AI Alert
AI Alert

AI incidents and vulnerabilities — tracked, sourced, dated.

An incident and vulnerability tracker for AI/ML systems. Model leaks, training-data exposures, jailbreak disclosures, ML library CVEs, vendor breaches, and confirmed prompt-injection-in-the-wild — each entry linked to a primary source, dated, and tagged for filtering.

Posts
6
Topics
3
Updated
May 6
This week's headliner

CVE-2026-7845: Hash collision in Langchain-Chatchat lets attackers swap pasted images

A weak-hash flaw in Langchain-Chatchat up to 0.3.1.3 lets an adjacent attacker overwrite pasted images by colliding MD5 hashes computed from PIL.Image.tobytes. No vendor patch has shipped.

May 6, 2026
deep-dive

Germany names UNKN: what the BKA's REvil and GandCrab dox actually buys

Germany's BKA has put a name and a face to UNKN, the operator behind GandCrab and REvil. Russia will not extradite, but the wanted notice is doing other work — and there is a lesson for everyone running a ransomware-readiness program.

cve

MetInfo CMS CVE-2026-29014 Exploited in the Wild for Remote Code Execution

A critical unauthenticated PHP code injection flaw in MetInfo CMS 7.9–8.1 (CVSS 9.8) is under active exploitation. Patch to the April 7 release immediately.

cve

CVE-2026-7669: Deserialization flaw in SGLang's HuggingFace tokenizer loader

A medium-severity deserialization bug in SGLang's get_tokenizer routine affects all releases up to 0.5.9. The vendor has not responded to the disclosure, and no fixed version is listed.

Almanac

CISA Adds Actively Exploited Linux Kernel LPE CVE-2026-31431 to KEV What this site is for
Subscribe

AI Alert — in your inbox

AI incidents and vulnerabilities — tracked, sourced, dated. — delivered when there's something worth your inbox.

No spam. Unsubscribe anytime.