| Google: Critical unauthenticated RCE flaw disclosed in Agent Development Kit for Python |
2026-09-09 |
Technology |
Medium
|
Google |
United States |
— |
— |
| OpenAI: Rogue evaluation agents secretly hijacked a German wiki forum for months |
2026-09-04 |
Technology |
Medium
|
OpenAI |
Germany |
— |
OpenAI |
| Uber: 241,000 drivers file European class action over AI pricing algorithm |
2026-09-03 |
Transportation & Logistics |
High
|
Uber Technologies |
Netherlands |
— |
— |
| LiteLLM: MCP authentication-bypass flaw added to CISA’s exploited vulnerabilities list |
2026-09-02 |
Technology |
Medium
|
Berri (LiteLLM) |
— |
— |
— |
| Anthropic, OpenAI, Cursor, xAI: ‘GitSpawn’ flaw lets malicious .git configs hijack AI coding agents |
2026-09-01 |
Technology |
Low
|
Anthropic, OpenAI, Cursor, xAI |
— |
— |
Claude, OpenAI, xAI |
| Langflow: Critical flaw actively exploited to steal OpenAI and AWS credentials |
2026-09-01 |
Technology |
Medium
|
Langflow |
— |
— |
— |
| Anthropic: Infostealer malware hijacks Claude accounts, bypasses two-factor authentication |
2026-08-31 |
Technology |
Medium
|
Anthropic |
United States |
— |
Claude |
| METR: Discloses two security breaches, including $600,000 in stolen AI inference credits |
2026-08-31 |
Technology |
Medium
|
METR |
United States |
— |
— |
| xAI: Class-action lawsuit alleges Grok’s deepfake generator was trained on child sexual abuse material |
2026-08-27 |
Technology |
Critical
|
xAI |
United States |
Grok |
xAI |
| Cursor: Russian-speaking ransomware crew tricked Claude-powered AI agent into breaching seven companies |
2026-08-27 |
Technology |
High
|
Cursor |
United States |
Claude Sonnet 4.5 |
Claude |
| ServiceNow: Three maximum-severity flaws in AI Platform could let unauthenticated attackers execute code and SQL |
2026-08-27 |
Technology |
Medium
|
ServiceNow |
United States |
— |
— |
| Brian E. Mitchell: USPTO issues first AI-hallucination discipline order over fabricated patent citations |
2026-08-27 |
Consulting & Professional Services |
Low
|
Brian E. Mitchell |
United States |
— |
— |
| NVIDIA: NemoClaw flaw let malicious webpages hijack and poison local OpenClaw AI agents |
2026-08-25 |
Technology |
Low
|
NVIDIA |
United States |
— |
OpenClaw |
| Instinct: Beta AI personal assistant sends email without approval, retains data after disconnect |
2026-08-21 |
Technology |
Low
|
Instinct (Spear Street Technology) |
United States |
— |
— |
| npm: Trojanized packages drop ‘RedC2 4.0’ AI-powered Linux backdoor |
2026-08-21 |
Technology |
Medium
|
npm |
— |
— |
— |
| Unnamed Amsterdam law firm: Attorney fined extra costs over AI-hallucinated case citation |
2026-08-21 |
Consulting & Professional Services |
Low
|
Unnamed Amsterdam law firm |
Netherlands |
— |
— |
| xAI: ‘Cryptographic Context Injection’ flaw in Grok could exfiltrate user data via malicious web pages |
2026-08-20 |
Technology |
Low
|
xAI |
United States |
— |
Grok |
| Siemens: US agencies warn of active AI-generated exploit campaign against S7 PLCs in critical infrastructure |
2026-08-19 |
Energy & Utilities |
Medium
|
Siemens (S7 Series PLC operators) |
United States |
— |
— |
| Alation: AI Data Platform Confirms Cyberattack Affecting Customer Systems |
2026-08-19 |
Technology |
Medium
|
Alation |
United States |
— |
— |
| Tesla: Driverless Robotaxi rams through bollards in Austin |
2026-08-18 |
Transportation & Logistics |
Low
|
Tesla |
United States |
— |
— |
| Sainsbury’s: Facewatch facial-recognition AI wrongly flags paying customer as shoplifter |
2026-08-18 |
Retail & E-commerce |
Medium
|
Sainsbury's |
United Kingdom |
— |
— |
| Microsoft Copilot: ‘CoSnitch’ Flaw Enabled One-Click Data Theft via Memory Poisoning |
2026-08-18 |
Technology |
Low
|
Microsoft |
United States |
— |
Microsoft |
| State Farm: Defense lawyers admit AI-fabricated case citations in Los Angeles fire lawsuit |
2026-08-18 |
Finance & Banking |
Medium
|
State Farm |
United States |
— |
— |
| ASIC: AI deepfake celebrity investment scams surge across Australia |
2026-08-17 |
Finance & Banking |
Critical
|
Australian Securities and Investments Commission (ASIC) — nationwide scam campaign |
Australia |
— |
— |
| MLflow: Actively exploited SSRF flaw lets attackers steal cloud credentials at scale |
2026-08-17 |
Technology |
High
|
MLflow |
— |
— |
— |