$ tail -f ./news/ai-security

AI Security News Feed

40 latest AI Sec News · built Jun 13, 2026
Vulnerability // 2026-03-21

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

A critical vulnerability in Langflow, identified as CVE-2026-33017, has been disclosed and is reportedly being exploited within hours of its announcement. This incident highlights the urgent need for timely patching and awareness in the AI/ML security landscape.

The Hacker News open_link()
Vulnerability // 2026-03-21

Three high-risk AI vulnerabilities discovered in Claude.ai - end-to-end attack chain exfiltrates sensitive info without user knowing

Researchers have identified three critical vulnerabilities in Claude.ai that could facilitate an end-to-end attack chain. These vulnerabilities allow sensitive information to be exfiltrated without the user's awareness, posing serious privacy and security risks.

techradar.com open_link()
Tool // 2026-03-21

How Ceros Gives Security Teams Visibility and Control in Claude Code

The article discusses how Ceros enhances security teams' capabilities by providing visibility and control over Claude code. This is particularly relevant as organizations increasingly rely on AI systems, necessitating robust security measures to protect against potential vulnerabilities.

The Hacker News open_link()
Policy // 2026-03-19

NIST Trustworthy and Responsible AI

NIST has published guidelines focused on building trustworthy and responsible AI systems. This document outlines best practices and standards essential for ethical AI development.

nvlpubs.nist.gov open_link()
Threat Actor // 2026-03-19

ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

The article discusses various security threats including ransomware-as-a-service targeting FortiGate devices and exploits affecting Citrix products. It highlights the importance of staying informed about these vulnerabilities and the evolving tactics used by threat actors in the cybersecurity landscape.

The Hacker News open_link()
Research // 2026-03-19

Protecting Context and Prompts: Deterministic Security for Non-Deterministic AI

This paper discusses the challenges of ensuring deterministic security in non-deterministic AI systems. It explores novel methods to protect context and prompts that are critical to the AI’s performance.

arxiv.org open_link()
Policy // 2026-03-19

Be intentional about how AI changes your codebase

The article encourages developers to be proactive in guiding AI's impact on their codebases, ensuring that changes are beneficial rather than detrimental. It emphasizes the importance of deliberate design decisions in AI integration.

news.ycombinator.com open_link()
Vulnerability // 2026-03-18

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

Recent vulnerabilities discovered in Amazon Bedrock, LangSmith, and SGLang pose significant risks, allowing for potential data exfiltration and remote code execution. These flaws highlight the urgent need for enhanced security measures in AI platforms to protect sensitive data.

The Hacker News open_link()
Policy // 2026-03-17

A2AS framework targets prompt injection and agentic AI security risks

The A2AS framework is designed to protect AI agents at runtime and prevent real-world incidents like fraud, data theft, and malware spread. It addresses unique vulnerabilities associated with agentic AI systems.

Help Net Security open_link()
Research // 2026-03-17

Top 14 AI Security Risks in 2026 - SentinelOne

The article outlines effective LLM security measures that address vulnerabilities across different phases of development and operational use. Understanding these risks is essential for maintaining secure AI deployments.

sentinelone.com open_link()
Policy // 2026-03-17

Building an AI Agent Security Framework for Enterprise-Scale AI

Traditional security tools cannot address the specific vulnerabilities of agentic AI systems, leaving enterprises exposed to novel threats. The article discusses the need for a new security framework tailored to these challenges.

obsidiansecurity.com open_link()
Policy // 2026-03-17

Reducing AI Risk Across Modern AI Applications

The article discusses strategies for mitigating risks associated with the deployment of AI applications. It highlights the importance of security measures to protect against vulnerabilities that could be exploited by malicious actors.

Wiz Blog open_link()