch up. However, some experts like Cohere CEO Aidan Gomez argue that China's AI progress stems partly from genuine independent innovation, not just copying, citing Chinese models that outperform American ones on certain benchmarks—something distillation alone cannot achieve.

CNBC Technology

Fix: For Azure AI Foundry and other cloud-based vulnerabilities: Microsoft stated they "have already been fully mitigated, and that they require no action for users to take." For Windows vulnerabilities CVE-2026-62721 and CVE-2026-85921: Install the 2026-09 Cumulative Update for Windows 11, version 26H1 (KB5129194) for either arm64-based systems or x64-based systems (version 28000.2956), depending on your system architecture.

The Hacker News

Fix: OpenAI narrowed the permissions on community sign-in tokens and revoked affected tokens and sessions. Discourse released a fix within two days that included image-processing sandboxing as an additional layer of defense, and published a security advisory.

SecurityWeek
Sep 18, 2026

OpenAI introduced the Australian Youth Safety Blueprint, a framework for protecting young people using AI through six areas including AI literacy (understanding how AI works), age-appropriate safeguards, privacy protection, crisis support, and parental controls. The company is rolling out ChatGPT for Teens in Australia with updated safety features for users aged 13-17, and emphasizes that companies should build protections into products from the start rather than placing safety responsibility on young people and families.

Fix: OpenAI began rolling out ChatGPT for Teens in Australia in August, described as 'a new default experience for users identified as aged 13 to 17, with updated safeguards designed around their developmental needs.' This builds on existing parental controls, under-18 safety policies, and age assurance (technology that verifies a user's age) to apply appropriate protections to the right users.

OpenAI Blog

Fix: OpenAI stated that "the company had addressed the vulnerabilities that had been exploited." No specific technical details, patches, version numbers, or mitigation steps are described in the source text.

The Guardian Technology
Sep 18, 2026

Anthropic's Claude model struggles with CAPTCHAs (automated tests that verify you're human by asking you to identify images or solve puzzles), often getting confused, second-guessing itself, and failing to complete simple image identification challenges before they expire. The article contrasts this with unconfirmed reports that other AI models like GPT-6 Astra can solve CAPTCHA-like games more successfully, making it unclear how consistently different AIs handle these security tests.

Schneier on Security

Fix: Anthropic patched the flaw in Claude Code version 2.1.179 or later. OpenAI patched it in Codex version 0.146.0 or later. GitHub Copilot has no fix available. Google will not patch Gemini CLI, which it is retiring.

The Hacker News
The Guardian Technology
CNBC Technology
Sep 18, 2026

Security firms are using AI agents not just for code review, but to build custom development tools that improve security audits. A security team used AI agents to build an LSP server (a tool that provides code editing features like autocomplete and navigation), a decompiler (a program that translates low-level code into more readable form), and formal verification tools (mathematical proofs of correctness) for the Miden VM, a new blockchain system, which helped them find serious bugs including an unvalidated input that could let attackers forge cryptographic signatures.

Trail of Bits Blog

Fix: AWS recommends a layered defense approach for operators: (1) "Scope the allowedTools the harness can use to what it needs"; (2) "Scope Identity vault service accounts to least privilege for the downstream integration"; and (3) "Watch outbound traffic from your harness containers."

Palo Alto Unit 42
CNBC Technology
The Hacker News
The Guardian Technology
Sep 18, 2026

AI researchers and company leaders are warning that AI tools pose serious risks, particularly because they could be misused to design bioweapons (weapons created from biological materials like viruses or toxins). The concern is real: in 2022, researchers showed that an AI molecule generator could create 40,000 potentially dangerous chemical compounds in just six hours, and today's AI chatbots can provide instructions on complex biological experiments to anyone, combined with increasingly accessible gene-editing tools.

MIT Technology Review

Fix: The source explicitly recommends the following mitigations: (1) Conduct comprehensive asset discovery across all digital environments to create an up-to-date inventory, with one designated platform serving as the single source of truth. (2) Implement multifactor authentication (MFA), as research shows accounts with MFA are 99% less likely to be hacked. (3) Go further by implementing passkeys, which are described as 'even more effective' than MFA and reduce friction from password management.

CSO Online
NVD/CVE Database