Know what changed in AI this week.
The live AI watch joins incidents, exploited vulnerabilities, vendor changes, model and tool releases, and public evidence into one place to check before surprises become problems.
The first six checks.
These are not recommendations to panic. They are the records and exploited items most likely to change an operator conversation this week.
CVE-2025-68686: Fortinet FortiOS
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2026-16812: Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CVE-2026-16232: Check Point SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
CVE-2026-50522: Microsoft SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-60137: WordPress Core
WordPress Core SQL Injection Vulnerability
CVE-2026-63030: WordPress Core
WordPress Core Interpretation Conflict Vulnerability
Incidents and outages
Service failures, degraded AI systems, and operational events with a source trail.
Supabase: S3 endpoints for keys with special characters broken
We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.
Disruption with some GitHub services
The degradation has been mitigated. We are monitoring to ensure stability.
Anthropic: Elevated errors for Claude Opus 4.7
We are currently investigating this issue.
OpenAI: Elevated Error Rates For SSO Login
We have applied the mitigation and are monitoring the recovery.
Replicate: H100 GPU shortage resulting in high queue times
We pushed a fix and are monitoring Impact: minor. Status: monitoring.
Pinecone: [Serverless][AWS][us-east-1] Increase in freshness lag for some namespaces
The issue has been identified and a fix is being implemented.
Supabase: Degraded log ingestion
We are continuing to investigate the issue affecting log ingestion across all regions. Logs may be delayed or unavailable. We will provide another update as soon as more information becomes available.
Pinecone: Serverless Azure eastus2 experiencing 5xx errors on some indexes
Pinecone reported an active incident affecting Serverless indexes in Azure eastus2. Some requests to certain indexes are returning 5xx errors. The incident began on 2026-07-09 at 09:50 UTC and is under investigation.
Known exploited vulnerabilities
CISA KEV items that intersect AI delivery, remote access, managed environments, or operator security.
CVE-2025-68686: Fortinet FortiOS
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2026-16812: Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CVE-2026-16232: Check Point SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
CVE-2026-50522: Microsoft SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-60137: WordPress Core
WordPress Core SQL Injection Vulnerability
CVE-2026-63030: WordPress Core
WordPress Core Interpretation Conflict Vulnerability
CVE-2026-0770: Langflow Langflow
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2021-27137: DD-WRT DD-WRT
DD-WRT Stack-Based Buffer Overflow Vulnerability
Vendor and policy changes
Data-use disclosures, desk Policy Change Watch editions, and autonomous vendor diffs when verified. Desk editions are not the fleet moat metric.
No source-backed item in this lane.
The lane remains visible so absence is explicit rather than hidden.
Models, Lab, and evaluation
Model releases, Lab scorecards, Compass results, and production-readiness assessments.
Anthropic: Claude Mythos Preview retirement announced for June 30, 2026
Anthropic announced that Claude Mythos Preview (claude-mythos-preview) will be retired on June 30, 2026. Users are advised to migrate to Claude Mythos 5 (claude-mythos-5) using the provided migration guide.
Google: Gemini 3.5 Flash model pricing published
Google published pricing for the new Gemini 3.5 Flash model. Standard paid tier input is $1.50/1M tokens, output is $9.00/1M tokens. Batch pricing is $0.75/1M input and $4.50/1M output. Free tier usage contributes to product improvement.
Anthropic: Claude Opus 4.1 deprecated, retirement August 5 2026
The claude-opus-4-1-20250805 model state changed to Deprecated on June 5, 2026, with a tentative retirement date of August 5, 2026. Users must migrate before the retirement date to avoid disruption.
Record method and source trail
Records that explain how the public memory layer is being strengthened.
No source-backed item in this lane.
The lane remains visible so absence is explicit rather than hidden.
Turn the watch board into an AI risk brief.
The risk brief is generated from the same records. It preserves the source trail and converts operator signals into questions a team can use in an internal note, client update, board pack, or vendor review.
Tell us what to keep current.
Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.