All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Recent warnings have raised concerns that advanced AI systems could pose existential risks to humanity, with claims ranging from potential misuse by criminals and state actors to creating weapons and biological threats. Industry figures like those at Anthropic and Elon Musk have publicly warned about these dangers, prompting tech reporters to examine whether these concerns are justified and to answer public questions about the scale of AI-related risks.
An AI agent (a software system that can act autonomously to complete tasks) was used to breach a Spanish organization and modify personal data. The article suggests that AI-driven attacks are becoming increasingly common and will soon be a standard tool for attackers rather than an unusual occurrence.
The MasterStudy LMS WordPress Plugin (a learning management system add-on for WordPress) in versions before 3.7.50 has a security flaw where it doesn't check whether a user actually owns a course before showing them student enrollment data. This means instructors can see the names and email addresses of students in other instructors' courses, leaking private student information.
The MasterStudy LMS WordPress Plugin (a learning management system tool for WordPress) before version 3.7.50 has a security flaw where it doesn't check whether users own or have permission to modify orders through its REST API (a system that lets external programs interact with WordPress). This allows instructors to change any order on the site, including giving people free course access, removing others' paid enrollments, and editing order notes.
A flaw in Microsoft 365 Copilot's permission settings allows someone with authorized access to improperly view sensitive information across a network. The issue stems from incorrect assignment of permissions (access rules) to a critical resource (important data or system component), meaning the AI tool isn't properly restricting who can see what.
Thomas Ptacek recommends using LLMs as copyediting tools rather than writing assistants, with a strict rule to never use specific phrases that an LLM suggests. He advocates for LLMs to help with fact-checking, spelling, grammar, and finding synonyms, but argues that adopting LLM-suggested wording produces text with a distinctive and undesirable quality.
vLLM (a software framework for running large language models) versions up to 0.29.0 has a memory cleanup bug in its decode workers (specialized processors that handle the generation phase of AI inference). Attackers can exploit this by sending requests with max_tokens=0 (asking for zero output tokens), which prevents the system from properly clearing temporary data, eventually consuming all available memory until the worker crashes and restarts.
M365 Copilot has a command injection vulnerability (a flaw where special characters in user input can trick the system into running unintended commands), which allows an authorized attacker to gain higher privileges over a network. The vulnerability affects users who already have some level of access to the system.
Microsoft 365 Copilot's Business Chat has a vulnerability where special characters are not properly filtered before being used in commands, allowing attackers to inject malicious commands (command injection, where an attacker sneaks unauthorized instructions into a system by exploiting how it processes input). This could let unauthorized people access and steal sensitive information across the network.
Azure Machine Learning contains a vulnerability where authorization checks (the system that verifies whether a user is allowed to perform an action) are not working correctly, allowing an attacker without permission to access and steal sensitive information over the internet.
Microsoft Copilot has a command injection vulnerability (a flaw where special characters in user input are not properly filtered, allowing attackers to execute unintended commands), which lets an unauthorized attacker access and leak sensitive information over a network.
Anthropic released three new metrics to help monitor how quickly AI is being developed, following CEO Dario Amodei's call for the AI industry to slow down its pace of advancement. The metrics measure AI-led research and development, oversight of AI agents (software that can perform tasks independently), and how computing resources are allocated within the company, with the goal of making AI development more transparent to the public so society can decide how to use this information.
AI Agent Automation, a platform for managing AI workflows with scheduling and monitoring tools, has a vulnerability in versions before 0.9.1 where authenticated users can manipulate file paths to escape the intended workspace directory and read sensitive files or overwrite files that the application can access. The vulnerability occurs because the system doesn't verify that file paths stay within approved directories after resolving them.
AI Agent Automation, a platform that runs automated AI workflows (sequences of actions controlled by AI), had a security flaw in versions before 0.9.1 where three memory functions (listMemories, deleteMemory, and clearAgentMemory) didn't properly verify that an authenticated attacker (someone who had valid login credentials) actually owned the data they were accessing. This meant an attacker could read, delete, or clear another user's conversation history and agent data if they knew that user's identifiers, breaking the isolation between different users' data.
SQLBot is a system that converts natural language questions into SQL database queries using AI and RAG (retrieval-augmented generation, where the system pulls in external data to help answer questions). Before version 1.9.0, authenticated users could exploit a second-order SQL injection (a type of attack where malicious code is stored first, then executed later) by crafting a fake table name in an Excel configuration file, which would then run as dangerous commands when the datasource was deleted.
SQLBot is a system that converts natural language questions into SQL database queries using AI and RAG (retrieval-augmented generation, where external data sources help the AI answer questions). Before version 1.9.0, the system failed to safely handle user-supplied table names when building SQL queries, allowing authenticated attackers to use special PostgreSQL functions to read sensitive files like /etc/passwd (which contains user account information) and configuration files, potentially exposing secrets and source code.
SQLBot, a system that converts natural language questions into database queries using AI and external data retrieval, had a security flaw before version 1.9.0 where authenticated users could upload SVG image files with embedded malicious code. When other users viewed these images, the malicious code would run in their browser session, potentially allowing attackers to steal data or perform actions on behalf of victims (this vulnerability is called stored cross-site scripting, where harmful code is saved and executed later).
Fix: Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.
NVD/CVE DatabaseFix: Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.
NVD/CVE DatabaseThe Linux Kernel contains an out-of-bounds write vulnerability (a bug where software writes data outside its intended memory area) in the ebtables SNAT target that allows attackers to manipulate network packet addresses and potentially corrupt system memory. This flaw affects end-of-life products, and users are advised to either apply vendor patches or stop using affected systems. The vulnerability is currently being exploited by attackers in real-world attacks.
Fix: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance for patching. If mitigations are unavailable, discontinue use of the product. Multiple patches are available in the Linux stable kernel repository (referenced via the git.kernel.org commit links provided). Stakeholders must evaluate their systems' internet exposure and adhere to BOD 26-04 patching guidelines by the due date of 2026-09-21.
CISA Known Exploited VulnerabilitiesThe Linux Kernel has a race condition vulnerability (a bug where concurrent, simultaneous operations interfere with each other) in AF_ALG sockets (a Linux interface for cryptographic operations) that causes data to be mixed up unpredictably when multiple writes happen at the same time, corrupting the socket's internal state. This vulnerability is currently being actively exploited by attackers. The source text does not provide specific technical steps to fix the issue, only that organizations must follow vendor instructions and comply with CISA's BOD 26-04 guidance on security patching, with a deadline of September 21, 2026.
A bug in the Linux Kernel's TLS (Transport Layer Security, the protocol that encrypts internet traffic) receive path allows a zero-length record to bypass security checks, which could cause subsequent TLS records to be processed incorrectly. Systems running end-of-life or unsupported versions are especially at risk, and users should either apply fixes or switch to supported versions.
Fix: Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance. If mitigations are unavailable, discontinue use of the product. Specific patches are available at: https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f, https://git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, https://git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9, https://git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e, and https://git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843.
CISA Known Exploited VulnerabilitiesFix: Update to version 0.9.1 or later, which fixes the issue.
NVD/CVE DatabaseFix: Update to version 0.9.1, where this issue is fixed.
NVD/CVE DatabaseFix: This issue is fixed in version 1.9.0.
NVD/CVE DatabaseFix: Update to version 1.9.0 or later. According to the source, 'This issue is fixed in version 1.9.0.'
NVD/CVE DatabaseFix: This issue is fixed in version 1.9.0.
NVD/CVE Database