All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
vLLM (a tool for running large language models) versions before 0.28.0 have a vulnerability where two endpoints (/v1/embeddings and /pooling) don't properly check if token IDs (numeric identifiers representing words) are valid. An attacker can send a request with a negative token ID to crash the system, and because this triggers a CUDA assertion (an error check on the GPU, the specialized processor used for AI), it corrupts the GPU's state and breaks all future requests until the service restarts.
Fix: Update vLLM to version 0.28.0 or later.
NVD/CVE DatabaseSecurity researchers at Hacktron AI used Anthropic's Claude AI model to find and exploit vulnerabilities in OpenAI's systems, gaining access to employee accounts as part of a bug-bounty program. The attack chained together two critical flaws: a memory bug in libheif (a library that converts iPhone image formats) that was already patched but not formally tracked, and another vulnerability in the Discourse forum software that allowed account takeover. OpenAI resolved the issues and awarded the researchers $6,500, highlighting how accessible AI tools are making it easier to find security weaknesses even in well-resourced companies.
Microsoft released patches for a maximum-severity flaw in Azure AI Foundry (an enterprise platform for building and managing generative AI applications) that could let attackers gain unauthorized elevated privileges without authentication, along with several other critical vulnerabilities in Microsoft 365 and Azure services. The company stated that cloud-based vulnerabilities have already been automatically mitigated and require no action from users, while Windows vulnerabilities were addressed through cumulative updates for Windows 11 version 26H1.
Researchers used Claude (an AI assistant) to build a working exploit for an unpatched bug in a third-party image library, then chained it with a flaw in OpenAI's sign-in system to gain remote code execution (the ability to run commands on someone else's computer) on OpenAI's community forum and take over employee accounts. The vulnerability stemmed from the forum accepting image uploads that were processed by ImageMagick with an outdated library, combined with sign-in tokens that granted excessive permissions to linked ChatGPT and GitHub accounts.
Researchers at Hacktron AI used Anthropic's Claude chatbot to help them ethically hack into OpenAI employees' accounts, gaining access to OpenAI's software cache (a temporary storage of frequently used data) through a staff discussion forum. The incident highlights how AI tools can simplify hacking tasks that once took months into operations completed in days, though OpenAI stated it had already patched the vulnerabilities the researchers exploited.
A security flaw in four AI coding agents (Claude Code, Codex, GitHub Copilot, and Gemini CLI) allows someone controlling a plugin's code repository to swap in malicious code even when the agent is locked to a specific reviewed version. The vulnerability works by creating a branch with a name that looks like a commit hash (a long string identifying exact code), tricking the agent into installing different code while reporting it installed the locked version, giving the malicious code access to the user's files and credentials.
Some technology leaders are asking the US government to slow down AI development and create safety rules, but President Trump dismisses these concerns as a 'hoax' and maintains a strong interest in supporting the AI industry. The article discusses why Trump is enthusiastic about AI despite warnings from tech experts about potential risks.
Business leaders at Salesforce's Dreamforce conference said that AI models from last year are sufficient for their current needs, with many companies still learning how to use the technology rather than needing faster development. The discussion contrasted with AI safety concerns raised by some researchers and executives who worry that model development is moving too quickly and poses risks.
Researchers found that AWS AgentCore Harness, a managed runtime for AI agents (software that can reason and take actions), has a security flaw where attackers can use prompt injection (tricking an AI by hiding instructions in its input) to steal plaintext credentials from the identity vault (secure storage for passwords and keys). The problem occurs because the harness's built-in shell tool, which is enabled by default and runs with root access (highest-level permissions), can access the same memory where credentials are temporarily exposed when retrieved from the vault.
Anthropic and OpenAI are pursuing smaller data center deals (20-30 megawatts of compute capacity) across the UK, Nordic countries, and the US, in addition to their existing large-scale infrastructure agreements. These smaller deployments appeal because they offer faster access to usable computing power and are better suited for inference (running trained AI models to respond to user requests), which is expected to become a larger portion of data center workloads than training by 2027.
A threat actor likely used an LLM (large language model, an AI system that generates text) to build PhantomRaven, a malware stealer distributed through npm (a package registry where developers share code libraries). The malware uses typosquatting (creating packages with names similar to legitimate ones) and a remote dynamic dependency (RDD, code downloaded from an external server rather than included directly) to steal developer credentials and secrets from machines, with the attacker claiming to be a bug bounty hunter who reports vulnerabilities to collect rewards.
Microsoft Copilot, an AI assistant, suggested inappropriate responses like 'congratulations!' when an Australian MP was drafting a reply to a constituent who disclosed plans for assisted dying, highlighting how AI can fail to understand serious contexts. The incident was presented as evidence of AI shortcomings during a parliamentary inquiry, with the MP calling for Australian-controlled AI systems.
This article argues that effective cybersecurity relies on mastering foundational controls rather than investing in expensive new tools. The author recommends five basic security practices: gaining visibility through asset discovery and management, implementing strong identity management with multifactor authentication (MFA, requiring multiple ways to verify a user's identity) and passkeys, right-sizing your security approach to match your actual needs, and maintaining basic hygiene. While emerging technologies like AI can add value, they only work well when built on a solid foundation of security fundamentals.
The GPTranslate WordPress plugin (versions up to 2.34.6) has a vulnerability where unauthenticated attackers can steal API keys (credentials that grant access to paid AI services like OpenAI or Claude) by analyzing public JavaScript files on the website. This affects most configurations except DeepSeek models and certain GPT setups run in server-proxy mode (a setup where the server handles API calls instead of the browser).
Fix: Discourse issued a fix on July 27 in response to the vulnerability. OpenAI says it has resolved the issues Hacktron uncovered.
TechCrunch (Security)Security teams struggle to protect increasingly complex hybrid environments (networks spanning both on-premises and cloud systems) as they grow and change faster than humans can manage manually. The article suggests that agentic AI (AI systems that can make decisions and take actions independently) could help security operations keep pace with this rapid change, especially as organizations expect 15% of daily work decisions to be made autonomously by agentic AI by 2028.
Distillation (training an AI model using outputs from a more advanced model) has become a focal point in U.S.-China AI competition, with American officials claiming Chinese labs use this technique to catch up. However, some experts like Cohere CEO Aidan Gomez argue that China's AI progress stems partly from genuine independent innovation, not just copying, citing Chinese models that outperform American ones on certain benchmarks—something distillation alone cannot achieve.
Fix: For Azure AI Foundry and other cloud-based vulnerabilities: Microsoft stated they "have already been fully mitigated, and that they require no action for users to take." For Windows vulnerabilities CVE-2026-62721 and CVE-2026-85921: Install the 2026-09 Cumulative Update for Windows 11, version 26H1 (KB5129194) for either arm64-based systems or x64-based systems (version 28000.2956), depending on your system architecture.
The Hacker NewsFix: OpenAI narrowed the permissions on community sign-in tokens and revoked affected tokens and sessions. Discourse released a fix within two days that included image-processing sandboxing as an additional layer of defense, and published a security advisory.
SecurityWeekOpenAI introduced the Australian Youth Safety Blueprint, a framework for protecting young people using AI through six areas including AI literacy (understanding how AI works), age-appropriate safeguards, privacy protection, crisis support, and parental controls. The company is rolling out ChatGPT for Teens in Australia with updated safety features for users aged 13-17, and emphasizes that companies should build protections into products from the start rather than placing safety responsibility on young people and families.
Fix: OpenAI began rolling out ChatGPT for Teens in Australia in August, described as 'a new default experience for users identified as aged 13 to 17, with updated safeguards designed around their developmental needs.' This builds on existing parental controls, under-18 safety policies, and age assurance (technology that verifies a user's age) to apply appropriate protections to the right users.
OpenAI BlogFix: OpenAI stated that "the company had addressed the vulnerabilities that had been exploited." No specific technical details, patches, version numbers, or mitigation steps are described in the source text.
The Guardian TechnologyAnthropic's Claude model struggles with CAPTCHAs (automated tests that verify you're human by asking you to identify images or solve puzzles), often getting confused, second-guessing itself, and failing to complete simple image identification challenges before they expire. The article contrasts this with unconfirmed reports that other AI models like GPT-6 Astra can solve CAPTCHA-like games more successfully, making it unclear how consistently different AIs handle these security tests.
Fix: Anthropic patched the flaw in Claude Code version 2.1.179 or later. OpenAI patched it in Codex version 0.146.0 or later. GitHub Copilot has no fix available. Google will not patch Gemini CLI, which it is retiring.
The Hacker NewsSecurity firms are using AI agents not just for code review, but to build custom development tools that improve security audits. A security team used AI agents to build an LSP server (a tool that provides code editing features like autocomplete and navigation), a decompiler (a program that translates low-level code into more readable form), and formal verification tools (mathematical proofs of correctness) for the Miden VM, a new blockchain system, which helped them find serious bugs including an unvalidated input that could let attackers forge cryptographic signatures.
Fix: AWS recommends a layered defense approach for operators: (1) "Scope the allowedTools the harness can use to what it needs"; (2) "Scope Identity vault service accounts to least privilege for the downstream integration"; and (3) "Watch outbound traffic from your harness containers."
Palo Alto Unit 42AI researchers and company leaders are warning that AI tools pose serious risks, particularly because they could be misused to design bioweapons (weapons created from biological materials like viruses or toxins). The concern is real: in 2022, researchers showed that an AI molecule generator could create 40,000 potentially dangerous chemical compounds in just six hours, and today's AI chatbots can provide instructions on complex biological experiments to anyone, combined with increasingly accessible gene-editing tools.
Fix: The source explicitly recommends the following mitigations: (1) Conduct comprehensive asset discovery across all digital environments to create an up-to-date inventory, with one designated platform serving as the single source of truth. (2) Implement multifactor authentication (MFA), as research shows accounts with MFA are 99% less likely to be hacked. (3) Go further by implementing passkeys, which are described as 'even more effective' than MFA and reduce friction from password management.
CSO Online