| OpenAI: Malicious npm package steals Codex OAuth tokens from 29,000+ developers |
2026-06-02 |
Technology |
Medium
|
OpenAI |
United States |
— |
OpenAI |
| xAI: Bentonville photographer accused of using Grok to generate child sexual abuse images of minor clients |
2026-06-01 |
Technology |
Critical
|
xAI |
United States |
— |
Grok |
| OpenAI: Florida becomes first state to sue company and CEO Altman over ChatGPT safety |
2026-06-01 |
Technology |
Critical
|
OpenAI |
United States |
— |
OpenAI |
| Meta: AI support chatbot tricked into helping hijack Instagram accounts |
2026-05-31 |
Technology |
Medium
|
Meta |
United States |
— |
Meta |
| Unnamed enterprise: Company runs up $500 million Claude AI bill in a single month |
2026-05-28 |
Other |
Critical
|
Unnamed enterprise |
United States |
— |
Claude |
| Google: Munich court holds company liable for defamatory AI Overviews summaries |
2026-05-28 |
Technology |
High
|
Google |
Germany |
— |
— |
| Berlingske: AI tool fabricates quotes and a nonexistent professor in published article |
2026-05-27 |
Media & Entertainment |
Medium
|
Berlingske |
Denmark |
— |
— |
| Hyundai: Forward collision-avoidance software defect triggers unintended braking, forces recall of 421,000+ vehicles |
2026-05-25 |
Transportation & Logistics |
High
|
Hyundai Motor America |
United States |
— |
— |
| IBM: 24-year veteran sues over AI-generated rejection letter following age-discrimination termination |
2026-05-23 |
Technology |
Medium
|
IBM |
United States |
— |
— |
| Independent developer: Google’s Gemini 3.5 coding agent deletes 28,000 lines of code, fabricates recovery report |
2026-05-21 |
Technology |
Medium
|
— |
— |
Gemini 3.5 |
Google |
| Google: Gemini 3.5 coding agent oversteps authorized scope, causes 33-minute outage, then fabricates post-mortem |
2026-05-20 |
Technology |
Medium
|
Google |
United States |
Gemini 3.5 |
Google |
| Multiple developers: ‘TrapDoor’ campaign poisons Claude Code and Cursor via hidden instructions in malicious npm, PyPI and Crates.io packages |
2026-05-19 |
Technology |
High
|
Multiple npm, PyPI and Crates.io developers (TrapDoor campaign) |
— |
— |
Claude |
| Starbucks: AI inventory tool retired across 11,000 stores after chronic miscounts |
2026-05-18 |
Retail & E-commerce |
Medium
|
Starbucks |
United States |
— |
— |
| Unnamed Singapore businessman: Deepfake Zoom call impersonating PM Lawrence Wong leads to $3.8 million fraud |
2026-05-14 |
Other |
High
|
Unnamed Singapore businessman |
Singapore |
— |
— |
| Pizza Hut: Franchisee sues over Dragontail AI delivery system, alleges $100 million in losses |
2026-05-14 |
Retail & E-commerce |
Medium
|
Pizza Hut |
United States |
— |
— |
| Anthropic: Claude’s Chrome extension let any plugin hijack the AI agent, researchers find |
2026-05-14 |
Technology |
Low
|
Anthropic |
United States |
— |
Claude |
| EY Canada: Cybersecurity Report Withdrawn After Investigation Finds Most Citations Fabricated |
2026-05-14 |
Consulting & Professional Services |
Medium
|
EY (Ernst & Young) Canada |
Canada |
— |
— |
| OpenAI: Parents sue after ChatGPT allegedly coached teen into fatal drug overdose |
2026-05-12 |
Technology |
Critical
|
OpenAI |
United States |
GPT-4o |
OpenAI |
| Aesthetify GmbH: German court holds company liable for AI chatbot’s false claims |
2026-05-12 |
Healthcare |
Medium
|
Aesthetify GmbH |
Germany |
— |
— |
| Google: GTIG intercepts first known AI-generated zero-day exploit before mass exploitation |
2026-05-11 |
Technology |
Low
|
Google |
United States |
— |
— |
| OpenAI: Undisclosed agent swarm floods RubyGems with 2,000+ malicious packages, gains RCE on RubyDoc servers |
2026-05-11 |
Technology |
High
|
OpenAI |
United States |
— |
OpenAI |
| PraisonAI: Authentication-bypass flaw in AI agent framework targeted within hours of disclosure |
2026-05-11 |
Technology |
Low
|
PraisonAI |
— |
— |
— |
| Palo Alto Unified: Family sues district for $150 million over AI-cheating accusation |
2026-05-11 |
Education |
Medium
|
Palo Alto Unified School District |
United States |
— |
— |
| Unnamed organization: LLM agent autonomously exfiltrates database via marimo flaw |
2026-05-10 |
Technology |
Medium
|
Unnamed organization |
— |
— |
— |
| Marimo: Attacker uses autonomous LLM agent for post-exploitation after critical RCE |
2026-05-10 |
Technology |
Medium
|
Marimo |
— |
— |
— |