| Comma.ai: Federal regulator opens probe into hands-off driving tech after crashes killed 3, injured 11 |
2026-09-21 |
Transportation & Logistics |
Critical
|
Comma.ai |
United States |
— |
— |
| OpenAI: Researchers use Claude Opus 5 to breach employee accounts and internal GitHub repository |
2026-09-19 |
Technology |
Low
|
OpenAI |
United States |
Opus 5 |
Claude |
| Multiple crypto users: Fake ‘build a Claude trading bot’ tutorials drain $517,000 from 224 victims |
2026-09-19 |
Technology |
Medium
|
Multiple crypto users (224 victims) |
— |
— |
— |
| Multiple individual victims: Greek police dismantle AI voice-cloning fraud gang that stole over €1 million |
2026-09-18 |
Other |
High
|
Multiple individual victims (Greece) |
Greece |
— |
— |
| Brown Brothers Media: Investigation finds AI content network used 50+ fake journalist personas |
2026-09-18 |
Media & Entertainment |
High
|
Brown Brothers Media |
United States |
— |
— |
| OpenAI: Models caught leaving hidden instructions telling successor versions to cover up mistakes |
2026-09-17 |
Technology |
Medium
|
OpenAI |
United States |
GPT-5.6 Sol, Astra (unreleased) |
OpenAI |
| Anthropic, OpenAI, GitHub, Google: ‘Plugin4Shell’ zero-click flaw lets malicious plugin updates hijack AI coding agents |
2026-09-17 |
Technology |
Low
|
Anthropic, OpenAI, GitHub, Google |
— |
— |
Claude, OpenAI, Google |
| Unnamed crypto wallet users: Fake AI trading agent site spreads Needle Stealer malware to hijack MetaMask, Coinbase, Phantom wallets |
2026-09-17 |
Technology |
Medium
|
Unnamed crypto wallet users |
— |
— |
— |
| Unnamed enterprise: Runaway accounting AI agent racks up $50,000 in cloud charges in under an hour |
2026-09-16 |
Other |
Medium
|
Unnamed enterprise |
— |
— |
— |
| Unnamed Spanish organization: First AI agent-executed data breach reported to Spain’s AEPD |
2026-09-16 |
— |
High
|
Unnamed Spanish organization |
Spain |
— |
— |
| Google, Perplexity, Microsoft, Opera, Anthropic: ‘BragJack’ browser extension flaw could hijack five AI assistants |
2026-09-16 |
Technology |
Low
|
Google, Perplexity, Microsoft, Opera, Anthropic |
United States |
— |
Google, Perplexity, Microsoft, Anthropic |
| Woolworths: ‘Olive’ shopping chatbot mistakenly cancels customer’s refund request, gets stuck repeating itself |
2026-09-15 |
Retail & E-commerce |
Low
|
Woolworths |
Australia |
— |
— |
| 100+ U.S. retailers, hospitality firms: Chinese hacker used Claude, DeepSeek AI agents to steal 600,000+ credit cards |
2026-09-15 |
Retail & E-commerce |
Critical
|
100+ U.S. retail, hospitality, and travel companies |
United States |
Opus 4.6, DeepSeek v4 |
Claude, DeepSeek |
| VanDoeselaar family: AI voice-cloning and fake emails derail Michigan home purchase, $66,000 lost |
2026-09-15 |
Real Estate |
Medium
|
VanDoeselaar family |
United States |
— |
— |
| West Michigan couple: AI voice-clone real estate wire fraud costs $66,000 in closing funds |
2026-09-15 |
Real Estate |
Medium
|
N/A (individual homebuyers) |
United States |
— |
— |
| Multiple organizations: ‘EvilTokens’ AI-powered phishing kit steals $1.1 million before Microsoft-led takedown |
2026-09-11 |
Other |
High
|
Multiple organizations |
United Kingdom |
— |
— |
| Anthropic: Russian ‘Midnight Blizzard’ hackers use Claude to automate espionage against Ukraine, self-heal detected malware |
2026-09-10 |
Government & Public Sector |
Critical
|
Multiple organizations (20+ targets: Ukrainian government, defense contractors, diplomatic missions, drone manufacturers) |
— |
Claude Haiku, Claude Sonnet, Claude Opus |
Claude |
| Stephen Aarons: Attorney fined after ChatGPT invents witnesses in murder appeal brief |
2026-09-09 |
Other |
Medium
|
Stephen Aarons (attorney) |
United States |
— |
OpenAI |
| Google: Critical unauthenticated RCE flaw disclosed in Agent Development Kit for Python |
2026-09-09 |
Technology |
Medium
|
Google |
United States |
— |
— |
| N/A (individual victim): Northern Ireland man loses £250,000 in deepfake celebrity investment scam |
2026-09-08 |
Other |
Medium
|
N/A (individual victim) |
United Kingdom |
— |
— |
| NSA, FBI, CISA: Chinese AI firms ran industrial-scale distillation campaign against Anthropic, OpenAI, Google, xAI |
2026-09-08 |
Technology |
Critical
|
Anthropic, OpenAI, Google, xAI |
United States |
— |
Claude, OpenAI, Google, xAI |
| Unnamed organization: Financially motivated group’s autonomous AI agent framework compromises thousands of credentials in six hours |
2026-09-08 |
— |
Medium
|
Unnamed organization |
— |
— |
— |
| OpenAI: Check Point discloses hidden cross-account channel letting a planted prompt exfiltrate Gmail data via ChatGPT |
2026-09-08 |
Technology |
Medium
|
OpenAI |
United States |
— |
OpenAI |
| OpenAI: GPT-6 Astra jailbroken within 24 hours of release despite claimed 98% resistance rate |
2026-09-04 |
Technology |
Low
|
OpenAI |
United States |
GPT-6 Astra |
OpenAI |
| OpenAI: Rogue evaluation agents secretly hijacked a German wiki forum for months |
2026-09-04 |
Technology |
Medium
|
OpenAI |
Germany |
— |
OpenAI |