All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability (a flaw in the rules that decide who can access what data) that allows attackers to unauthorized create, delete, or modify critical data, or gain complete access to all data these systems can reach. This vulnerability is currently being exploited by attackers in the real world.
Fix: Apply mitigations per vendor instructions (Oracle), follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The due date for remediation is 2026-08-27. For detailed instructions, see Oracle's security alert at https://www.oracle.com/security-alerts/cpujan2026.html
CISA Known Exploited VulnerabilitiesAnthropic's most advanced AI model is facing adoption challenges as cheaper alternatives gain traction in the market. While Anthropic's revenue grew significantly to $65 billion annualized by July 2026, data from the Ramp AI index (which tracks AI model spending across 70,000 companies) shows that users are gravitating toward older, less expensive Anthropic models like Opus 4.8 rather than the newest Opus 5 released in July.
A video game called Halloween: The Game was banned in Australia by the Classification Board, not because of its graphic violence and killings, but due to what regulators identified as 'incentivised drug use' in the gameplay. The ban has prompted criticism from academics and former officials who argue Australia's classification standards are inconsistent, since the game's extreme violence alone wasn't the reason for the ban.
This survey article examines how generative AI (machine learning models that can create new content) is being used to produce deepfakes (synthetic media where a person's face or voice is digitally manipulated to appear authentic) and discusses methods to detect them. The paper reviews current techniques for both creating and identifying deepfakes, and considers future challenges in an era where AI-generated content is becoming increasingly sophisticated and difficult to distinguish from real media.
This academic survey examines how AI and intelligent technologies affect security in IoV (Internet of Vehicles, where connected cars communicate with each other and infrastructure). The paper discusses integrating edge computing (processing data closer to vehicles rather than in distant data centers) with AI to improve IoV security, though specific vulnerabilities and their fixes are not detailed in this overview.
This is a research survey paper published in ACM Computing Surveys that compares security risks across different types of AI systems, including LLMs (large language models, which are AI systems trained on massive amounts of text), AI agents (systems that can take actions based on their decisions), and embodied agents (AI systems that interact with the physical world through robots or similar devices). The paper examines and contrasts the various security vulnerabilities and threats that each of these AI system types faces.
OpenAI's chief global affairs officer warns that people need to prepare for "ongoing, persistent" cyber-attacks launched by advanced AI systems, as these models gain capabilities to plan and execute attacks. The company has paused development of its most advanced internal models due to rising safety concerns, signaling a new phase in AI development where the technology poses greater security risks.
Researchers have developed a method for encrypting images using deep learning combined with chaotic systems (mathematical systems that produce unpredictable, random-looking outputs). The approach reconstructs chaotic patterns using neural networks to create a security system that scrambles images in a way that makes them unreadable without the correct decryption key.
FlexDPI is a system for deep packet inspection (DPI, where network traffic is examined in detail to monitor what data is being sent) that aims to protect user privacy while still allowing network monitoring. The research presents a method that lets users choose which security rules apply to their traffic, while using verification techniques to ensure the system works correctly without exposing sensitive information.
This academic paper proposes a new authentication system that combines blockchain (a distributed ledger technology that records data across many computers) with privacy protection methods for military surveillance applications in 6G (the next generation of wireless networks). The framework is designed to allow secure identification and verification of users while keeping their personal information hidden from unauthorized access.
BEdX25519 is a lightweight authenticated key exchange protocol (a method for two devices to securely agree on encryption keys) designed for IoT (Internet of Things) devices to communicate directly with each other using blockchain (a distributed ledger technology) and elliptic curve cryptography (a type of mathematical encryption based on curves). The protocol aims to make secure device-to-device communication more efficient for resource-constrained IoT systems.
This academic paper, published in September 2026, describes a method for securely accessing encrypted data using hardware tokens (physical devices that store security credentials). The research presents a scheme designed to protect data while allowing authorized users to access it through these specialized hardware devices.
This academic paper describes a method for protecting videos using watermarking (a technique that embeds hidden information into media to prove ownership or detect tampering) by applying multiple mathematical transformations to make the watermark resistant to attacks. The research, published in November 2026, proposes using orthogonal transformations (mathematical operations that preserve certain properties) in combination to create a hybrid approach that is harder for attackers to remove or corrupt.
This academic paper proposes an improved authentication scheme for IoV (Internet of Vehicles, where connected cars communicate with each other and infrastructure) based on an enhanced BLS signature algorithm (a cryptographic method for verifying that a message came from a legitimate source). The research focuses on making vehicle authentication more efficient while maintaining security for connected vehicle systems.
This is a research paper about a new method for protecting images by combining compression (making files smaller) and encryption (scrambling data so only authorized people can read it) using a 2D coupled chaotic map (a mathematical technique that creates unpredictable patterns). The paper proposes an algorithm that allows the encrypted images to be traced or verified, adding an extra security layer beyond standard image protection.
This academic paper describes a new cryptographic method called revocable predicate encryption for inner products (a mathematical operation that combines two vectors), built using dual pairing vector space (a mathematical structure for encryption). The research presents a theoretical approach to encryption that allows certain access rights to be revoked, or taken away, after they've been granted, while maintaining security properties.
This research paper presents a framework that combines reversible data hiding (a technique to hide information within data while being able to completely restore the original data later) with homomorphic encryption (encryption that allows computations to be performed on encrypted data without decrypting it first). The approach is designed to work with dispersed data (information spread across multiple locations or systems) and offers a general method that could be applied to various scenarios.
N/A -- This is a research publication about image watermarking (hiding data inside images) using statistical modeling techniques, not an AI/LLM security issue, vulnerability, or incident.
Researchers have developed a new authentication and key agreement protocol (a method for securely verifying users and establishing encrypted connections) that combines PUF (physical unclonable functions, unique hardware fingerprints that cannot be copied) and biometrics (biological traits like fingerprints) to allow users to maintain secure sessions while moving between different systems or networks. The protocol is designed to preserve anonymity while enabling seamless handover across domains (separate security zones or organizations).
This research paper proposes a watermarking-based intrusion detection system for CAN bus (Controller Area Network, a communication system used in vehicles and industrial equipment) that uses dynamic wavelet analysis to detect malicious messages and resist attacks on the detection model itself. The system aims to protect CAN bus communications from unauthorized access and manipulation while remaining robust against adversarial attacks (attempts to fool the security system).