What changed in AI security, Jan 26 to Feb 1, 2026
Jan 26 to Feb 1, 2026 (ISO week 2026-W05). Weeks run Monday to Sunday in UTC.
26 records published, -4 on the previous week: 4 vulnerabilities (-18), 0 incidents (no change), 13 research items (+9), 9 news items (+5), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-24779: vLLM server-side request forgery in MediaConnector via URL host bypass
CVE-2026-24779NVD/CVE Database - High
CVE-2026-24747: PyTorch weights_only unpickler memory corruption via malicious checkpoint file
CVE-2026-24747NVD/CVE Database - High
CVE-2026-24477: AnythingLLM exposes Qdrant API key via /api/setup-complete endpoint
CVE-2026-24477NVD/CVE Database - High
CVE-2026-24123: BentoML path traversal in bentofile.yaml file path fields
CVE-2026-24123NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| graphrag-vectors | PyPI | LanceDB | 3.0.1 | |
| graphrag-llm | PyPI | LiteLLM | 3.0.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 3 | 2.0 | +1.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 13.Building Trustworthy AI Agents
Peer-reviewedIEEE Xplore (Security & AI Journals)Understanding the Adversarial Landscape of Large Language Models Through the Lens of Attack Objectives
Peer-reviewedIEEE Xplore (Security & AI Journals)CA–CI: Integrating Contextual Integrity and the Capabilities Approach for Dignity Considerations in AI Governance
Peer-reviewedIEEE Xplore (Security & AI Journals)Forgotten Memories
Peer-reviewedIEEE Xplore (Security & AI Journals)NAP-Tuning: Neural Augmented Prompt Tuning for Adversarially Robust Vision-Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Safeguarding Federated Learning From Data Reconstruction Attacks via Gradient Dropout
Peer-reviewedIEEE Xplore (Security & AI Journals)Privacy-Preserving Model Transcription With Differentially Private Synthetic Distillation
Peer-reviewedIEEE Xplore (Security & AI Journals)SEGA: A Transferable Signed Ensemble Gaussian Black-Box Attack Against No-Reference Image Quality Assessment Models
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.