Skip to content

What changed in AI security, Mar 9 to Mar 15, 2026

Mar 9 to Mar 15, 2026 (ISO week 2026-W11). Weeks run Monday to Sunday in UTC.

170 records published, -30 on the previous week: 18 vulnerabilities (-22), 0 incidents (no change), 18 research items (-4), 134 news items (-4), 0 policy items (no change).

Critical and high advisories

Vulnerability records rated critical or high, newest first.

Exploitation signals

Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.
AdvisoryExploitationEPSSPublished
CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
CVE-2025-68613CISA Known Exploited Vulnerabilities
Known exploited99.0%

Packages that began delegating to a language model

Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.
PackageEcosystemLLM SDKsReleaseReleased
nemo-gymPyPIAnthropic SDK, Model Context Protocol SDK, OpenAI SDK0.2.0
ddgsPyPIModel Context Protocol SDK9.11.3
langchain-plaidPyPILangChain0.1.0

Topics that moved

Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.
TopicRecordsWeekly mean, previous 4Difference
AI agents3012.3+17.8
Deepfakes and impersonation70.8+6.3
Prompt injection and jailbreaks52.0+3.0

Research

Peer-reviewed first, then newest. Showing 8 of 18.

Policy and regulation

Newest first.

No regulatory or policy records were published in this week.

Generated from the AI Sec Watch database at . Every item links to its record.

RSS feed of weekly changesPrevious week