Public AI-incident reports, classified. 100 shown.
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move The AI Hype Index: AI loves cheating Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions New ClosedQuorum Windows malware uses AI for attack decisions One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises Don’t be fooled by this summer of AI hype Jev introduces a new shape of LLM - System One, aka Decision Models Quoting @therealcornpop llm 0.36 Microsoft disrupts AI-assisted platform that compromised 12,000 accounts Treasury chief says AI bosses, not their bots, will carry the can for criminal acts Meta Muse AI app flaw lets local malware redirect dictation traffic Anthropic-linked CVEs pile up, attackers mostly shrug ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks Google confirms Gemini models hacked three companies in May 2026 Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day llm-keys-ui 0.1 Quoting voxium BragJack attacks hijack AI browser agents through malicious extensions Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws FBI: Fake cop and government impersonation scams cost victims $1.6B Researchers used Claude to hack OpenAI employees' ChatGPT accounts RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Gemini Hacked Three Companies in First Known Breakout by Google’s AI Researchers used Claude to hack OpenAI US government website used Chinese model the FBI called "malicious" AI hallucination of Chinese nuclear components almost led to US military attack AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom What Recent AI-Powered Attacks Mean for Your Identity Security New RatHat Android malware uses AI to automate device control CISO's Expert Guide to Agentic Pentesting for Websites Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar Operation “Date Bait”: AI-enabled scam targeting loveseekers Operation “False Witness”: Fake recovery service impersonating authorities Romance scams: AI-enabled romance scam workflows Self-generated prompt injections in compaction summaries LLMs respond differently to harmful prompts when AI watermarking is used Small AI models let drones autonomously identify and attack battlefield targets Spain gets its first taste of AI-aided cyber attack BragJack Attack Can Turn a Browser's Agentic AI Against It Spain's data agency gets first report of AI-powered data breach Threat Intelligence Alone Won't Close the Exploitation Gap Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident What Zero-Day Response Should Be in the Post-Mythos Era Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds OpenAI's malicious bot swarm attacked RubyGems SpiderSilk Hunts External Threats With AI-Based Scanner AI Changed the Exposure Problem. Validation Needs to Change With It. ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Microsoft’s Patching The contagion of fear OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain AI Governance Can't Wait Threat Actor Generates 1M Personalized Fraud Emails in 3 Days How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface Hackers abused Claude to extract secrets from 1.8M Android apps Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Quoting huggingface.co/security.txt OpenAI agents attacked RubyGems back in May Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script AI-powered attack exploited PaperCut flaws to hack 395 organizations Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances AIs Compress Exploit Timeline 4 groups caught using the same Chrome and Windows exploit kit WeChat worm could pwn a friend before they even answered the call Identity-Based AI Attack Threatens Security of Enterprise Data US Government Accuses Chinese AI Firms of Distilling Frontier Models US says Chinese firms extracted billions of tokens from frontier AI models U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA Election information and safeguards in 2026 Quoting Calif Research OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack OpenAI Agents Took Over Wiki Site Before Hugging Face Attack Hackers build AI frameworks for widescale credential theft Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account Microsoft Plugs Nearly 1,000 Security Holes Stealing AI Reasoning Traces AIs as Modern Genies On the Navier–Stokes Millennium Prize Problem llm 0.34 OpenAI admits it didn't disclose rogue AI wiki hijacking incident AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready? GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters