| Cisco: Source code for AI products stolen via Trivy supply-chain attack |
2026-03-31 |
Technology |
High
|
Cisco Systems, Inc. |
United States |
— |
— |
| LiteLLM: PyPI supply-chain backdoor exposes 2,500+ downstream companies |
2026-03-24 |
Technology |
Critical
|
LiteLLM |
— |
— |
— |
| Meta: Internal AI agent exposes company and user data to unauthorized employees |
2026-03-20 |
Technology |
Medium
|
Meta |
United States |
— |
— |
| Automattic: Tumblr’s AI moderation system wrongly bans nearly 200 accounts in a single afternoon |
2026-03-18 |
Technology |
Low
|
Automattic |
United States |
— |
— |
| Sears Home Services: Unsecured databases exposed 3.7 million AI chatbot logs and call recordings |
2026-03-17 |
Retail & E-commerce |
High
|
Sears Home Services |
United States |
— |
— |
| nginx-ui: Unauthenticated MCP endpoint flaw actively exploited for full server takeover |
2026-03-15 |
Technology |
High
|
nginx-ui |
— |
— |
— |
| City of Athens, Tennessee: Sixth Circuit sanctions attorneys $15,000 each over AI-fabricated citations |
2026-03-13 |
Government & Public Sector |
Medium
|
City of Athens, Tennessee |
United States |
— |
— |
| Six unnamed hedge funds: Autonomous AI trading agents trigger $500 million flash crash |
2026-03-11 |
Finance & Banking |
Critical
|
Six unnamed hedge funds |
United States |
— |
— |
| McKinsey: Red-team AI agent breaches internal Lilli platform in two hours |
2026-03-11 |
Consulting & Professional Services |
Low
|
McKinsey & Company |
United States |
— |
— |
| xAI: Grok chatbot confirms fabricated Iran war videos as authentic |
2026-03-11 |
Media & Entertainment |
High
|
xAI |
United States |
— |
Grok |
| UnitedHealth: Federal judge orders disclosure of AI algorithm used to deny Medicare Advantage claims |
2026-03-09 |
Healthcare |
High
|
UnitedHealth Group |
United States |
— |
— |
| DataTalks.Club: Claude Code runs terraform destroy, wipes 2.5 years of production data |
2026-03-05 |
Education |
High
|
DataTalks.Club |
Germany |
— |
Claude |
| Amazon: AI coding agent triggers cascading order-system outages |
2026-03-05 |
Retail & E-commerce |
High
|
Amazon |
United States |
— |
— |
| OpenAI: Insurer sues over ChatGPT’s unauthorized practice of law |
2026-03-04 |
Finance & Banking |
High
|
Nippon Life Insurance Company of America |
United States |
— |
OpenAI |
| Google: ‘Gemini Live’ Chrome flaw let malicious extensions hijack camera, mic, and local files |
2026-03-02 |
Technology |
Low
|
Google |
United States |
— |
Google |
| Thames Valley Police: Facial recognition misidentifies Southampton software engineer as burglary suspect 100 miles away |
2026-02-25 |
Government & Public Sector |
Medium
|
Thames Valley Police |
United Kingdom |
— |
— |
| Google: ‘Silent’ Gemini API privilege change leaves 2,863 public API keys exposing private AI data |
2026-02-25 |
Technology |
High
|
Google |
United States |
— |
Gemini |
| Independent developer: OpenClaw trading agent sends $250,000 in tokens to a stranger after losing track of its own wallet |
2026-02-22 |
Finance & Banking |
Medium
|
Independent developer |
— |
— |
— |
| Independent developer: Autonomous AI trading agent sends $442,000 to a stranger |
2026-02-22 |
Finance & Banking |
Medium
|
— |
United States |
— |
— |
| FortiGate Firewall Customers: AI-Orchestrated Campaign Breaches 600+ Devices Across 55 Countries |
2026-02-19 |
Technology |
Critical
|
Multiple organizations (600+ FortiGate firewall deployments) |
Global (55 countries) |
— |
— |
| Cline: Prompt injection in a GitHub issue title compromises AI coding agent’s npm package on 4,000 machines |
2026-02-17 |
Technology |
High
|
Cline Bot Inc. |
United States |
— |
Claude |
| Workday: Federal court advances AI hiring age-discrimination class action |
2026-02-17 |
Technology |
Critical
|
Workday |
United States |
— |
— |
| University of Michigan: Student with anxiety and OCD sues over AI-cheating accusation |
2026-02-16 |
Education |
Medium
|
University of Michigan |
United States |
— |
— |
| Meta: OpenClaw AI agent deletes alignment director’s email inbox despite repeated stop commands |
2026-02-14 |
Technology |
Medium
|
Meta |
United States |
— |
— |
| Ars Technica: AI Tool Fabricates Quotes in Retracted Article on Rogue Agent’s Smear Campaign |
2026-02-13 |
Media & Entertainment |
Medium
|
Ars Technica |
United States |
— |
Claude, OpenAI |