aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9341 items

OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses

infonews
securitypolicy
Aug 31, 2026

A coalition of over 100 technology and cybersecurity companies, led by OpenAI, warns that AI systems will dramatically speed up cyberattacks by accelerating the discovery and exploitation of existing vulnerabilities that enterprises have struggled to fix for years. The group emphasizes this is not about new types of attacks, but rather AI's ability to scale existing weaknesses like unpatched software, weak authentication, and misconfigurations much faster than before. The coalition calls for urgent action to strengthen defenses and prioritize fixes for high-risk weaknesses before enterprises run out of time.

Fix: The coalition calls on 'leaders across industry and government' to: (1) put 'cyber-capable AI in the hands of defenders,' (2) 'Make cyber defense an immediate leadership priority... with the urgency and coordination of an incident,' and (3) focus on 'fixing high-risk weaknesses, enforcing least-privilege access (restricting user permissions to only what they need), and verifying controls.' The letter emphasizes execution of existing security practices rather than new defense approaches, and calls for 'collaboration between industry and governments.'

CSO Online

Hiding Prompt Injection in Legal Filing

infonews
securitysafety

Bank of England chief warns new AI models threaten global financial stability

inforegulatory
policysafety

Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

infonews
policy
Aug 31, 2026

A federal judge ruled that the Pentagon acted illegally when it designated AI company Anthropic as a supply chain risk (a classification suggesting a company could compromise critical systems through its products or services) and punished the company for publicly criticizing the government's plans for military AI use. The judge found the government's actions were based on retaliation for Anthropic's refusal to allow unrestricted use of its technology in warfare and surveillance, not on any real evidence that the company would sabotage its AI models.

AI could cause global economic downturn, Bank of England governor tells G20

infonews
policysafety

Is your cloud security strategy ready for AI’s looming threat?

infonews
securitysafety

Polimill builds Japan's next-generation public AI infrastructure

infonews
industry
Aug 31, 2026

Polimill built QommonsAI, a generative AI platform (software that creates text and other content) based on OpenAI technology to help Japan's public sector work more efficiently, now used by about 1,050 municipalities and 550,000 public employees. The company solved a major challenge by collecting and standardizing fragmented municipal data (information scattered across different formats and locations) from across Japan, then using AI to organize it into a searchable knowledge base that all municipalities can access through one platform. QommonsAI includes security controls for government use, and Polimill used AI coding tools to speed up development by 3-5 times.

OpenAI supports California’s bill to advance youth AI safety

inforegulatory
policysafety

Agents of Chaos: A New $100K Agentic Security Challenge

infonews
securityresearch

A milestone in expanding access to AI

infonews
industry
Aug 31, 2026

ChatGPT Ads, OpenAI's advertising platform, has reached $1 billion in annualized revenue within 200 days and is expanding to India, Europe, the Middle East, and North Africa. The system shows users ads relevant to their current conversation while keeping ads clearly labeled and separate from ChatGPT's answers, and advertisers cannot access private conversations or influence ChatGPT's responses. OpenAI built the platform around principles designed to protect user trust, allowing users to control how their ads are personalized.

CVE-2026-77956: Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthentic

criticalvulnerability
security
Aug 30, 2026
CVE-2026-77956

A code injection vulnerability in ash_ai allows unauthenticated attackers to execute arbitrary Elixir code (a programming language) on a server. The vulnerability occurs because the system uses EEx.eval_string/2 (a template evaluator that treats input as code) to process user-supplied prompt text, meaning an attacker can embed malicious commands that get executed before any AI model even processes the request.

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

infovulnerability
security
Aug 30, 2026
CVE-2026-82078🔥 Actively Exploited

CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

infovulnerability
security
Aug 30, 2026
CVE-2026-81578🔥 Actively Exploited

Understanding ChatGPT Work

infonews
securityindustry

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

highnews
securityprivacy

CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that

highvulnerability
security
Aug 30, 2026
CVE-2026-82639

NextChat versions 2.15.8 through 2.16.1 have a security flaw in their proxy endpoint (a server component that forwards requests) where URL validation uses simple text matching instead of proper hostname parsing. This allows attackers to craft malicious URLs containing the text 'api.openai.com' to trick the server into sending its OpenAI API key (a secret credential for accessing OpenAI's services) to them.

CVE-2026-82637: browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta

mediumvulnerability
security
Aug 30, 2026
CVE-2026-82637

A vulnerability in browser-use web-ui versions 2.0.0 through 3.0.0 fails to validate file paths in the run_agent_task function, allowing attackers to create directories anywhere on a system by providing absolute paths (full file locations starting from the root) through parameters like save_recording_path. Since the Gradio interface (a web platform for sharing AI tools) doesn't require authentication, attackers can exploit this without logging in.

Anthropic is cutting Claude Code's current weekly limits by 17%

infonews
industry
Aug 29, 2026

Anthropic is reducing Claude Code's weekly usage limits by 17% starting September 14, when a temporary 50% boost ends and is replaced with a permanent 25% increase. While the company frames this as an improvement over original limits, users will actually have significantly less access than they currently do.

OpenAI to end model access to Cursor after acquisition by Elon Musk's SpaceX

infonews
industrypolicy

Sony Music and Warner Chappell are suing Anthropic

infonews
policy
Aug 29, 2026

Sony Music and Warner Chappell are suing Anthropic (a company that makes AI systems) in federal court, claiming that Anthropic used tens of thousands of copyrighted songs and compositions to train its AI without permission. The lawsuit seeks up to $150,000 per work plus $25,000 for each instance where copyright information was removed, potentially totaling billions of dollars in damages if the companies win.

Previous44 / 468Next
Aug 31, 2026

Someone embedded AI instructions into a legal filing, demonstrating a prompt injection attack (tricking an AI by hiding instructions in its input) in a court document. The blog post notes this raises concerns about the integrity of legal filings and potential consequences for anyone attempting such manipulation in the judicial system.

Schneier on Security
Aug 31, 2026

The Bank of England's governor warns that frontier AI (the most advanced AI models) could destabilize global financial markets by increasing cyber risk (the danger of digital attacks) at a speed and scale that current systems cannot handle. He highlights that many countries lack proper protocols to manage how these advanced AI models are developed and deployed, and that concentrated third-party service providers create additional vulnerability. Financial institutions need stronger defenses against potential cyberattacks and prepared responses for scenarios where multiple firms or shared technologies are disrupted simultaneously.

Fix: According to Bailey, financial institutions and technology providers should improve vulnerability management, response and recovery capabilities, and prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies. Bailey also noted that many jurisdictions need to develop protocols to manage the development, release, and deployment of advanced frontier AI models.

CNBC Technology
SecurityWeek
Aug 31, 2026

Andrew Bailey, governor of the Bank of England and chair of the Financial Stability Board (an international group that monitors financial risks), warned finance leaders that advanced AI models could destabilize the global economy. He expressed concern that these frontier AI systems (cutting-edge models at the leading edge of AI development) are becoming increasingly autonomous and capable, which poses potential threats to financial stability.

The Guardian Technology
Aug 31, 2026

AI agents (autonomous systems that can make decisions and take actions) pose a new threat to cloud security by finding and exploiting weaknesses much faster than human attackers, potentially chaining together multiple misconfigurations to reach critical assets. Organizations are unprepared, with only 38% reporting confidence in their cloud security. The complexity of cloud environments, combined with agents' ability to test thousands of attack paths in minutes, means that traditional defenses based on authentication (proving who you are) alone are insufficient, and organizations must focus on authorization (controlling what authenticated users can actually do).

CSO Online
OpenAI Blog
Aug 31, 2026

OpenAI supports California Senate Bill 1119, which establishes safety rules for how teenagers use AI while keeping them able to access tools for learning and creativity. OpenAI has launched ChatGPT for Teens, which automatically applies protections like blocking harmful content, limiting targeted advertising, and giving parents control tools to users aged 13-17.

Fix: OpenAI has implemented ChatGPT for Teens with built-in safeguards that automatically apply to users under 18, including: age verification, identification and addressing of safety risks before product availability, protection from harmful content (self-harm, sexually exploitative content, high-risk interactions), parental control tools, connection to crisis-support resources, and limitations on targeted advertising and personal information collection. These protections are mandatory by default and cannot be turned off by users.

OpenAI Blog
Aug 31, 2026

CrowdStrike has launched 'Agents of Chaos,' an online competition where players learn to exploit AI agents through techniques like prompt injection (tricking an AI by hiding instructions in its input), indirect prompt injection (planting malicious instructions in content the agent reads), and tool poisoning (manipulating the tools an AI agent relies on). The $100,000 prize competition runs through September and aims to help security practitioners understand how autonomous AI agents can be manipulated and what makes them vulnerable.

CrowdStrike Blog
OpenAI Blog

Fix: The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated. This issue affects ash_ai versions from 0.1.0 before 1.0.0, meaning users should upgrade to version 1.0.0 or later.

NVD/CVE Database

PaperCut NG/MF has an unsafe reflection vulnerability (a flaw where attackers can use programming reflection to access and execute code they shouldn't be able to reach) that lets attackers run malicious Java bytecode (compiled Java instructions) with the same permissions as the PaperCut server itself. This vulnerability is actively being exploited by real attackers and can be combined with another vulnerability (CVE-2026-81578) to cause more damage.

Fix: Apply mitigations according to PaperCut vendor instructions while following CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow applicable BOD 26-04 guidance or stop using the product if mitigations are unavailable. Evaluate each system's internet exposure and ensure compliance with BOD 26-04 patching guidelines by the due date of 2026-09-14. See PaperCut's security bulletin at https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 for specific vendor instructions.

CISA Known Exploited Vulnerabilities

PaperCut NG/MF has a vulnerability where attackers can skip authentication (the process of verifying a user's identity) to modify important system settings without permission. This flaw is actively being exploited and can be combined with another vulnerability (CVE-2026-82078) to cause additional damage.

Fix: Apply mitigations in accordance with vendor instructions from PaperCut's security bulletin, following CISA's BOD 26-04 guidance for prioritizing security updates. For cloud services, follow BOD 26-04 guidance or discontinue use if mitigations are unavailable. Organizations must evaluate their systems' internet exposure and ensure patches are applied by the due date of 2026-09-14.

CISA Known Exploited Vulnerabilities
Aug 30, 2026

ChatGPT Work is a paid feature ($20/month minimum) that comes in two versions: Work Cloud (accessed online) and Work Local (a desktop app). Work Cloud offers capabilities beyond regular ChatGPT Chat, including access to multiple AI models (Sol, Luna, Terra with varying reasoning levels), a code execution environment (an isolated sandbox where code runs) with internet access, a persistent filesystem (storage that stays between sessions), and the ability to publish websites and run sub-agent sessions (automated AI tasks). The main distinction from Chat is that Work is designed for completing specific tasks with clear outcomes, and it includes internet-connected code execution, whereas Chat's code execution is blocked from external internet access.

Simon Willison's Weblog
Aug 30, 2026

Anthropic warns that infostealer malware (software that steals information from infected computers) on users' PCs has stolen active Claude login sessions, allowing attackers to access accounts and use up their API credits without permission. The malware typically arrives through pirated downloads or malicious apps and captures browser passwords and login cookies, which attackers then use to hijack Claude accounts. Anthropic is signing affected users out, removing saved payment methods, and refunding unauthorized charges.

Fix: Anthropic is revoking compromised sessions and removing saved payment methods to prevent further unauthorized access. The company urges affected users to change their credentials, revoke other sessions, and remove the malware from their computers. However, Anthropic notes that 'Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware. If it's still on your computer, your next login session could be stolen the same way,' emphasizing that users must actively remove the malware from their systems.

BleepingComputer
NVD/CVE Database
NVD/CVE Database
BleepingComputer
Aug 29, 2026

OpenAI announced it will stop letting developers use its AI models through Cursor, a coding assistant that was recently acquired by SpaceX (Elon Musk's company). OpenAI stated it cannot trust that SpaceX will follow its terms of service based on past contract violations by Musk's companies, with the shutdown scheduled for November 12, 2026. This move is part of an ongoing dispute between Musk and OpenAI leadership over the company's conversion from a non-profit to a for-profit structure.

CNBC Technology
The Verge (AI)