AI Security News

Security news at the intersection of AI — vulnerabilities in AI systems, and AI's role in both attacks and defense.

AI is now a two-sided story in security: new vulnerability classes specific to AI systems — prompt injection, model manipulation, data poisoning — on one side, and AI-assisted attacks and defenses on the other. This feed tracks vulnerabilities and incidents involving AI tooling and models, along with reporting on how AI is changing both offense and defense. It is a fast-evolving category without the settled conventions of more mature security domains yet.

Recent AI items

CVE-2026-49986The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by…
@cveNotify · Aug 14, 2026
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Themhttps://ift.tt/H6wVMdF
@ctinow · Aug 14, 2026
CVE-2026-72642The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside…
@cveNotify · Aug 14, 2026
CVE-2026-72675Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carri…
@cveNotify · Aug 13, 2026
CVE-2026-73555vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestVa…
@cveNotify · Aug 13, 2026
AI has fundamentally changed email attacks.See how attackers create convincing AI-powered phishing campaigns, why traditional email security struggles to stop them, and how AI-native detection catches…
@thehackernews · Aug 13, 2026
CVE-2026-67991crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A…
@cveNotify · Aug 13, 2026
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwanhttps://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/
@PentestingNews · Aug 13, 2026
CVE-2026-73298The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configuration…
@cveNotify · Aug 12, 2026
CVE-2026-73299Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestri…
@cveNotify · Aug 12, 2026
CVE-2026-73298The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configuration…
@cveNotify · Aug 12, 2026
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwanhttps://ift.tt/p0BJ8P1
@ctinow · Aug 12, 2026
CVE-2026-73264Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible…
@cveNotify · Aug 12, 2026
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoninghttps://ift.tt/wu6MP4z
@ctinow · Aug 12, 2026
Researchers found a way to make a weaker AI decode a stronger model's hidden reasoning.They extracted hidden traces from OpenAI, Anthropic, and Google APIs, recovering secret API keys and passwords, a…
@thehackernews · Aug 12, 2026
CVE-2026-48762TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF p…
@cveNotify · Aug 11, 2026
CVE-2026-73032PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is p…
@cveNotify · Aug 11, 2026
CVE-2026-70335Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges…
@cveNotify · Aug 11, 2026
CVE-2026-65675No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.🎖@cveNotify
@cveNotify · Aug 11, 2026
CVE-2026-72922AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api…
@cveNotify · Aug 11, 2026
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Developmenthttps://ift.tt/HouSx3O
@ctinow · Aug 11, 2026
CVE-2026-72771n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged…
@cveNotify · Aug 11, 2026
OpenAI just released a more cyber-permissive GPT-5.6.GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some…
@thehackernews · Aug 11, 2026
Corma Raises $60 Million for Defensive Cybersecurity AI Modelhttps://ift.tt/TQdDozJ
@ctinow · Aug 11, 2026
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyberhttps://ift.tt/u9TtNiC
@ctinow · Aug 11, 2026
Anthropic Adds Invisible Watermarks to Claude AI-Generated Text and Signed Metadata to Fileshttps://gbhackers.com/anthropic-adds-invisible-watermarks-to-claude-ai-generated-text/
@PentestingNews · Aug 11, 2026
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chainshttps://gbhackers.com/openai-launches-gpt-5-6-cyber-to-find-zero-day-vulnerabilities/
@PentestingNews · Aug 11, 2026
Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attackshttps://gbhackers.com/claude-code-auto-mode-blocks-attacks/
@PentestingNews · Aug 11, 2026
OpenAI says Daybreak will expand to offer specialized cyber serviceshttps://cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/
@PentestingNews · Aug 11, 2026
CVE-2026-19368A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/ge…
@cveNotify · Aug 11, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.