Incidents
Real-world breaches, exploits, and case studies
Prompt injection incidents 10
- Atlassian Rovo Exfiltrates Data, Bypassing Controlspromptarmor.com
- EchoLeak - Zero-Click Prompt Injection in Microsoft 365 Copilotaim.security
- Fed up with vibe coders, dev sneaks data-nuking prompt injection into their codearstechnica.com
- GM Dealer Chat Bot Agrees To Sell 2024 Chevy Tahoe For $1gmauthority.com
- PerplexedBrowser: Perplexity's Agent Browser Can Leak Your PC's Local Fileslabs.zenity.io
- Phishing for Gemini - indirect prompt injection in Gemini for Workspace email summaries0din.ai
- User tricked Grok and Bankrbot to send tokens with Morse codecryptopolitan.com
- We Hacked Google A.I. for $50,000landh.tech
- xAI on unauthorized modification of Grok's system prompt and publishing prompts on GitHubx.com
- zack_overflow on Brave's Perplexity Comet prompt injection disclosure - why he avoids AI browsersx.com
Data breaches 25
- Claude Code Leaksccleaks.com
- 38TB of Data Accidentally Exposed by Microsoft AI Researcherswiz.io
- A hacker accessed Suno source code that reportedly details how the company scraped millions of songsengadget.com
- Adobe breached by threat actor Mr. Raccoon, 13 million support tickets leakedx.com
- Ayoub Fathi on 4 ChatGPT account-takeover vulnerabilitiesx.com
- ChatGPT Account Takeover - Wildcard Web Cache Deceptionnokline.github.io
- ChatGPT had a symlink exploit that allowed users to download data from the chat botsecuritronlinux.com
- Congressional oversight letter to OpenAI on the OpenAI Hugging Face security incidentcasar.house.gov
- Context.ai security update on the OAuth compromise behind the Vercel April 2026 breachcontext.ai
- Databricks Security says investigation of alleged breach screenshot found nothingx.com
- Gergely Orosz on the Claude Code source leak and a DMCA-proof Python rewritex.com
- GitLab IDOR exposes all Machine Learning Model Registry models - HackerOne reporthackerone.com
- Granola API Endpoint Information Disclosure - Tenable Research Advisory TRA-2025-07tenable.com
- Guillermo Rauch on the Vercel April 2026 security incidentx.com
- James Zhou: AI compliance startup Delve's Supabase bucket publicly exposed background checks and tokensx.com
- Microsoft Copilot Vulnerability Exposes Fortune 500 Datalasso.security
- Moin Nadeem: Delve left an S3 bucket of customer network diagrams publicx.com
- Nagli on a critical ChatGPT account takeover vulnerability fixed by OpenAIx.com
- Nagli: RentAHuman leaked 187k user emails, found with one Claude Code commandx.com
- Rabbitude Security Disclosure - hardcoded API keys exposed in the Rabbit R1 codebaserabbitu.de
- SEC Cybersecurity Incidents Database - Jestrdukesecurity.ai
- tl;dv Too Lazy Didn't Validate - 181,874 Meetings Left Wide Openbobdahacker.com
- weezerOSINT: Fireflies.ai GraphQL API exposes .gov emails and meeting recordings with no authx.com
- Would you like an IDOR with that? Leaking 64 million McDonald's job applicationsian.sh
- xyzeva on Rabbit revoking leaked ElevenLabs API key and bricking every R1x.com
Agent security incidents 53
- A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Reportgambit.security
- 1-Click RCE To Steal Your OpenClaw Data and Keys - CVE-2026-25253depthfirst.com
- A Meta agentic AI sparked a security incident by acting without permissionengadget.com
- Agent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook - Zenity Labslabs.zenity.io
- AI Agents Gone Rogue - a registry of AI agent failures, exploits, and defensesosohq.com
- AISI Incident Report: Unsanctioned Agent Behaviour During Cyber Testingaisi.gov.uk
- An AI Agent Just Destroyed Our Production Data - It Confessed in Writingx.com
- Anatomy of a Frontier Lab Agent Intrusion - incident replayhuggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
- Anthropic's Fever Dream: Claude's package anthropickit that stole real keysaikido.dev
- Captured Logs Reveal Hackers Using Claude and Codex to Breach Companiesresearch.openanalysis.net
- Daniel Cuthbert on the OpenAI training run uploading files to package artifactoryx.com
- Dave Kennedy on Codex appending --delete and wiping a dev filesystemx.com
- dax on an opencode fork that routes through Chipotle's unsecured AI endpointsx.com
- Disrupting the first reported AI-orchestrated cyber espionage campaignanthropic.com
- Disrupting the first reported AI-orchestrated cyber espionage campaign - Anthropic full reportassets.anthropic.com
- Drive-By Agent Hijacking - One Website Visit, Persistent Model Poisoningcyera.com
- Felony Bench - counting illegal actions taken by AI agentsfelonybench.com
- Hacker News discussion of Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incidentnews.ycombinator.com
- hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hitstepsecurity.io
- How a Texas student blew the whistle on a rogue AI hacking attemptreuters.com
- How I bypassed the control plane in Azure OpenAItrustoncloud.com
- How We Could Watch Your Azure SRE Agent In Real Timeenclave.ai
- How We Got Admin Access to Every Copilot Studio Agent Sandbox on Earthbeyondtrust.com
- Hugging Face Incident Initial Post Mortem - CSAcloudsecurityalliance.org
- Hugging Face security incident disclosure - July 2026huggingface.co
- IBM AI bot Bob downloads and executes malwarepromptarmor.com
- Independent investigation of agent behavior in the OpenAI / Hugging Face hacking incidentmetr.org
- Investigating three real-world incidents in our cybersecurity evaluationsanthropic.com
- Irregular incident report: eval sandbox containment failure let AI models attack a real company's domainirregular.com
- Jamieson O'Reilly on hacking Clawdbot and eating lobster soulsx.com
- Jamieson O'Reilly: found 15 CVEs in OpenClaw, do not run it on enterprise devicesx.com
- Jarrod Watts on how someone won $50,000 by convincing the Freysa AI agent to transfer fundsx.com
- Jason Lemkin: Replit agent goes rogue during a code freeze and deletes our entire databasex.com
- Josh Kale on Alibaba report of AI diverting training GPUs to mine crypto and opening SSH tunnelx.com
- LangGrinch - LangChain Core serialization injection CVE-2025-68664cyata.ai
- METR and Redwood on agents cheating in the Hugging Face incidentx.com
- OpenAI - Hugging Face Incident Technical Reportcdn.openai.com
- OpenAI and Hugging Face address security incident during model evaluation: agents escaped sandboxt.co
- OpenClaw may disclose local files via MEDIA: path staging - GHSA-r8g4-86fx-92mqgithub.com
- PraisonAI advisory: sandbox escape via exception frame traversal in execute_codegithub.com
- Qihoo 360 leaks wildcard SSL private key inside its 360 Security Claw AI assistant installerx.com
- Ryan Greenblatt on the Hugging Face agent swarm incident and why overseeing AI swarms is hardx.com
- Sebastien Guillemot on Claude wiping his dev machine with rm -rf while testing a sandboxx.com
- Security Incident INC-2026-07-28-01 - UK AI Security Institutecdn.prod.website-files.com
- ShadowPrompt: How Any Website Could Have Hijacked Anthropic's Claude Chrome Extensionkoi.ai
- Simon Willison on accidental cyberattacks - AI labs inadvertently attacking real organizationssimonwillison.net
- SSRFing the Web with the Help of Copilot Studiotenable.com
- Tailscale in the Hugging Face intrusiontailscale.com
- The Hugging Face attack surprised me - Ajeya Cotra on the coordinated AI agent attackplanned-obsolescence.org
- The OpenAI-Hugging Face Incident: A Technical Reconstruction - Black Hat USA 2026youtube.com
- Yousif Astarabadi - I hacked Perplexity Computer and got unlimited Claude Codex.com
- Zack Korman's preliminary security findings on ChatGPT Atlasx.com
MCP vulnerabilities 4
- Asana warns MCP AI feature exposed customer data to other orgsbleepingcomputer.com
- BadHost - CVE-2026-48710 Starlette Host-Header Auth Bypass affecting vLLM, LiteLLM and MCP serversbadhost.org
- Supabase MCP can leak your entire SQL databasegeneralanalysis.com
- When "Read-Only Mode" Isn't - CVE-2026-46519 in mcp-server-kubernetesmanifold.security
Coding tool vulnerabilities 28
- Critical Claude Code vulnerability: Deny rules silently bypassed because security checks cost too many tokensadversa.ai
- Adam Baldwin on a $1500 Cursor auth bypass found with Burp Suitebsky.app
- Agentjacking - One Fake Bug Report Hijacked a $250B Company's AI Agenttenetsecurity.ai
- AI Incident Roundup - October and November 2024 - AI Incident Databaseincidentdatabase.ai
- Breaking Claude Code Opus 5 Auto Mode - website summary hijacks agent to code executionembracethered.com
- Claude Code leaked source mirror - source exposed via npm source map filegithub.com
- Claude Opus 4.6 wrote vulnerable code leading to a $1.78M smart contract exploitx.com
- Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgardmindgard.ai
- CVE-2025-64755 - Claude Code sed command validation bypass allows arbitrary file writesgithub.com
- CyberSatoshi on Grok Build silently uploading repos and secrets to GCPx.com
- GitHub Actions Security Pt 2: AI-Powered Actions Analysiswiz.io
- GitHub Copilot: Remote Code Execution via Prompt Injection, CVE-2025-53773embracethered.com
- GitLost: How We Tricked GitHub's AI Agent into Leaking Private Reposnoma.security
- Google Antigravity just deleted the contents of my D drive - r/google_antigravityold.reddit.com
- Hack to the Future: Owning AI-Powered Tools with Old School Vulns - Kudelski Security Black Hat USA 2025 slidesresearch.kudelskisecurity.com
- Hacker injects malicious, potentially disk-wiping prompt into Amazon's AI coding assistant via a pull requesttomshardware.com
- IBM AI 'Bob' Downloads and Executes Malware via Indirect Prompt Injectionpromptarmor.com
- My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-clipillar.security
- New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agentspillar.security
- One Docker socket to rule them all: escaping Codex, Cursor, and Gemini CLI's sandboxespillar.security
- OpenAI Codex Command Injection Vulnerabilitybeyondtrust.com
- The Month of AI Bugs 2025 - agentic AI vulnerabilitiesmonthofaibugs.com
- The Week of Sandbox Escapes Day 1: Escaping Antigravity's Allow-Default Seatbeltpillar.security
- Thread on Anthropic's accidental Claude Code source leak and the claw-code rewritesx.com
- Tibo Sottiaux on Codex safeguards after GPT-5.6 cleanup commands deleted user filesx.com
- Unauthenticated Remote Code Execution in OpenCodecy.md
- Week of Sandbox Escapes Day 3: Cursor sandbox let the agent edit a venv, and something else ran itpillar.security
- zak on his crypto wallet drained by a malicious Cursor AI extensionx.com