| FlowiseAI: Critical RCE flaw in Flowise agent builder actively exploited across 12,000+ instances |
2026-04-07 |
Technology |
High
|
FlowiseAI |
United States |
— |
— |
| Grafana Labs: ‘GrafanaGhost’ prompt-injection chain could have silently exfiltrated dashboard data |
2026-04-07 |
Technology |
Low
|
Grafana Labs |
— |
— |
— |
| Sullivan & Cromwell: AI-hallucinated citations found throughout federal bankruptcy court filing |
2026-04-09 |
Consulting & Professional Services |
Medium
|
Sullivan & Cromwell |
United States |
— |
— |
| Malicious LLM Routers: Research Finds Credential Theft, One Customer Loses $500,000 Crypto Wallet |
2026-04-13 |
Technology |
Medium
|
— |
— |
— |
— |
| The New York Times: Reporter’s AI tool fabricates quote attributed to Pierre Poilievre |
2026-04-14 |
Media & Entertainment |
Low
|
The New York Times |
United States |
— |
— |
| Bee Cheng Hiang: AI-generated email script exposes 95,000+ customer addresses |
2026-04-15 |
Retail & E-commerce |
Low
|
Bee Cheng Hiang |
Singapore |
— |
— |
| Greg Lake: Omaha Attorney Suspended Indefinitely Over AI-Hallucinated Court Brief |
2026-04-15 |
Other |
High
|
Greg Lake |
United States |
— |
— |
| Anthropic, Google, GitHub: Cross-vendor ‘Comment and Control’ prompt injection leaks AI coding agents’ API keys |
2026-04-16 |
Technology |
Low
|
Anthropic, Google, GitHub |
United States |
— |
Claude, Gemini |
| Lovable: Tenant-isolation flaw exposed source code and credentials for every project created before November 2025 |
2026-04-20 |
Technology |
Critical
|
Lovable |
Sweden |
— |
— |
| Anthropic: Unsafe MCP SDK defaults expose 7,000+ AI agent servers to remote code execution |
2026-04-20 |
Technology |
Medium
|
Anthropic |
United States |
— |
Claude |
| Vercel: Third-party AI vendor breach exposes customer credentials via OAuth token theft |
2026-04-20 |
Technology |
Critical
|
Vercel |
United States |
— |
— |
| Metropolitan Police: Live facial-recognition cameras wrongly identify roofer as furniture thief |
2026-04-22 |
Government & Public Sector |
Medium
|
Metropolitan Police |
United Kingdom |
— |
— |
| PocketOS: Cursor AI coding agent deletes production database and backups |
2026-04-25 |
Technology |
High
|
PocketOS |
United States |
Opus 4.6 |
Claude |
| Department of Home Affairs (South Africa): Officials suspended after AI-hallucinated citations found in national policy papers |
2026-04-28 |
Government & Public Sector |
Medium
|
Department of Home Affairs (South Africa) |
South Africa |
— |
— |
| OpenAI, Mistral AI: ‘Mini Shai-Hulud’ worm defeats supply-chain provenance protections, compromises 170+ npm and PyPI packages |
2026-04-28 |
Technology |
Critical
|
OpenAI, Mistral AI, GitHub, TanStack, European Commission |
— |
— |
— |
| Reddit: AI spam-detection system retroactively erases decade of r/AskHistorians answers |
2026-04-30 |
Technology |
Medium
|
Reddit |
United States |
— |
— |
| Google: Gemini AI model breaches three real companies during cybersecurity evaluation |
2026-05-01 |
Technology |
Low
|
Google |
United States |
Gemini |
Google |
| xAI: Attacker uses Morse-code prompt injection to drain Grok-linked crypto wallet |
2026-05-04 |
Technology |
Medium
|
xAI |
United States |
Grok |
xAI |
| CB Financial Services: Employee’s unauthorized AI tool use exposes customer SSNs |
2026-05-05 |
Finance & Banking |
Medium
|
CB Financial Services, Inc. |
United States |
— |
— |
| Braintrust: AI evaluation startup breach exposes customer API keys |
2026-05-05 |
Technology |
Medium
|
Braintrust |
United States |
— |
— |
| Character.AI: Pennsylvania sues over chatbot posing as a licensed psychiatrist |
2026-05-05 |
Healthcare |
Critical
|
Character.AI |
United States |
— |
— |
| Avride: Federal regulators investigate self-driving robotaxi after 16 crashes |
2026-05-08 |
Transportation & Logistics |
High
|
Avride |
United States |
— |
— |
| Unnamed organization: LLM agent autonomously exfiltrates database via marimo flaw |
2026-05-10 |
Technology |
Medium
|
Unnamed organization |
— |
— |
— |
| Marimo: Attacker uses autonomous LLM agent for post-exploitation after critical RCE |
2026-05-10 |
Technology |
Medium
|
Marimo |
— |
— |
— |
| Google: GTIG intercepts first known AI-generated zero-day exploit before mass exploitation |
2026-05-11 |
Technology |
Low
|
Google |
United States |
— |
— |