What changed in AI security, Sep 29 to Oct 5, 2025
Sep 29 to Oct 5, 2025 (ISO week 2025-W40). Weeks run Monday to Sunday in UTC.
16 records published, -11 on the previous week: 10 vulnerabilities (-12), 0 incidents (no change), 5 research items (+2), 1 news item (no change), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2025-59944: Cursor IDE case-sensitive file protection bypass allowing code execution
CVE-2025-59944NVD/CVE Database - High
CVE-2025-61593: Cursor CLI Agent prompt injection leads to code execution
CVE-2025-61593NVD/CVE Database - High
CVE-2025-61592: Cursor CLI remote code execution via malicious repository config
CVE-2025-61592NVD/CVE Database - High
CVE-2025-61591: Cursor command injection via MCP OAuth with untrusted server
CVE-2025-61591NVD/CVE Database - High
CVE-2025-61590: Cursor remote code execution through Visual Studio Code workspaces
CVE-2025-61590NVD/CVE Database - High
CVE-2025-59536: Claude Code code injection through startup trust dialog
CVE-2025-59536NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-59536: Claude Code code injection through startup trust dialog CVE-2025-59536NVD/CVE Database | Not listed | 27.2% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 3 | 2.8 | +0.3 |
Research
Peer-reviewed first, then newest.Privacy-Preserving Federated Learning Scheme With Mitigating Model Poisoning Attacks: Vulnerabilities and Countermeasures
Peer-reviewedIEEE Xplore (Security & AI Journals)Toward a Secure Framework for Regulating Artificial Intelligence Systems
Peer-reviewedIEEE Xplore (Security & AI Journals)Successfully Mitigating AI Management Risks to Scale AI Globally
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)AI-Shielder: Exploiting Backdoors to Defend Against Adversarial Attacks
Peer-reviewedIEEE Xplore (Security & AI Journals)SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.