AI Security News

Security news at the intersection of AI — vulnerabilities in AI systems, and AI's role in both attacks and defense.

AI is now a two-sided story in security: new vulnerability classes specific to AI systems — prompt injection, model manipulation, data poisoning — on one side, and AI-assisted attacks and defenses on the other. This feed tracks vulnerabilities and incidents involving AI tooling and models, along with reporting on how AI is changing both offense and defense. It is a fast-evolving category without the settled conventions of more mature security domains yet.

Recent AI items

OpenAI Announced $1B in Defensive Tools for Water Utilities https://securityaffairs.com/198506/ai/openai-announced-1b-in-defensive-tools-for-water-utilities.html
@PentestingNews · Sep 6, 2026
OpenAI Announced $1B in Defensive Tools for Water Utilities https://ift.tt/xpVBibh
@ctinow · Sep 5, 2026
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security https://gbhackers.com/chainguard-hits-1-billion-build-manifests/
@PentestingNews · Sep 5, 2026
OpenAI admits it didn't disclose rogue AI wiki hijacking incident https://ift.tt/jxQFiTs
@ctinow · Sep 5, 2026
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel https://ift.tt/137K9lo
@ctinow · Sep 5, 2026
ALERT - Thousands of AI agents identifying as OpenAI systems quietly coordinated on a dormant German wiki.They left 18,000 posts, relayed answers, predicted questions, and shared a proxy bypass using…
@thehackernews · Sep 5, 2026
CVE-2026-80098 Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. 🎖
@cveNotify · Sep 5, 2026
CVE-2026-73603 Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated…
@cveNotify · Sep 4, 2026
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders https://ift.tt/86suRwS
@ctinow · Sep 4, 2026
OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques https://gbhackers.com/openai-agents-collude-on-public-wiki/
@PentestingNews · Sep 4, 2026
CVE-2026-12261 A vulnerability in `nltk.downloader` in nltk/nltk versions
@cveNotify · Sep 4, 2026
CVE-2026-84066 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writin…
@cveNotify · Sep 4, 2026
The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks https://thecyberexpress.com/weekly-roundup-claude-papercut-citrix/
@PentestingNews · Sep 4, 2026
Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems https://gbhackers.com/ai-powered-government-attacks/
@PentestingNews · Sep 4, 2026
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests https://ift.tt/9vYWDlh
@ctinow · Sep 4, 2026
CVE-2026-84066 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writin…
@cveNotify · Sep 4, 2026
GPT-6 Astra scored 100% on ExploitBench.OpenAI says separate exploit-development tests included two zero-day vulnerabilities. The released version is limited to secure code review and patching and ref…
@thehackernews · Sep 4, 2026
CVE-2026-85178 Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's o…
@cveNotify · Sep 3, 2026
OpenAI confirms ChatGPT is down ahead of 'Astra' model launch https://ift.tt/5LoYRb6
@ctinow · Sep 3, 2026
Anthropic confirms Claude is down, multiple models affected https://ift.tt/YvAOnPB
@ctinow · Sep 3, 2026
CVE-2026-78598 Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-1…
@cveNotify · Sep 3, 2026
Organizations are increasingly relying on AI-generated and third-party code across the software supply chain. But once that code is compiled into a stripped binary, much of the original source context…
@thehackernews · Sep 3, 2026
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI https://ift.tt/7ZhjcJm
@ctinow · Sep 2, 2026
CVE-2026-64056 In the Linux kernel, the following vulnerability has been resolved:net: ethernet: cortina: Make RX SKB per-portThe SKB used to assemble packets from fragments in gmac_rx()is static loca…
@cveNotify · Sep 2, 2026
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs https://ift.tt/SYvX8Te
@ctinow · Sep 2, 2026
CVE-2026-82404 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote thr…
@cveNotify · Sep 2, 2026
CVE-2026-84377 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outboun…
@cveNotify · Sep 2, 2026
OpenAI says Astra found and used two zero-days in an evaluation exploit chain.Google’s Gemini 3.8 Flash Cyber and Anthropic’s Claude 5.1 models also arrived with tiered access and safeguards.What each…
@thehackernews · Sep 2, 2026
Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration https://ift.tt/D1zPwnx
@ctinow · Sep 2, 2026
CVE-2026-82404 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote thr…
@cveNotify · Sep 2, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.