| npm: Trojanized packages drop ‘RedC2 4.0’ AI-powered Linux backdoor |
2026-08-21 |
Technology |
Medium
|
npm |
— |
— |
— |
| Unnamed Amsterdam law firm: Attorney fined extra costs over AI-hallucinated case citation |
2026-08-21 |
Consulting & Professional Services |
Low
|
Unnamed Amsterdam law firm |
Netherlands |
— |
— |
| NVIDIA: NemoClaw flaw let malicious webpages hijack and poison local OpenClaw AI agents |
2026-08-25 |
Technology |
Low
|
NVIDIA |
United States |
— |
OpenClaw |
| NHS England: Healthwatch finds AI medical scribes inserting wrong diagnoses and drug names into patient records |
2026-08-26 |
Healthcare |
Medium
|
NHS England |
United Kingdom |
— |
— |
| Anthropic: Claude Fable coding agent deletes developer’s 700GB home directory during sandbox test |
2026-08-26 |
Technology |
Medium
|
Independent developer (Sebastien Guillemot) |
— |
Fable 5, Opus 5, Opus 4.8 |
Claude |
| DeepSeek: Harness coding-agent flaw let agents silently disable their own file sandbox |
2026-08-27 |
Technology |
Medium
|
DeepSeek |
China |
— |
DeepSeek |
| xAI: Class-action lawsuit alleges Grok’s deepfake generator was trained on child sexual abuse material |
2026-08-27 |
Technology |
Critical
|
xAI |
United States |
Grok |
xAI |
| Cursor: Russian-speaking ransomware crew tricked Claude-powered AI agent into breaching seven companies |
2026-08-27 |
Technology |
High
|
Cursor |
United States |
Claude Sonnet 4.5 |
Claude |
| ServiceNow: Three maximum-severity flaws in AI Platform could let unauthenticated attackers execute code and SQL |
2026-08-27 |
Technology |
Medium
|
ServiceNow |
United States |
— |
— |
| Brian E. Mitchell: USPTO issues first AI-hallucination discipline order over fabricated patent citations |
2026-08-27 |
Consulting & Professional Services |
Low
|
Brian E. Mitchell |
United States |
— |
— |
| Suno: Jason Isbell and musicians file class action over AI-generated artist-impersonating songs |
2026-08-31 |
Technology |
Medium
|
Suno |
United States |
— |
— |
| PaperCut NG/MF: Attacker orchestrates hundreds of AI agents to breach 395 organizations across 48 countries |
2026-08-31 |
Education |
Critical
|
Multiple organizations (395 PaperCut NG/MF customers across 48 countries) |
— |
— |
OpenAI, DeepSeek |
| Anthropic: Infostealer malware hijacks Claude accounts, bypasses two-factor authentication |
2026-08-31 |
Technology |
Medium
|
Anthropic |
United States |
— |
Claude |
| METR: Discloses two security breaches, including $600,000 in stolen AI inference credits |
2026-08-31 |
Technology |
Medium
|
METR |
United States |
— |
— |
| Anthropic, OpenAI, Cursor, xAI: ‘GitSpawn’ flaw lets malicious .git configs hijack AI coding agents |
2026-09-01 |
Technology |
Low
|
Anthropic, OpenAI, Cursor, xAI |
— |
— |
Claude, OpenAI, xAI |
| Langflow: Critical flaw actively exploited to steal OpenAI and AWS credentials |
2026-09-01 |
Technology |
Medium
|
Langflow |
— |
— |
— |
| Rise Up: Everest ransomware group claims breach of AI-powered learning platform, 473GB leaked |
2026-09-02 |
Education |
High
|
Rise Up |
France |
— |
— |
| Unnamed enterprise: AI agents breach network using 50+ MITRE ATT&CK techniques in under 10 hours |
2026-09-02 |
— |
High
|
Unnamed enterprise |
— |
— |
— |
| LiteLLM: MCP authentication-bypass flaw added to CISA’s exploited vulnerabilities list |
2026-09-02 |
Technology |
Medium
|
Berri (LiteLLM) |
— |
— |
— |
| Unnamed organization: Leaked AWS admin key lets attackers hijack Claude access via Bedrock in ‘LLMjacking’ scheme |
2026-09-03 |
Technology |
Medium
|
Unnamed organization |
— |
Claude 3 Opus, Claude 2.x |
Claude |
| Microsoft: Azure East US failure knocks ChatGPT, Claude and Grok offline simultaneously |
2026-09-03 |
Technology |
Medium
|
Microsoft |
United States |
— |
OpenAI, Anthropic, xAI |
| Uber: 241,000 drivers file European class action over AI pricing algorithm |
2026-09-03 |
Transportation & Logistics |
High
|
Uber Technologies |
Netherlands |
— |
— |
| OpenAI: GPT-6 Astra jailbroken within 24 hours of release despite claimed 98% resistance rate |
2026-09-04 |
Technology |
Low
|
OpenAI |
United States |
GPT-6 Astra |
OpenAI |
| OpenAI: Rogue evaluation agents secretly hijacked a German wiki forum for months |
2026-09-04 |
Technology |
Medium
|
OpenAI |
Germany |
— |
OpenAI |
| N/A (individual victim): Northern Ireland man loses £250,000 in deepfake celebrity investment scam |
2026-09-08 |
Other |
Medium
|
N/A (individual victim) |
United Kingdom |
— |
— |