aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9291 items

Could AI really end humanity? Post your questions for our tech reporters now

infonews
safetypolicy
Sep 18, 2026

Recent warnings have raised concerns that advanced AI systems could pose existential risks to humanity, with claims ranging from potential misuse by criminals and state actors to creating weapons and biological threats. Industry figures like those at Anthropic and Elon Musk have publicly warned about these dangers, prompting tech reporters to examine whether these concerns are justified and to answer public questions about the scale of AI-related risks.

The Guardian Technology

AI Agent Breaches Spanish Organization, Modifies Personal Data

infonews
security
Sep 18, 2026

An AI agent (a software system that can act autonomously to complete tasks) was used to breach a Spanish organization and modify personal data. The article suggests that AI-driven attacks are becoming increasingly common and will soon be a standard tool for attackers rather than an unusual occurrence.

CVE-2026-88844: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c

infovulnerability
security
Sep 18, 2026
CVE-2026-88844

The MasterStudy LMS WordPress Plugin (a learning management system add-on for WordPress) in versions before 3.7.50 has a security flaw where it doesn't check whether a user actually owns a course before showing them student enrollment data. This means instructors can see the names and email addresses of students in other instructors' courses, leaking private student information.

CVE-2026-81340: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability

infovulnerability
security
Sep 18, 2026
CVE-2026-81340

The MasterStudy LMS WordPress Plugin (a learning management system tool for WordPress) before version 3.7.50 has a security flaw where it doesn't check whether users own or have permission to modify orders through its REST API (a system that lets external programs interact with WordPress). This allows instructors to change any order on the site, including giving people free course access, removing others' paid enrollments, and editing order notes.

CVE-2026-85887: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat

highvulnerability
security
Sep 17, 2026
CVE-2026-85887

A flaw in Microsoft 365 Copilot's permission settings allows someone with authorized access to improperly view sensitive information across a network. The issue stems from incorrect assignment of permissions (access rules) to a critical resource (important data or system component), meaning the AI tool isn't properly restricting who can see what.

CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability

infovulnerability
security
Sep 17, 2026
CVE-2026-53266🔥 Actively Exploited

CVE-2025-39964: Linux Kernel Race Condition Vulnerability

infovulnerability
security
Sep 17, 2026
CVE-2025-39964🔥 Actively Exploited

CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

infovulnerability
security
Sep 17, 2026
CVE-2025-39682🔥 Actively Exploited

How To Write With An LLM

infonews
industry
Sep 17, 2026

Thomas Ptacek recommends using LLMs as copyediting tools rather than writing assistants, with a strict rule to never use specific phrases that an LLM suggests. He advocates for LLMs to help with fact-checking, spelling, grammar, and finding synonyms, but argues that adopting LLM-suggested wording produces text with a distinctive and undesirable quality.

CVE-2026-93436: vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di

highvulnerability
security
Sep 17, 2026
CVE-2026-93436

vLLM (a software framework for running large language models) versions up to 0.29.0 has a memory cleanup bug in its decode workers (specialized processors that handle the generation phase of AI inference). Attackers can exploit this by sending requests with max_tokens=0 (asking for zero output tokens), which prevents the system from properly clearing temporary data, eventually consuming all available memory until the worker crashes and restarts.

CVE-2026-85885: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized

criticalvulnerability
security
Sep 17, 2026
CVE-2026-85885

M365 Copilot has a command injection vulnerability (a flaw where special characters in user input can trick the system into running unintended commands), which allows an authorized attacker to gain higher privileges over a network. The vulnerability affects users who already have some level of access to the system.

CVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business

highvulnerability
security
Sep 17, 2026
CVE-2026-78501

Microsoft 365 Copilot's Business Chat has a vulnerability where special characters are not properly filtered before being used in commands, allowing attackers to inject malicious commands (command injection, where an attacker sneaks unauthorized instructions into a system by exploiting how it processes input). This could let unauthorized people access and steal sensitive information across the network.

CVE-2026-68791: Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network

highvulnerability
security
Sep 17, 2026
CVE-2026-68791

Azure Machine Learning contains a vulnerability where authorization checks (the system that verifies whether a user is allowed to perform an action) are not working correctly, allowing an attacker without permission to access and steal sensitive information over the internet.

CVE-2026-55946: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut

mediumvulnerability
security
Sep 17, 2026
CVE-2026-55946

Microsoft Copilot has a command injection vulnerability (a flaw where special characters in user input are not properly filtered, allowing attackers to execute unintended commands), which lets an unauthorized attacker access and leak sensitive information over a network.

Anthropic shares 3 metrics to help AI companies monitor pace of development

infonews
policy
Sep 17, 2026

Anthropic released three new metrics to help monitor how quickly AI is being developed, following CEO Dario Amodei's call for the AI industry to slow down its pace of advancement. The metrics measure AI-led research and development, oversight of AI agents (software that can perform tasks independently), and how computing resources are allocated within the company, with the goal of making AI development more transparent to the public so society can decide how to use this information.

CVE-2026-54520: AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior

highvulnerability
security
Sep 17, 2026
CVE-2026-54520

AI Agent Automation, a platform for managing AI workflows with scheduling and monitoring tools, has a vulnerability in versions before 0.9.1 where authenticated users can manipulate file paths to escape the intended workspace directory and read sensitive files or overwrite files that the application can access. The vulnerability occurs because the system doesn't verify that file paths stay within approved directories after resolving them.

CVE-2026-54519: AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior

highvulnerability
security
Sep 17, 2026
CVE-2026-54519

AI Agent Automation, a platform that runs automated AI workflows (sequences of actions controlled by AI), had a security flaw in versions before 0.9.1 where three memory functions (listMemories, deleteMemory, and clearAgentMemory) didn't properly verify that an authenticated attacker (someone who had valid login credentials) actually owned the data they were accessing. This meant an attacker could read, delete, or clear another user's conversation history and agent data if they knew that user's identifiers, breaking the isolation between different users' data.

CVE-2026-53557: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use

criticalvulnerability
security
Sep 17, 2026
CVE-2026-53557

SQLBot is a system that converts natural language questions into SQL database queries using AI and RAG (retrieval-augmented generation, where the system pulls in external data to help answer questions). Before version 1.9.0, authenticated users could exploit a second-order SQL injection (a type of attack where malicious code is stored first, then executed later) by crafting a fake table name in an Excel configuration file, which would then run as dangerous commands when the datasource was deleted.

CVE-2026-53556: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat

highvulnerability
security
Sep 17, 2026
CVE-2026-53556

SQLBot is a system that converts natural language questions into SQL database queries using AI and RAG (retrieval-augmented generation, where external data sources help the AI answer questions). Before version 1.9.0, the system failed to safely handle user-supplied table names when building SQL queries, allowing authenticated attackers to use special PostgreSQL functions to read sensitive files like /etc/passwd (which contains user account information) and configuration files, potentially exposing secrets and source code.

CVE-2026-53555: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl

highvulnerability
security
Sep 17, 2026
CVE-2026-53555

SQLBot, a system that converts natural language questions into database queries using AI and external data retrieval, had a security flaw before version 1.9.0 where authenticated users could upload SVG image files with embedded malicious code. When other users viewed these images, the malicious code would run in their browser session, potentially allowing attackers to steal data or perform actions on behalf of victims (this vulnerability is called stored cross-site scripting, where harmful code is saved and executed later).

Previous4 / 465Next
Dark Reading

Fix: Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.

NVD/CVE Database

Fix: Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.

NVD/CVE Database
NVD/CVE Database

The Linux Kernel contains an out-of-bounds write vulnerability (a bug where software writes data outside its intended memory area) in the ebtables SNAT target that allows attackers to manipulate network packet addresses and potentially corrupt system memory. This flaw affects end-of-life products, and users are advised to either apply vendor patches or stop using affected systems. The vulnerability is currently being exploited by attackers in real-world attacks.

Fix: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance for patching. If mitigations are unavailable, discontinue use of the product. Multiple patches are available in the Linux stable kernel repository (referenced via the git.kernel.org commit links provided). Stakeholders must evaluate their systems' internet exposure and adhere to BOD 26-04 patching guidelines by the due date of 2026-09-21.

CISA Known Exploited Vulnerabilities

The Linux Kernel has a race condition vulnerability (a bug where concurrent, simultaneous operations interfere with each other) in AF_ALG sockets (a Linux interface for cryptographic operations) that causes data to be mixed up unpredictably when multiple writes happen at the same time, corrupting the socket's internal state. This vulnerability is currently being actively exploited by attackers. The source text does not provide specific technical steps to fix the issue, only that organizations must follow vendor instructions and comply with CISA's BOD 26-04 guidance on security patching, with a deadline of September 21, 2026.

CISA Known Exploited Vulnerabilities

A bug in the Linux Kernel's TLS (Transport Layer Security, the protocol that encrypts internet traffic) receive path allows a zero-length record to bypass security checks, which could cause subsequent TLS records to be processed incorrectly. Systems running end-of-life or unsupported versions are especially at risk, and users should either apply fixes or switch to supported versions.

Fix: Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance. If mitigations are unavailable, discontinue use of the product. Specific patches are available at: https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f, https://git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, https://git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9, https://git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e, and https://git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843.

CISA Known Exploited Vulnerabilities
Simon Willison's Weblog
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
CNBC Technology

Fix: Update to version 0.9.1 or later, which fixes the issue.

NVD/CVE Database

Fix: Update to version 0.9.1, where this issue is fixed.

NVD/CVE Database

Fix: This issue is fixed in version 1.9.0.

NVD/CVE Database

Fix: Update to version 1.9.0 or later. According to the source, 'This issue is fixed in version 1.9.0.'

NVD/CVE Database

Fix: This issue is fixed in version 1.9.0.

NVD/CVE Database