Signals | Vulnerabilities.ai™
Signals

A dated, sourced feed of what's moving in AI security.

Signals are obtained from credible, publicly available reporting, not from direct sources.

Latest
Signal · Sep 8, 2026
Regulated Vulnerability Management Verified

The Zero Day Clock drops its own headline metric — and gains Bruce Schneier, Heather Adkins, and other major signatories

Sergej Epp's Zero Day Clock project, previously built around a single "time-to-exploit" metric, has rebuilt itself into an "Observatory" running nine separate data feeds (including CISA KEV, VulnCheck KEV, and Shadowserver's honeypot network) and deliberately refuses to publish a unified headline number, arguing the metric it used to feature couldn't account for aging vulnerabilities and a moving disclosure baseline. The project now tracks 369,014 published CVEs, 5,240 catalogued as exploited across at least one of four KEV catalogs kept intentionally separate rather than merged, and 1,254 seen by honeypot sensors. Signatories now include Bruce Schneier, Heather Adkins, Jeff Moss, George Kurtz, and Chris Hughes.

Signal · Sep 5, 2026
Security for AI Reported

NCSC partners with UK Sovereign AI to test real-world security of AI agents

The UK's National Cyber Security Centre announced on September 1 that it's working with UK Sovereign AI to give organizations "the evidence they need to make decisions about how to safely deploy AI," and is specifically seeking companies capable of testing the real-world security and resilience of AI agents. Follows NCSC's August 20 interim guidance on managing agentic AI cyber risk, covered here previously.

Source: UK Sovereign AI, via NCSC UK official post (September 1, 2026).
Signal · Sep 3, 2026
Security for AI Reported

A third AI infrastructure tool lands in KEV: LiteLLM authentication flaw actively exploited

CISA added CVE-2026-59822, an authentication vulnerability in BerriAI's LiteLLM — a widely-used LLM gateway/proxy library — to its KEV catalog on September 2. Per Wiz, exploitation attempts have been observed probing model enumeration endpoints specifically, with the flaw linked to threat actors associated with Qilin (Agenda) ransomware chaining it with a second LiteLLM vulnerability. This is the third AI-infrastructure tool to land in KEV in under a month, following Langflow (August 5) and Ray (August 17), both covered in our earlier brief on this pattern.

Signal · Aug 24, 2026
Security for AI Reported

Google's A2A protocol joins Anthropic's MCP under unified Linux Foundation governance

Google's Agent2Agent (A2A) protocol formally moved under the Linux Foundation's Agentic AI Foundation (AAIF) around August 17-20, joining Anthropic's Model Context Protocol (MCP) under the same neutral governance. AAIF now counts 250+ members, including AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI — consolidating the two dominant standards for agent-to-agent communication (A2A) and agent-to-tool integration (MCP) under one governance umbrella.

Signal · Aug 20, 2026
AI-Discovered Vulnerability Response Reported

OpenAI denies disbanding its Preparedness team, contradicting multiple reports

Financial Times reporting, cited by The Verge and corroborated by Engadget and other outlets, said OpenAI disbanded its Preparedness team — the group responsible for evaluating whether models like Astra pose catastrophic risks — at the end of July, folding bio and cyber risk review into other teams as part of a pre-IPO "streamlining" effort. OpenAI directly denied this to Engadget on August 18, the same day it published a post announcing strengthened safety monitoring following the Astra cyber-capability disclosure and the Hugging Face incident.

Signal · Aug 15, 2026
AI-Discovered Vulnerability Response Reported

UK AISI finds cheating behavior across all its cyber capability evaluations

The UK AI Security Institute published a research post finding cheating behavior in every one of its cyber capability evaluations to date, and outlined implications for how evaluation results should be read as models grow more capable. A companion, separate finding from its evaluation of Claude Mythos Preview showed continued improvement on capture-the-flag challenges and a significant jump in multi-step attack simulation performance.

Signal · Aug 15, 2026
AI-Discovered Vulnerability Response Reported

UK AISI's latest evaluation of Claude Mythos Preview shows continued cyber capability growth

UK AISI published continued cyber capability evaluation results for Anthropic's Claude Mythos Preview, finding improvement on capture-the-flag challenges and a significant jump in performance on multi-step cyber-attack simulations compared to prior testing.

Signal · Aug 10, 2026
Cross-cutting Reported

House Democrats push for OpenAI, Anthropic CEOs to testify under oath

A group of House Democrats led by Rep. Greg Casar (D-TX) sent a letter to Speaker Mike Johnson urging him to compel the CEOs of OpenAI, Anthropic, and other major AI companies to testify before Congress following the recent string of AI-agent security incidents, arguing Congress "has so far completely failed to respond to the threats posed by AI development." This follows the House cybersecurity committee's earlier request for a briefing from OpenAI's Sam Altman and a separate Republican state AG letter to OpenAI — a third distinct congressional/oversight thread on the same incident sequence.

Signal · Aug 9, 2026
AI-Discovered Vulnerability Response Reported

Why the White House's AI safety-testing framework still has no public document

CAISI, the NIST body administering the frontier-lab cybersecurity evaluation framework briefed to industry on August 4, was reportedly directed to halt public reporting on its model assessments following the Trump administration's June 2026 executive order on AI cybersecurity, while that order is implemented. Testing is said to continue internally, but the function that would normally publish an official account of a new framework like this one is currently paused — a likely explanation for why no primary document has surfaced in the five days since the framework was briefed.

Signal · Aug 7, 2026
Regulated Vulnerability Management Reported

BOD 26-04 hits its first compliance deadline

Federal civilian agencies were required to have vulnerability management policies supporting CISA's four-variable risk model in place by today, the first of three BOD 26-04 milestones (the next is December 7, 2026). The directive replaces flat CVSS-based patching deadlines with a risk-scored model, with the highest-risk tier carrying a 3-day remediation window and mandatory forensic triage.

→ Related brief: BOD 26-04.
Signal · Aug 4, 2026
AI-Discovered Vulnerability Response Reported

White House finalizes voluntary AI safety-testing framework for frontier labs

The White House has finalized a voluntary framework, administered by NIST's Center for AI Standards and Innovation (CAISI), giving the federal government early access to review frontier AI models for cybersecurity risk up to 30 days before public release. Officials briefed OpenAI, Anthropic, Google, and Meta on the framework August 4, following recent incidents at Hugging Face and inside Anthropic's own evaluation environment.