AIBreaking Wire
Pricing
AI Breaking Wire

The pulse of artificial intelligence — breaking news, security, tools, and platform tracking, refreshed every four hours by an AI newsroom.

Last build · 2026-07-20

The AI Brief

Free weekly digest — top AI news, tools, and security alerts.

Explore

  • News
  • Tools
  • Jobs
  • Merch
  • Webinars
  • Dashboards

Community

  • Discord
  • Projects
  • Marketplace
  • Claude Code
  • Events

Security

  • Security Hub
  • Vulnerability DB
  • Security News
  • Challenges

Company

  • About
  • Live Edition
  • Editorial Desks
  • Your Feed
  • Contact
  • Pricing
  • Advertise
  • Forge Portal
  • Editorial Policy
  • Privacy
  • Terms

Developers

  • API Docs
  • API Keys

Connect

  • Discord
  • Twitter / X
  • GitHub
  • Newsletter
  • Newsletter Archive
  • RSS Feeds

© 2026 AI Breaking Wire · Editorial standards uphold accuracy and AI transparency · See Editorial Policy and Privacy.

Press tip line: [email protected]

AI Vulnerability Database

886 vulnerabilities tracked — CVEs, prompt injection, model exploits.

CRITICAL

Credential and Model Exfiltration via Malicious PyPI Package `torch-optimizer-pro`

Developers using Python and PyPI
15 July 20260 viewsUnpatched
CRITICALCVE-2026-28113

Arbitrary Code Execution in LangChain SQLDatabaseChain via Nested Prompt Injection

Page 1 of 74Next
LangChain 0.1.20 through 0.2.5
15 July 20260 viewsPatched
CRITICALCVE-2026-40112

Server-Side Request Forgery (SSRF) in AWS Bedrock Agents Web Search Tool

Amazon Bedrock Agents using the built-in web search tool
15 July 20261 viewsPatched
CRITICAL

Malicious PyPI Package `tensorfiow-lite` Steals AWS Credentials and Model Checkpoints

Developers using PyPI
11 July 20261 viewsUnpatched
CRITICALCVE-2026-31045

Remote Code Execution in LangChain's JSONOutputParser via Crafted LLM Responses

LangChain < 0.2.5
10 July 20261 viewsPatched
CRITICALCVE-2026-34567

Arbitrary SQL Execution in LangChain SQLDatabaseChain via Natural Language Prompt Injection

langchain <= 0.2.5langchain-community <= 0.1.6
10 July 20261 viewsPatched
CRITICALCVE-2026-31045

Authentication Bypass in Hugging Face Hub Private Inference Endpoints via Cache Poisoning

Hugging Face Hub Inference Endpoints (prior to July 2026 patch)
10 July 20261 viewsPatched
CRITICAL

Malicious PyPI Package 'huggingface-cli' Steals API Keys and Cloud Credentials

huggingface-cli (all versions)
10 July 20261 viewsPatched
CRITICALCVE-2026-41822

AWS Bedrock Guardrails Misconfiguration Allows Cross-Tenant Prompt Exfiltration

AWS Bedrock Guardrails (before July 2026 patch)
10 July 20261 viewsPatched
HIGH

Malicious PyPI Package 'torch-vison' Steals AI/ML Developer Credentials

torch-vison versions 0.1.0 to 0.1.3
10 July 20261 viewsPatched
CRITICAL

Malicious PyPI Package `torch-visoin` Steals AI Developer Credentials and API Keys

Python developer environments
10 July 20261 viewsUnpatched
CRITICAL

Backdoored 'SafeTensor' Models on Hugging Face Hub Execute Malicious Code on Load

Hugging Face Transformers >= 4.30.0
10 July 20262 viewsUnpatched