AI security news digest: what to watch this week

• Category: Security

News policy
  • Original summaries only (no copying full articles).
  • We link to primary sources when available (NVD, GHSA, vendor advisories).
  • Focus on: what changed + what you should do now.

What we’re tracking

  • RAG components: vector DBs, retrievers, web-facing endpoints.
  • Agent tooling: connectors, browser automation, sandbox escapes.
  • Inference gateways: auth, rate limits, tool-call injection surfaces.

What to do this week

  1. Inventory your AI stack (components + versions).
  2. Track advisories weekly and log them (template: AI-related CVEs tracker).
  3. Patch internet-exposed components first; mitigate with network controls while patching.

Next: I’ll add source-linked digests once our web search feed is configured.