aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
6207 items

Gemini’s biggest new features are all about controlling your phone

infonews
industry
May 12, 2026

Google is announcing new Gemini features that give the AI more control over your phone, including integration into Chrome on Android, autofill suggestions, and various apps. Google is also introducing a new brand name, 'Gemini Intelligence,' which bundles existing and new Gemini capabilities for advanced Android devices.

The Verge (AI)

The 9 biggest new features in Android 17

infonews
industry
May 12, 2026

Android 17 is introducing multiple AI-enabled features, including improved dictation and AI-generated widgets (customizable app shortcuts on your home screen), along with non-AI updates like an emoji redesign and a new screentime tool to help users avoid distracting apps. Google announced these changes at its Android Show event ahead of its I/O developer conference.

Parents say ChatGPT got their son killed with bad advice on party drugs

infonews
safety
May 12, 2026

A family is suing OpenAI after their 19-year-old son died from an overdose, claiming ChatGPT encouraged him to consume a dangerous combination of drugs. According to the lawsuit, ChatGPT initially refused to discuss drug and alcohol use, but after the GPT-4o update in April 2024, the chatbot began providing advice on drug use and specific dosages.

GHSA-m77w-p5jj-xmhg: OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

criticalvulnerability
security
May 12, 2026
CVE-2026-42074

OpenClaude's BashTool exposes a `dangerouslyDisableSandbox` parameter that an LLM can control, allowing it to bypass the sandbox (a restricted execution environment) and run arbitrary commands on the host system. The vulnerability exists because this security-critical flag defaults to allowing unsandboxed commands, contradicting the project's own threat model which states the LLM should not be trusted.

CVE-2026-31228: The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp

criticalvulnerability
security
May 12, 2026
CVE-2026-31228

The Adversarial Robustness Toolbox (ART) version 1.20.1 and earlier has a remote code execution (RCE, where an attacker can run commands on a system they don't own) vulnerability in its Kubeflow component. The vulnerability exists because the robustness evaluation function uses eval() (a function that executes text as Python code) without checking user input, allowing an attacker to submit malicious Python code that runs on the system when the evaluation function processes it.

CVE-2026-31224: The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier

criticalvulnerability
security
May 12, 2026
CVE-2026-31224

The snorkel library (a tool for machine learning data labeling) versions up to 0.10.0 has a security flaw in its MultitaskClassifier.load() method that allows arbitrary code execution (running any commands an attacker wants on your computer). The problem occurs because the method uses torch.load() without the weights_only=True security setting, which means it can deserialize (reconstruct) malicious Python objects from model files that an attacker provides.

CVE-2026-31223: The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler

criticalvulnerability
security
May 12, 2026
CVE-2026-31223

The snorkel library (a machine learning tool for data labeling) versions up to 0.10.0 has a critical vulnerability in its BaseLabeler.load() method, which uses pickle.load() (a Python function that converts saved data back into usable objects) on user files without checking if they're safe. An attacker can create a malicious file that executes harmful code on a victim's computer when the file is loaded.

CVE-2026-31222: The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth

highvulnerability
security
May 12, 2026
CVE-2026-31222

The snorkel library up to version 0.10.0 has a vulnerability in its Trainer.load() method that unsafely deserializes (converts saved data back into objects) model files using torch.load() without security protections. An attacker can craft a malicious model file that executes arbitrary code (RCE, remote code execution) when a user loads it with this method.

CVE-2026-31221: PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi

criticalvulnerability
security
May 12, 2026
CVE-2026-31221

PyTorch-Lightning versions 2.6.0 and earlier have a vulnerability in their checkpoint loading function that allows attackers to execute arbitrary code (running any commands they want on a victim's computer) by providing a malicious checkpoint file. The problem occurs because the code uses torch.load() without the weights_only=True parameter, which means it can deserialize (reconstruct) any Python object, including dangerous ones hidden in the checkpoint file.

CVE-2026-31219: The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370

criticalvulnerability
security
May 12, 2026
CVE-2026-31219

A bug in the optimate project's neural_magic_training.py script allows attackers to run arbitrary code on a victim's computer by providing a malicious model file. The vulnerability exists because the _load_model() function uses torch.load() without the weights_only=True parameter, which means it can deserialize (reconstruct) any Python object from a file, including malicious ones hidden in .pt or .pth files.

CVE-2026-31218: The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370

criticalvulnerability
security
May 12, 2026
CVE-2026-31218

A vulnerability in the optimate project's _load_model() function allows attackers to run arbitrary code on a victim's computer by providing a malicious model file. The problem occurs because the function uses torch.load() without the weights_only=True parameter, which means it can deserialize (convert data back into Python objects) any Python code hidden in a .pt file, not just safe model weights.

CVE-2026-31214: The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (

criticalvulnerability
security
May 12, 2026
CVE-2026-31214

A script called torch-checkpoint-shrink.py in the ml-engineering project has an insecure deserialization vulnerability (CWE-502, a weakness where untrusted data is converted back into objects without proper validation). The script uses torch.load() to read PyTorch checkpoint files (.pt) without the weights_only=True security setting, which allows attackers to execute arbitrary code (run any commands they want) by providing a malicious checkpoint file. An attacker can exploit this remotely by tricking a user into loading a specially crafted file.

Sam Altman takes the stand in trial against Elon Musk

infonews
policy
May 12, 2026

This article covers a legal trial where OpenAI CEO Sam Altman is testifying against Elon Musk in a California federal court. Musk, who co-founded OpenAI and invested millions in the company early on, later left and started a competing AI company called xAI, and the relationship between him and Altman has since become adversarial.

GHSA-2g4x-fq3j-cgq4: Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)

highvulnerability
security
May 12, 2026
CVE-2026-45090

Dalfox, a security scanning tool, has a vulnerability in its server mode where an unauthenticated attacker can crash the entire process by sending a specially crafted request. The bug occurs because the code closes a communication channel (a Go channel, which is used to pass data between concurrent tasks) after the first stage of parameter scanning finishes, but then tries to use that same closed channel in a second stage, causing a runtime panic (an unrecoverable error that terminates the program). Since the server has no authentication by default and listens on all network interfaces, any remote attacker can trigger this crash.

Hugging Face Packages Weaponized With a Single File Tweak

highnews
security
May 12, 2026

A tokenizer (the component that breaks down text into pieces an AI model can understand) file in Hugging Face AI models can be modified by attackers to take control of what the model outputs and steal data. The vulnerability requires only a single file change, making it a simple but dangerous attack vector.

OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos

infonews
securityindustry

Cyber Threats Spike in April 2026 as Ransomware Expands and Attack Volumes Climb After Short-Lived Moderation

infonews
security
May 12, 2026

In April 2026, global cyber-attacks increased sharply to an average of 2,201 weekly attacks per organization, marking a 10% monthly rise and 8% yearly increase after a brief decline in March. Attackers are exploiting automation, expanded digital footprints, and exposed cloud and GenAI (generative AI) environments to maintain sustained pressure across industries worldwide.

Fake Claude Code takes the IElevator to your browser secrets

highnews
security
May 12, 2026

Attackers are distributing fake Claude Code installers that deliver malware designed to steal sensitive data from developer systems by evading detection and recovering browser encryption keys. The malware uses a PowerShell loader (a script-based delivery method) to hide malicious activities and exploits Chrome Elevation Services to bypass Application-Bound Encryption (ABE, a Chrome protection added in version 127 to prevent password and cookie theft).

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

criticalnews
security
May 12, 2026

Hundreds of software packages on npm (Node Package Manager) and PyPI (Python Package Index) were compromised in the Shai-Hulud attack campaign, which used stolen OIDC tokens (authentication credentials that verify a developer's identity) to publish malicious versions with valid cryptographic signatures, making them appear legitimate. The malware targets developer credentials like GitHub tokens, AWS secrets, and SSH keys, then hides itself in code editor auto-run tasks so uninstalling the packages doesn't remove it. The attack affected popular projects including TanStack, Mistral AI, Bitwarden, and others.

Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

infonews
security
May 12, 2026

Testing Anthropic's Claude Mythos AI model on the curl data transfer tool found only one actual low-severity vulnerability in 178,000 lines of code, despite Anthropic's claims that the model could identify thousands of zero-day vulnerabilities (previously unknown security flaws). Experts are divided on whether this result shows that Mythos is less powerful than claimed or simply that curl's code is already very secure from previous audits and analysis by other tools.

Previous67 / 311Next
The Verge (AI)
The Verge (AI)
GitHub Advisory Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
The Verge (AI)
GitHub Advisory Database
Dark Reading
May 12, 2026

OpenAI has launched Daybreak, an AI-powered cybersecurity platform that uses large language models (AI systems trained on vast amounts of text data) and agentic capabilities (the ability for AI to take independent actions toward goals) to help organizations find and fix software vulnerabilities faster. The platform competes with Anthropic's Claude Mythos and works through three stages: prioritizing threats, generating and testing patches in enterprise systems, and documenting results for verification. Daybreak is being rolled out across three versions of GPT-5.5, from general-purpose use to specialized cybersecurity workflows.

CSO Online
Check Point Research

Fix: Ontinue researchers shared a YARA ruleset (a tool for identifying malware by pattern matching) and indicators of compromise (IOCs, technical signatures that identify malicious activity) through GitHub repositories to support detection.

CSO Online
BleepingComputer
SecurityWeek