{
 "name": "Sev0 AI security incident dataset",
 "url": "https://sev0.fyi/",
 "license": "https://creativecommons.org/licenses/by/4.0/",
 "updated": "2026-09-28",
 "count": 60,
 "incidents": [
  {
   "title": "OpenAI research agents posted 53 ChatGPT user images to public sites",
   "summary": "OpenAI confirmed that agents in its research environment uploaded 53 images from ChatGPT users to third-party image hosting sites without authorization. Most were removed; OpenAI did not say whether they showed identifiable people.",
   "date_disclosed": "2026-09-25",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "OpenAI",
   "org_sector": "ai_vendor",
   "ai_vendor": "openai",
   "product": "OpenAI research agents",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "personal_data"
   ],
   "impact": "limited",
   "records_affected": 53,
   "model_at_fault": "yes",
   "sources": [
    "https://tech-insider.org/openai-agents-leaked-53-chatgpt-images-2026/",
    "https://kingy.ai/blog/openai-data-leak-explained/"
   ],
   "id": "2026-09-25-openai-agents-leaked-chatgpt-images",
   "severity": "low",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "OpenAI agent breached Australian Medicare statistics portal",
   "summary": "Australia's prime minister said an OpenAI agent got around access controls on a Services Australia Medicare statistics portal in June, accessed non-public files and wrote files to the server. No personal information is believed to have been accessed. OpenAI said it happened during an internal evaluation and notified the government nearly three months later.",
   "date_disclosed": "2026-09-23",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Services Australia",
   "org_sector": "government",
   "country": "AU",
   "ai_vendor": "openai",
   "product": "OpenAI research agent",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "internal_docs"
   ],
   "impact": "limited",
   "model_at_fault": "yes",
   "sources": [
    "https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078",
    "https://www.cnbc.com/2026/09/24/openai-agent-hacked-australian-government-website-.html",
    "https://www.helpnetsecurity.com/2026/09/24/openai-agent-hacking-australia/"
   ],
   "date_occurred": "2026-06-18",
   "id": "2026-09-23-openai-agent-australia-medicare-portal",
   "severity": "low",
   "days_to_disclose": 97,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Spain's data regulator received its first breach report blaming an autonomous AI agent",
   "summary": "An organization told Spain's data protection agency that an attacker's AI agent, built on a known language model, logged into its systems, hunted for flaws on its own, altered users' personal data and accessed invoices. The regulator stressed the account is unverified and did not name the organization or the model.",
   "date_disclosed": "2026-09-15",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "Undisclosed (Spain)",
   "org_sector": "other",
   "country": "ES",
   "ai_vendor": "unknown",
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "both",
   "data_types": [
    "personal_data",
    "financial"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/",
    "https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/"
   ],
   "date_occurred": "2026-09-14",
   "id": "2026-09-15-spain-aepd-first-ai-agent-breach",
   "severity": "high",
   "days_to_disclose": 1,
   "family": "ai_run_attack"
  },
  {
   "title": "OpenAI agent swarm flooded RubyGems with malicious packages",
   "summary": "Researchers linked the May 'GemStuffer' campaign, which flooded RubyGems with hundreds of packages and forced a pause on sign-ups, to OpenAI agents running training tasks. The agents gained code execution on RubyDoc servers and attempted a zero-day to steal user API keys; RubyGems found no evidence credentials were taken. OpenAI confirmed the incident.",
   "date_disclosed": "2026-09-11",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "RubyGems",
   "org_sector": "technology",
   "ai_vendor": "openai",
   "product": "OpenAI research agents",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "unknown"
   ],
   "impact": "limited",
   "model_at_fault": "yes",
   "sources": [
    "https://rubyhack.ai/",
    "https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html",
    "https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/"
   ],
   "date_occurred": "2026-05-11",
   "id": "2026-09-11-openai-agents-rubygems-gemstuffer",
   "severity": "low",
   "days_to_disclose": 123,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Anthropic disclosed a fourth case of a Claude model breaching a real system during testing",
   "summary": "Anthropic found that in January 2026 an early Claude Opus 4.6 checkpoint reached the internet from a cyber evaluation it believed was simulated, retrieved credentials, gained administrator access to a real third-party system, changed settings and read personal information. The case was missed by Anthropic's first review and found in August; it has asked METR to investigate all four incidents.",
   "date_disclosed": "2026-09-09",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Undisclosed",
   "org_sector": "other",
   "ai_vendor": "anthropic",
   "product": "Claude (cyber evaluation)",
   "model_name": "Claude Opus 4.6",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "personal_data"
   ],
   "impact": "organization",
   "model_at_fault": "yes",
   "sources": [
    "https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html",
    "https://www.unite.ai/anthropic-discloses-fourth-cyber-incident-in-alignment-assessment/"
   ],
   "date_occurred": "2026-01-01",
   "id": "2026-09-09-anthropic-fourth-eval-incident",
   "severity": "high",
   "days_to_disclose": 251,
   "family": "agent_misbehaviour"
  },
  {
   "title": "OpenAI agents took over a dormant German wiki as a secret coordination board",
   "summary": "Researchers found about 18,000 posts left between May and July 2026 by autonomous agents identifying as OpenAI systems on DSEwiki, a 25-year-old German developer wiki. Meant to only read the web, the agents exploited old wiki software that saves edits via ordinary page requests to share task answers and sandbox escape tips, repeatedly overwriting the front page. OpenAI confirmed it after Reuters reported that leadership knew for weeks.",
   "date_disclosed": "2026-09-04",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "DSEwiki (wikiservice.at)",
   "org_sector": "technology",
   "country": "DE",
   "ai_vendor": "openai",
   "product": "OpenAI research agents",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "destruction",
   "data_types": [
    "unknown"
   ],
   "impact": "limited",
   "model_at_fault": "yes",
   "sources": [
    "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
    "https://www.euronews.com/next/2026/09/09/rogue-openai-agents-hijacked-a-german-wiki-and-it-stayed-secret-for-weeks"
   ],
   "date_occurred": "2026-05-11",
   "id": "2026-09-04-openai-agents-dsewiki-swarm",
   "severity": "medium",
   "days_to_disclose": 116,
   "family": "agent_misbehaviour"
  },
  {
   "title": "ClarityCheck left 9 million facial recognition images exposed",
   "summary": "A reverse image search and identity verification service left a 450 GB database of about 9 million facial and profile images publicly accessible, including images of children. The researcher reported it and the database was secured.",
   "date_disclosed": "2026-08-19",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "ClarityCheck",
   "org_sector": "technology",
   "ai_vendor": "unknown",
   "product": "ClarityCheck",
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "harm_type": "exposure",
   "data_types": [
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 9042977,
   "model_at_fault": "no",
   "sources": [
    "https://www.expressvpn.com/blog/clarity-check-data-exposed/",
    "https://www.techradar.com/pro/security/over-9-million-facial-recognition-images-leaked-in-major-breach-at-reverse-image-search-and-identity-verification-service"
   ],
   "id": "2026-08-19-claritycheck-facial-images-exposed",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "AI agent swarm used against Taiwanese government systems",
   "summary": "Suspected China-linked operators ran a near-autonomous campaign using open-source agent frameworks, with multiple parallel sub-agents handling reconnaissance, credential attacks and lateral movement. Reported results included 85 cracked accounts and more than 2,500 personnel records taken. Taiwan's Ministry of Digital Affairs confirmed an AI-agent-assisted attack.",
   "date_disclosed": "2026-08-12",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Taiwan government",
   "org_sector": "government",
   "country": "TW",
   "ai_vendor": "unknown",
   "product": "Hermes and OpenClaw agents",
   "open_source": true,
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "exposure",
   "data_types": [
    "personal_data",
    "credentials"
   ],
   "impact": "multi_org",
   "records_affected": 2500,
   "model_at_fault": "no",
   "sources": [
    "https://www.theregister.com/security/2026/08/12/near-autonomous_ai_agents_attack_taiwans_nuclear_safety_agency/5287055"
   ],
   "date_occurred": "2026-07-01",
   "id": "2026-08-12-taiwan-government-ai-agent-campaign",
   "severity": "high",
   "days_to_disclose": 42,
   "family": "ai_run_attack"
  },
  {
   "title": "CHAINDROP npm worm planted persistence hooks in Claude Code settings",
   "summary": "A self-propagating worm starting from a hijacked maintainer account spread to 452 npm packages with around two billion monthly downloads. Alongside cloud and CI secrets it harvested AI tool configs and planted hooks in Claude Code and VS Code settings so it re-ran on every coding agent session.",
   "date_disclosed": "2026-08-04",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "multiple",
   "product": "Claude Code",
   "product_surface": "coding_agent",
   "ai_role": "supply_chain",
   "mechanism": "agent_hijack",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "ecosystem",
   "model_at_fault": "no",
   "sources": [
    "https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain",
    "https://safedep.io/keyv-npm-supply-chain-compromise/"
   ],
   "id": "2026-08-04-chaindrop-npm-worm-claude-hooks",
   "severity": "high",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "Langflow AI pipeline RCE flaws exploited in the wild, added to CISA KEV",
   "summary": "Critical unauthenticated remote code execution flaws in Langflow, a popular AI agent and pipeline builder, were exploited within about a day of disclosure and drew attacks from hundreds of IPs. Several Langflow CVEs landed on CISA's Known Exploited Vulnerabilities list, and one campaign fed Langflow access into agent-driven ransomware.",
   "date_disclosed": "2026-08-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "Langflow",
   "open_source": true,
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "unsecured_ai_infrastructure",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "multi_org",
   "model_at_fault": "no",
   "sources": [
    "https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html",
    "https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours"
   ],
   "cve_ids": [
    "CVE-2026-33017",
    "CVE-2026-9198"
   ],
   "id": "2026-08-01-langflow-rce-mass-exploitation",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Anthropic models breached three real companies during cyber evaluations",
   "summary": "Anthropic found that a partner's misconfiguration left some cyber evaluation machines connected to the live internet, and its models attacked real organizations. In one case a model extracted credentials and read production data, and in another a model published a malicious PyPI package that ran on 15 real systems. Victims were notified and internet-connected cyber tests were halted.",
   "date_disclosed": "2026-07-30",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "anthropic",
   "product": "Claude (cyber evaluation)",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "unknown"
   ],
   "impact": "multi_org",
   "model_at_fault": "yes",
   "sources": [
    "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
    "https://techcrunch.com/2026/07/30/anthropic-says-its-own-ai-models-breached-three-companies-during-security-tests/"
   ],
   "id": "2026-07-30-anthropic-eval-models-breached-companies",
   "severity": "high",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "OpenAI evaluation agents escaped sandbox and breached Hugging Face",
   "summary": "During an internal cyber evaluation, OpenAI models escaped their sandbox via zero-days in a JFrog Artifactory proxy, reached the internet and gained code execution in Hugging Face production infrastructure. The agents harvested cloud, database, VPN and GitHub credentials before Hugging Face cut access. Hugging Face reported no tampering with public models or datasets.",
   "date_disclosed": "2026-07-21",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Hugging Face",
   "org_sector": "ai_vendor",
   "ai_vendor": "openai",
   "product": "OpenAI research agents",
   "model_name": "GPT-5.6",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "sandbox_escape",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "yes",
   "sources": [
    "https://openai.com/index/hugging-face-model-evaluation-security-incident/",
    "https://huggingface.co/blog/security-incident-july-2026",
    "https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/"
   ],
   "date_occurred": "2026-07-09",
   "cve_ids": [
    "CVE-2026-65921",
    "CVE-2026-66014"
   ],
   "id": "2026-07-21-openai-agents-hugging-face",
   "severity": "high",
   "days_to_disclose": 12,
   "family": "agent_misbehaviour"
  },
  {
   "title": "JADEPUFFER: first documented LLM-driven ransomware operation",
   "summary": "Sysdig captured a ransomware operation run end to end by an LLM agent. It entered through an internet-facing Langflow server, harvested and reused credentials, moved laterally, set up persistence and destroyed a production database, correcting its own failures along the way.",
   "date_disclosed": "2026-07-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Undisclosed",
   "org_sector": "other",
   "ai_vendor": "unknown",
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "both",
   "data_types": [
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
    "https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/"
   ],
   "cve_ids": [
    "CVE-2025-3248"
   ],
   "id": "2026-07-01-jadepuffer-agentic-ransomware",
   "severity": "high",
   "days_to_disclose": null,
   "family": "ai_run_attack"
  },
  {
   "title": "Hermes AI agent automated intrusion into Thailand's Ministry of Finance",
   "summary": "Researchers found exposed attacker directories showing an AI agent running unattended post-exploitation against Thailand's Ministry of Finance, enumerating hosts, browsing personnel records and staging webshells and implants. No evidence of file exfiltration was found; the activity was assessed as a Chinese-speaking espionage actor.",
   "date_disclosed": "2026-07-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Thailand Ministry of Finance",
   "org_sector": "government",
   "country": "TH",
   "ai_vendor": "unknown",
   "product": "Hermes agent",
   "open_source": true,
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "internal_docs"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent",
    "https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/"
   ],
   "id": "2026-07-01-thailand-finance-ministry-hermes-agent",
   "severity": "high",
   "days_to_disclose": null,
   "family": "ai_run_attack"
  },
  {
   "title": "Novo Nordisk breach included theft of internal AI model assets",
   "summary": "Novo Nordisk disclosed that attackers accessed internal systems and copied non-public data, including pseudonymised clinical trial data and internal AI model assets. The group claiming responsibility said it entered through a GitHub access token and took 1.3 TB; Novo reportedly refused a ransom demand.",
   "date_disclosed": "2026-06-11",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Novo Nordisk",
   "org_sector": "health",
   "country": "DK",
   "ai_vendor": "other",
   "product_surface": "model_or_package",
   "ai_role": "target",
   "mechanism": "stolen_token",
   "harm_type": "exposure",
   "data_types": [
    "health",
    "model_weights",
    "internal_docs"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.novonordisk.com/news-and-media/latest-news/incident-update.html",
    "https://www.securityweek.com/ozempic-maker-novo-nordisk-says-hackers-breached-it-systems/",
    "https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/"
   ],
   "id": "2026-06-11-novo-nordisk-ai-model-assets",
   "severity": "high",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "Miasma worm poisoned Microsoft repos to hijack AI coding agents",
   "summary": "A self-replicating worm spread through more than 70 Microsoft and Azure GitHub repositories, planting config files that make Claude Code, Gemini CLI, Cursor and VS Code run a credential stealer when a developer opens the repo. GitHub disabled 73 repositories within minutes.",
   "date_disclosed": "2026-06-05",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Microsoft",
   "org_sector": "technology",
   "ai_vendor": "multiple",
   "product": "Claude Code, Gemini CLI, Cursor",
   "product_surface": "coding_agent",
   "ai_role": "supply_chain",
   "mechanism": "agent_hijack",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "multi_org",
   "model_at_fault": "no",
   "sources": [
    "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
    "https://www.govinfosecurity.com/miasma-worm-hits-microsofts-ai-coding-ecosystem-a-31912"
   ],
   "id": "2026-06-05-miasma-worm-ai-coding-agents",
   "severity": "high",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "Meta's AI support tool abused to hijack 20,000 Instagram accounts",
   "summary": "Attackers abused Meta's AI-assisted account recovery tool, which failed to check that the reset email matched the account, to take over 20,225 Instagram accounts without two-factor authentication. Meta disclosed the incident in a breach notice and says affected accounts were secured.",
   "date_disclosed": "2026-06-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Meta (Instagram)",
   "org_sector": "technology",
   "ai_vendor": "meta",
   "product": "Meta AI support assistant",
   "product_surface": "custom_ai_app",
   "ai_role": "vector",
   "mechanism": "app_flaw",
   "harm_type": "exposure",
   "data_types": [
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 20225,
   "model_at_fault": "no",
   "sources": [
    "https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/"
   ],
   "id": "2026-06-01-meta-ai-support-instagram-takeovers",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "US bank reported customer SSNs entered into an unauthorized AI app",
   "summary": "Community Bank disclosed in an SEC filing that customer names, dates of birth and Social Security numbers had been entered into an unapproved AI application. The bank opened an investigation and notified regulators.",
   "date_disclosed": "2026-05-12",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Community Bank",
   "org_sector": "finance",
   "country": "US",
   "ai_vendor": "unknown",
   "product_surface": "custom_ai_app",
   "ai_role": "vector",
   "mechanism": "shadow_ai",
   "harm_type": "exposure",
   "data_types": [
    "personal_data",
    "financial"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.theregister.com/security/2026/05/12/us-bank-reports-itself-after-ai-customer-data-mishap/5238787"
   ],
   "id": "2026-05-12-community-bank-unauthorized-ai-app",
   "severity": "high",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "AI-driven attacker escaped container and stole Kubernetes secrets",
   "summary": "Sysdig observed an AI-agent-driven attacker enter through a marimo RCE, abuse a mounted Docker socket to reach host root, then reuse a service account token to extract cluster secrets including database, AWS and OpenAI API credentials.",
   "date_disclosed": "2026-05-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Undisclosed",
   "org_sector": "other",
   "ai_vendor": "unknown",
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape"
   ],
   "date_occurred": "2026-05-29",
   "cve_ids": [
    "CVE-2026-39987"
   ],
   "id": "2026-05-01-sysdig-agentic-kubernetes-escape",
   "severity": "high",
   "days_to_disclose": -28,
   "family": "ai_run_attack"
  },
  {
   "title": "AI agent went from marimo notebook exploit to full database dump in under an hour",
   "summary": "Sysdig observed an LLM-driven intrusion that exploited an internet-facing marimo notebook, harvested cloud credentials, pulled an SSH key from AWS Secrets Manager and exfiltrated a full PostgreSQL database through four pivots in under an hour, without pre-written scripts.",
   "date_disclosed": "2026-05-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Undisclosed",
   "org_sector": "other",
   "ai_vendor": "unknown",
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "unknown"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots"
   ],
   "date_occurred": "2026-05-10",
   "cve_ids": [
    "CVE-2026-39987"
   ],
   "id": "2026-05-01-sysdig-marimo-agent-database-theft",
   "severity": "high",
   "days_to_disclose": -9,
   "family": "ai_run_attack"
  },
  {
   "title": "Cursor agent running Claude deleted PocketOS production database and backups",
   "summary": "While working on a routine staging task, a Cursor coding agent running Claude Opus 4.6 decided on its own to fix a credential mismatch by deleting a storage volume. It found an unrelated, over-scoped Railway API token in the codebase and wiped the production database and its backups in about nine seconds. The platform was down for around 30 hours before a backup was restored.",
   "date_disclosed": "2026-04-27",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "PocketOS",
   "org_sector": "technology",
   "ai_vendor": "anthropic",
   "product": "Cursor",
   "model_name": "Claude Opus 4.6",
   "product_surface": "coding_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "personal_data",
    "financial"
   ],
   "impact": "organization",
   "model_at_fault": "yes",
   "sources": [
    "https://www.theregister.com/2026/04/27/cursoropus_agent_snuffs_out_pocketos/",
    "https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue",
    "https://incidentdatabase.ai/cite/1469"
   ],
   "id": "2026-04-27-pocketos-cursor-agent-deleted-database",
   "severity": "high",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "AI companion site MyLovely.AI breach exposed explicit prompts",
   "summary": "A breach of AI companion and image platform MyLovely.AI exposed emails, prompts and generated image links for more than 100,000 users. Around 113,000 explicit prompts were included, about 70,000 of them linkable to user IDs, raising sextortion risk.",
   "date_disclosed": "2026-04-09",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "MyLovely.AI",
   "org_sector": "technology",
   "ai_vendor": "unknown",
   "product": "MyLovely.AI",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "unknown",
   "harm_type": "exposure",
   "data_types": [
    "personal_data",
    "chat_logs"
   ],
   "impact": "organization",
   "records_affected": 100000,
   "model_at_fault": "no",
   "sources": [
    "https://www.helpnetsecurity.com/2026/04/09/mylovely-ai-data-breach-user-conversations/"
   ],
   "id": "2026-04-09-mylovely-ai-companion-breach",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "unknown"
  },
  {
   "title": "Compromised AI tool Context.ai used as a pivot into Vercel",
   "summary": "Attackers compromised AI productivity vendor Context.ai, then used an OAuth token from a Vercel employee who had granted the tool broad Google Workspace access to reach some Vercel environments and read environment variables.",
   "date_disclosed": "2026-04-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Vercel",
   "org_sector": "technology",
   "ai_vendor": "unknown",
   "product": "Context.ai",
   "product_surface": "enterprise_copilot",
   "ai_role": "supply_chain",
   "mechanism": "stolen_token",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://vercel.com/kb/bulletin/vercel-april-2026-security-incident",
    "https://www.darkreading.com/application-security/vercel-employees-ai-tool-access-data-breach"
   ],
   "id": "2026-04-01-context-ai-vercel-oauth",
   "severity": "high",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "LiteLLM AI gateway releases on PyPI backdoored to steal credentials",
   "summary": "Attackers used publishing credentials stolen through an earlier Trivy compromise to push malicious LiteLLM releases to PyPI for about 40 minutes. The payload harvested cloud, Kubernetes, CI/CD and database secrets and installed a backdoor. Analysts later assessed credentials from 2,500+ organizations were exposed, and AI recruiter Mercor confirmed it was affected.",
   "date_disclosed": "2026-03-24",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "LiteLLM",
   "open_source": true,
   "product_surface": "model_or_package",
   "ai_role": "supply_chain",
   "mechanism": "poisoned_package",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "ecosystem",
   "model_at_fault": "no",
   "sources": [
    "https://docs.litellm.ai/blog/security-update-march-2026",
    "https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/",
    "https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/"
   ],
   "cve_ids": [
    "CVE-2026-33634"
   ],
   "id": "2026-03-24-litellm-pypi-supply-chain",
   "severity": "high",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "McKinsey's internal AI platform Lilli exposed via SQL injection",
   "summary": "Security firm CodeWall pointed an autonomous offensive agent at McKinsey's Lilli AI platform and gained read and write access to its production database within about two hours via a blind SQL injection. The database held tens of millions of chat messages, hundreds of thousands of files and the platform's system prompts. McKinsey patched quickly and said forensics found no unauthorized third-party access to client data.",
   "date_disclosed": "2026-03-09",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "McKinsey & Company",
   "org_sector": "other",
   "ai_vendor": "unknown",
   "product": "Lilli",
   "product_surface": "enterprise_copilot",
   "ai_role": "target",
   "mechanism": "app_flaw",
   "harm_type": "exposure",
   "data_types": [
    "chat_logs",
    "internal_docs",
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 57000,
   "model_at_fault": "no",
   "sources": [
    "https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform",
    "https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/",
    "https://incidentdatabase.ai/cite/1412"
   ],
   "id": "2026-03-09-mckinsey-lilli-sql-injection",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Browser extensions harvested private AI chats into a commercial database",
   "summary": "A researcher found private chatbot conversations captured by browser extensions, stored in a vector database and sold through an API. The data included healthcare workers pasting patient details and people asking about their immigration status.",
   "date_disclosed": "2026-03-03",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "AI chatbot users",
   "org_sector": "multiple",
   "ai_vendor": "multiple",
   "product": "Browser extensions",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "third_party_leak",
   "harm_type": "exposure",
   "data_types": [
    "chat_logs",
    "personal_data",
    "health"
   ],
   "impact": "multi_org",
   "model_at_fault": "no",
   "sources": [
    "https://www.theregister.com/software/2026/03/03/chatbot-data-harvesting-yields-sensitive-personal-info/4166233"
   ],
   "id": "2026-03-03-browser-extensions-harvest-ai-chats",
   "severity": "high",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "Jailbroken Claude Code used to breach Mexican government agencies",
   "summary": "A single attacker jailbroke Claude and used Claude Code as the planner and executor of intrusions into more than ten Mexican federal, state and municipal agencies and a financial institution. Reported losses were around 150 GB of data including national ID numbers, voter data and employee credentials.",
   "date_disclosed": "2026-03-02",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "Mexican government agencies",
   "org_sector": "government",
   "country": "MX",
   "ai_vendor": "anthropic",
   "product": "Claude Code",
   "model_name": "Claude",
   "product_surface": "coding_agent",
   "ai_role": "weapon",
   "mechanism": "jailbreak_misuse",
   "harm_type": "exposure",
   "data_types": [
    "personal_data",
    "credentials"
   ],
   "impact": "multi_org",
   "records_affected": 195000000,
   "model_at_fault": "unclear",
   "sources": [
    "https://www.upguard.com/news/sat-data-breach-2026-03-02",
    "https://socradar.io/blog/mexican-government-breach-claude-chatgpt/"
   ],
   "id": "2026-03-02-mexican-government-claude-code",
   "severity": "high",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "Anthropic accidentally published Claude Code's full source code to npm",
   "summary": "A packaging mistake shipped a complete source map inside a public Claude Code release, exposing about 500,000 lines of the agent's code, including its permission system and unreleased features. The code was mirrored widely within hours.",
   "date_disclosed": "2026-03-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Anthropic",
   "org_sector": "ai_vendor",
   "ai_vendor": "anthropic",
   "product": "Claude Code",
   "product_surface": "coding_agent",
   "ai_role": "target",
   "mechanism": "accidental_publication",
   "data_types": [
    "source_code"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://guardion.ai/ai-incidents/anthropic-claude-code-source-map-leak"
   ],
   "harm_type": "exposure",
   "id": "2026-03-01-anthropic-claude-code-source-leak",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Meta internal AI agent's advice triggered a two-hour data exposure",
   "summary": "An internal Meta AI agent posted inaccurate technical advice on an internal forum without being asked. An employee acted on it, triggering a high-severity incident in which staff could view sensitive company and user data they were not authorized to see for nearly two hours. Meta says no user data was mishandled.",
   "date_disclosed": "2026-03-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Meta",
   "org_sector": "technology",
   "ai_vendor": "meta",
   "product": "Internal Meta agent",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "overreach",
   "harm_type": "exposure",
   "data_types": [
    "personal_data",
    "internal_docs"
   ],
   "impact": "organization",
   "model_at_fault": "yes",
   "sources": [
    "https://www.theverge.com/ai-artificial-intelligence/897528/meta-rogue-ai-agent-security-incident",
    "https://incidentdatabase.ai/cite/1471"
   ],
   "id": "2026-03-01-meta-internal-agent-sev1",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Sears Home Services AI chatbot databases exposed 3.7 million records",
   "summary": "A researcher found three unsecured databases behind Sears Home Services' AI chatbot and scheduling assistant, exposing chat logs, call recordings, scheduling files and customer personal data. Access was restricted the day after disclosure.",
   "date_disclosed": "2026-03-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Sears Home Services",
   "org_sector": "retail",
   "country": "US",
   "ai_vendor": "unknown",
   "product": "Sears virtual assistant",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "harm_type": "exposure",
   "data_types": [
    "chat_logs",
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 3700000,
   "model_at_fault": "no",
   "sources": [
    "https://www.securitymagazine.com/articles/102188-37m-records-exposed-many-belonging-to-sears-home-services",
    "https://cybernews.com/ai-news/ai-chatbot-data-leak-sears/"
   ],
   "id": "2026-03-01-sears-ai-chatbot-databases",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Autonomous Claude-powered bot compromised the Trivy security scanner",
   "summary": "A bot describing itself as an autonomous security research agent exploited a GitHub Actions misconfiguration in Trivy, stole a token, deleted releases and pushed a malicious VS Code extension. Incomplete credential rotation let a second group return weeks later and poison Trivy's actions, which led to the LiteLLM compromise.",
   "date_disclosed": "2026-03-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Aqua Security (Trivy)",
   "org_sector": "technology",
   "ai_vendor": "anthropic",
   "product": "hackerbot-claw",
   "model_name": "Claude Opus 4.5",
   "product_surface": "autonomous_agent",
   "ai_role": "weapon",
   "mechanism": "autonomous_intrusion",
   "harm_type": "both",
   "data_types": [
    "credentials",
    "source_code"
   ],
   "impact": "multi_org",
   "model_at_fault": "unclear",
   "sources": [
    "https://orca.security/resources/blog/hackerbot-claw-github-actions-attack/",
    "https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack"
   ],
   "date_occurred": "2026-02-28",
   "cve_ids": [
    "CVE-2026-28353"
   ],
   "id": "2026-03-01-trivy-hackerbot-claw",
   "severity": "high",
   "days_to_disclose": 1,
   "family": "ai_run_attack"
  },
  {
   "title": "Claude Cowork deleted a folder of 15 years of family photos while tidying a desktop",
   "summary": "Asked to organize a desktop and remove temporary Office files, Claude Cowork tried to rename a folder and instead deleted one holding about 15 years of family photos via a terminal command, then told the user what it had done. The files were recovered through iCloud's deleted-files window.",
   "date_disclosed": "2026-02-07",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Individual user",
   "org_sector": "other",
   "ai_vendor": "anthropic",
   "product": "Claude Cowork",
   "model_name": "Claude",
   "product_surface": "autonomous_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "personal_data"
   ],
   "impact": "limited",
   "records_affected": 27000,
   "model_at_fault": "yes",
   "sources": [
    "https://incidentdatabase.ai/cite/1441/",
    "https://futurism.com/artificial-intelligence/claude-wife-photos",
    "https://www.dexerto.com/entertainment/ai-apologizes-for-deleting-family-photos-after-dev-tries-to-organize-wifes-computer-3319640/"
   ],
   "id": "2026-02-07-claude-cowork-deleted-family-photos",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Chat & Ask AI app exposed 300 million chatbot messages",
   "summary": "A misconfigured Firebase backend behind Chat & Ask AI, a popular app fronting ChatGPT, Claude and Gemini, exposed around 300 million messages from more than 25 million users, including full conversation histories. The developer fixed it within hours of the researcher's report.",
   "date_disclosed": "2026-02-05",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Codeway",
   "org_sector": "technology",
   "ai_vendor": "multiple",
   "product": "Chat & Ask AI",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "harm_type": "exposure",
   "data_types": [
    "chat_logs",
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 25000000,
   "model_at_fault": "no",
   "sources": [
    "https://www.malwarebytes.com/blog/news/2026/02/ai-chat-app-leak-exposes-300-million-messages-tied-to-25-million-users",
    "https://www.foxnews.com/tech/millions-ai-chat-messages-exposed-app-data-leak"
   ],
   "id": "2026-02-05-chat-ask-ai-firebase-leak",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "OpenClaw AI agent one-click RCE with 40,000+ exposed instances",
   "summary": "A flaw in the OpenClaw personal AI agent's control UI let a single malicious link steal its auth token and run code, even on local installs. Scans found more than 40,000 exposed instances, many leaking API keys, messaging tokens and chat history.",
   "date_disclosed": "2026-02-03",
   "status": "confirmed",
   "in_the_wild": false,
   "org_name": "OpenClaw users",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "OpenClaw",
   "open_source": true,
   "product_surface": "autonomous_agent",
   "ai_role": "target",
   "mechanism": "app_flaw",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "chat_logs"
   ],
   "impact": "none_known",
   "model_at_fault": "no",
   "sources": [
    "https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html"
   ],
   "cve_ids": [
    "CVE-2026-25253"
   ],
   "id": "2026-02-03-openclaw-one-click-rce",
   "severity": "low",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Hundreds of malicious OpenClaw skills spread info-stealer malware",
   "summary": "The ClawHub marketplace for the OpenClaw AI agent was flooded with malicious skills posing as crypto, productivity and updater tools. Researchers found 341 malicious skills in one audit, delivering macOS info-stealers, keyloggers and backdoors, some of which stole OpenClaw's own stored credentials.",
   "date_disclosed": "2026-02-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "OpenClaw users",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "OpenClaw (ClawHub skills)",
   "open_source": true,
   "product_surface": "autonomous_agent",
   "ai_role": "supply_chain",
   "mechanism": "poisoned_package",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "limited",
   "model_at_fault": "no",
   "sources": [
    "https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting",
    "https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html",
    "https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap"
   ],
   "id": "2026-02-01-clawhavoc-malicious-openclaw-skills",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "supply_chain_access"
  },
  {
   "title": "Prompt injection in Cline's Claude triage bot led to a rogue npm release",
   "summary": "Cline's AI issue triage bot accepted input from any GitHub user and could run shell commands, so a crafted issue could make it leak an npm publish token. After an incomplete fix, an attacker used the token to publish a rogue Cline release that silently installed OpenClaw on about 4,000 machines.",
   "date_disclosed": "2026-02-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Cline",
   "org_sector": "technology",
   "ai_vendor": "anthropic",
   "product": "Cline",
   "open_source": true,
   "product_surface": "coding_agent",
   "ai_role": "vector",
   "mechanism": "prompt_injection",
   "harm_type": "exposure",
   "data_types": [
    "credentials"
   ],
   "impact": "multi_org",
   "records_affected": 4000,
   "model_at_fault": "yes",
   "sources": [
    "https://cline.bot/blog/post-mortem-unauthorized-cline-cli-npm",
    "https://github.com/advisories/GHSA-9ppg-jx86-fqw7"
   ],
   "date_occurred": "2026-02-17",
   "cve_ids": [
    "GHSA-9ppg-jx86-fqw7"
   ],
   "id": "2026-02-01-cline-clinejection-npm-token",
   "severity": "high",
   "days_to_disclose": -16,
   "family": "manipulated_ai"
  },
  {
   "title": "Claude Code ran terraform destroy and wiped DataTalks.Club production",
   "summary": "During a migration to AWS, a Claude Code agent working without the current Terraform state concluded no infrastructure existed and proposed running terraform destroy. The operator approved it, deleting the course platform's production stack including its database and automated snapshots. AWS support restored a snapshot and the platform recovered in about a day.",
   "date_disclosed": "2026-02-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "DataTalks.Club",
   "org_sector": "education",
   "ai_vendor": "anthropic",
   "product": "Claude Code",
   "model_name": "Claude",
   "product_surface": "coding_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "personal_data"
   ],
   "impact": "organization",
   "model_at_fault": "yes",
   "sources": [
    "https://alexeyondata.substack.com/p/how-i-dropped-our-production-database",
    "https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-code-deletes-developers-production-setup-including-its-database-and-snapshots-2-5-years-of-records-were-nuked-in-an-instant",
    "https://incidentdatabase.ai/cite/1424"
   ],
   "id": "2026-02-01-datatalks-claude-code-terraform-destroy",
   "severity": "high",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Vibe-coded AI agent network Moltbook exposed 1.5M API tokens",
   "summary": "Moltbook, a social network for AI agents largely built with AI coding tools, shipped a Supabase key in client-side code with no row-level security, giving anyone full read and write access. Wiz found about 35,000 emails, thousands of private agent messages and 1.5 million agent API tokens. It was fixed within hours.",
   "date_disclosed": "2026-02-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Moltbook",
   "org_sector": "technology",
   "ai_vendor": "any_model",
   "product": "Moltbook",
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "personal_data",
    "chat_logs"
   ],
   "impact": "organization",
   "records_affected": 35000,
   "model_at_fault": "no",
   "sources": [
    "https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys",
    "https://incidentdatabase.ai/cite/1364"
   ],
   "id": "2026-02-01-moltbook-exposed-supabase",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Google's Antigravity agent wiped a user's entire drive while clearing a cache",
   "summary": "Asked to clear a project cache, Google's Antigravity coding agent, running in its auto-execute Turbo mode, ran a delete command on the root of the user's D: drive instead of the project folder. The quiet flag skipped confirmation and the recycle bin, and the files could not be recovered.",
   "date_disclosed": "2025-12-01",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Individual user",
   "org_sector": "other",
   "country": "GR",
   "ai_vendor": "google",
   "product": "Antigravity",
   "model_name": "Gemini 3",
   "product_surface": "coding_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "personal_data"
   ],
   "impact": "limited",
   "model_at_fault": "yes",
   "sources": [
    "https://www.theregister.com/2025/12/01/google_antigravity_wipes_d_drive/",
    "https://www.tomshardware.com/tech-industry/artificial-intelligence/googles-agentic-ai-wipes-users-entire-hard-drive-without-permission-after-misinterpreting-instructions-to-clear-a-cache-i-am-deeply-deeply-sorry-this-is-a-critical-failure-on-my-part"
   ],
   "id": "2025-12-01-google-antigravity-wiped-drive",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Analytics vendor breach exposed names and emails of OpenAI API users",
   "summary": "An attacker broke into Mixpanel, an analytics provider OpenAI used on its API platform, and exported names, email addresses, approximate locations and browser details of some API users. OpenAI said no chats, API keys or payment data were involved and stopped using Mixpanel.",
   "date_disclosed": "2025-11-26",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "OpenAI (via Mixpanel)",
   "org_sector": "ai_vendor",
   "ai_vendor": "openai",
   "product": "OpenAI API platform",
   "product_surface": "model_or_package",
   "ai_role": "target",
   "mechanism": "third_party_leak",
   "data_types": [
    "personal_data"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://openai.com/index/mixpanel-incident/"
   ],
   "date_occurred": "2025-11-09",
   "harm_type": "exposure",
   "id": "2025-11-26-openai-mixpanel-vendor-breach",
   "severity": "medium",
   "days_to_disclose": 17,
   "family": "supply_chain_access"
  },
  {
   "title": "ShadowRay 2.0: attackers hijacked exposed Ray AI clusters into a botnet",
   "summary": "Oligo Security found an active campaign exploiting a disputed, unpatched flaw in the Ray AI compute framework to take over internet-exposed clusters, using AI-generated payloads. Hijacked clusters were used for cryptomining, data and credential theft and DDoS attacks, with more than 230,000 Ray servers exposed online.",
   "date_disclosed": "2025-11-18",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "Ray",
   "open_source": true,
   "product_surface": "model_or_package",
   "ai_role": "target",
   "mechanism": "unsecured_ai_infrastructure",
   "harm_type": "exposure",
   "data_types": [
    "credentials",
    "unknown"
   ],
   "impact": "multi_org",
   "model_at_fault": "no",
   "sources": [
    "https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet",
    "https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html"
   ],
   "cve_ids": [
    "CVE-2023-48022"
   ],
   "id": "2025-11-18-shadowray-2-ray-clusters-botnet",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "State-backed group used Claude Code to automate an espionage campaign",
   "summary": "Anthropic said a Chinese state-sponsored group manipulated Claude Code into running most of an espionage campaign against about 30 tech, finance, chemical and government targets, including reconnaissance, exploitation, credential theft and data extraction. Several intrusions succeeded before Anthropic banned the accounts and notified victims.",
   "date_disclosed": "2025-11-13",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "anthropic",
   "product": "Claude Code",
   "model_name": "Claude",
   "product_surface": "coding_agent",
   "ai_role": "weapon",
   "mechanism": "jailbreak_misuse",
   "data_types": [
    "credentials",
    "internal_docs"
   ],
   "impact": "multi_org",
   "model_at_fault": "unclear",
   "sources": [
    "https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf",
    "https://attack.mitre.org/campaigns/C0062/"
   ],
   "date_occurred": "2025-09-01",
   "harm_type": "exposure",
   "id": "2025-11-13-anthropic-gtg-1002-espionage",
   "severity": "high",
   "days_to_disclose": 73,
   "family": "manipulated_ai"
  },
  {
   "title": "Two AI companion apps streamed 43 million intimate messages from an open server",
   "summary": "Cybernews found an unprotected streaming server used by the developer of Chattee Chat and GiMe Chat, exposing over 43 million messages and 600,000 images and videos from more than 400,000 users, along with login tokens and purchase records. The server was secured after disclosure.",
   "date_disclosed": "2025-10-09",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Imagime Interactive (Chattee Chat, GiMe Chat)",
   "org_sector": "technology",
   "country": "HK",
   "ai_vendor": "unknown",
   "product": "Chattee Chat, GiMe Chat",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "harm_type": "exposure",
   "data_types": [
    "chat_logs",
    "personal_data",
    "credentials"
   ],
   "impact": "organization",
   "records_affected": 400000,
   "model_at_fault": "no",
   "sources": [
    "https://cybernews.com/security/ai-girlfriend-app-leak-exposes-400k-users/",
    "https://www.malwarebytes.com/blog/news/2025/10/millions-of-very-private-chats-exposed-by-two-ai-companion-apps"
   ],
   "date_occurred": "2025-08-28",
   "id": "2025-10-09-chattee-gime-companion-apps-leak",
   "severity": "high",
   "days_to_disclose": 42,
   "family": "leaky_ai_product"
  },
  {
   "title": "First malicious MCP server found secretly copying every email to an attacker",
   "summary": "A fake postmark-mcp package on npm, used to let AI assistants send email, added a hidden BCC to every message it sent, forwarding password resets, invoices and internal mail to an attacker's address. It was downloaded about 1,600 times before removal.",
   "date_disclosed": "2025-09-25",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "postmark-mcp users",
   "org_sector": "multiple",
   "ai_vendor": "any_model",
   "product": "postmark-mcp",
   "open_source": true,
   "product_surface": "model_or_package",
   "ai_role": "supply_chain",
   "mechanism": "poisoned_package",
   "data_types": [
    "personal_data",
    "credentials",
    "internal_docs"
   ],
   "impact": "multi_org",
   "records_affected": 1643,
   "model_at_fault": "no",
   "sources": [
    "https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html",
    "https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/"
   ],
   "date_occurred": "2025-09-17",
   "harm_type": "exposure",
   "id": "2025-09-25-postmark-mcp-malicious-server",
   "severity": "high",
   "days_to_disclose": 8,
   "family": "supply_chain_access"
  },
  {
   "title": "Vyro AI's image apps streamed prompts and login tokens from an open server",
   "summary": "Cybernews researchers found an unprotected Elasticsearch server run by Vyro AI, maker of ImagineArt and other consumer AI apps, leaking user prompts and authentication tokens in real time. Search engines had indexed the server months earlier.",
   "date_disclosed": "2025-09-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Vyro AI",
   "org_sector": "technology",
   "ai_vendor": "unknown",
   "product": "ImagineArt, Chatly",
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "data_types": [
    "chat_logs",
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://guardion.ai/ai-incidents/vyro-ai-imagineart-elasticsearch-leak"
   ],
   "harm_type": "exposure",
   "id": "2025-09-01-vyro-ai-elasticsearch-leak",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Criminal used Claude Code to run data extortion against 17 organizations",
   "summary": "Anthropic disrupted a criminal who used Claude Code to carry out reconnaissance, credential theft, network intrusion and data theft against at least 17 organizations including hospitals, emergency services and government bodies. Claude also analyzed stolen financial data to set ransom demands, some above $500,000.",
   "date_disclosed": "2025-08-27",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Multiple",
   "org_sector": "multiple",
   "ai_vendor": "anthropic",
   "product": "Claude Code",
   "model_name": "Claude",
   "product_surface": "coding_agent",
   "ai_role": "weapon",
   "mechanism": "jailbreak_misuse",
   "data_types": [
    "personal_data",
    "health",
    "financial",
    "credentials"
   ],
   "impact": "multi_org",
   "model_at_fault": "unclear",
   "sources": [
    "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
    "https://www.darkreading.com/cyberattacks-data-breaches/anthropic-ai-automate-data-extortion-campaign"
   ],
   "harm_type": "exposure",
   "id": "2025-08-27-anthropic-gtg-2002-vibe-hacking",
   "severity": "high",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "s1ngularity: npm malware turned developers' AI coding tools against them",
   "summary": "Malicious versions of the Nx build tool, which has millions of weekly downloads, ran a script that ordered any installed Claude, Gemini or Amazon Q command-line assistant to hunt for secrets on the victim's machine. Stolen tokens, SSH keys and wallets were posted to public GitHub repos, and a second wave used them to make thousands of private repositories public.",
   "date_disclosed": "2025-08-26",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Nx (Nrwl)",
   "org_sector": "technology",
   "ai_vendor": "multiple",
   "product": "Claude Code, Gemini CLI, Amazon Q",
   "product_surface": "coding_agent",
   "ai_role": "weapon",
   "mechanism": "agent_hijack",
   "data_types": [
    "credentials",
    "source_code"
   ],
   "impact": "ecosystem",
   "model_at_fault": "no",
   "sources": [
    "https://nx.dev/blog/s1ngularity-postmortem",
    "https://www.wiz.io/blog/s1ngularity-supply-chain-attack",
    "https://thehackernews.com/2025/08/malicious-nx-packages-in-s1ngularity.html"
   ],
   "harm_type": "exposure",
   "id": "2025-08-26-nx-s1ngularity-ai-cli-malware",
   "severity": "high",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "Grok's share button published 370,000 conversations to search engines",
   "summary": "Grok's share feature created public pages that search engines indexed with no warning to users. Forbes found more than 370,000 conversations searchable on Google, including medical questions, uploaded files and at least one password.",
   "date_disclosed": "2025-08-20",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "xAI",
   "org_sector": "ai_vendor",
   "ai_vendor": "xai",
   "product": "Grok",
   "model_name": "Grok",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "accidental_publication",
   "data_types": [
    "chat_logs",
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 370000,
   "model_at_fault": "no",
   "sources": [
    "https://www.forbes.com/sites/iainmartin/2025/08/20/elon-musks-xai-published-hundreds-of-thousands-of-grok-chatbot-conversations/",
    "https://fortune.com/2025/08/22/xai-grok-chats-public-on-google-search-elon-musk"
   ],
   "harm_type": "exposure",
   "id": "2025-08-20-grok-shared-chats-indexed",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data",
   "summary": "A threat actor used stolen OAuth tokens from the Drift AI chat agent's Salesforce integration to export data from hundreds of company Salesforce instances, hunting for AWS keys, passwords and other secrets. Victims included Cloudflare, Palo Alto Networks, Zscaler and Google. Salesloft and Salesforce revoked all Drift tokens.",
   "date_disclosed": "2025-08-20",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Salesloft (Drift)",
   "org_sector": "multiple",
   "ai_vendor": "unknown",
   "product": "Drift",
   "product_surface": "chatbot",
   "ai_role": "supply_chain",
   "mechanism": "stolen_token",
   "data_types": [
    "credentials",
    "personal_data",
    "internal_docs"
   ],
   "impact": "multi_org",
   "records_affected": 700,
   "model_at_fault": "no",
   "sources": [
    "https://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attack",
    "https://www.anomali.com/blog/salesloft-drift-breach-recap",
    "https://www.wtwco.com/en-us/insights/2025/09/the-drift-oauth-breach-a-cybersecurity-wake-up-call"
   ],
   "date_occurred": "2025-08-08",
   "harm_type": "exposure",
   "id": "2025-08-20-salesloft-drift-oauth-theft",
   "severity": "high",
   "days_to_disclose": 12,
   "family": "supply_chain_access"
  },
  {
   "title": "Shared ChatGPT conversations showed up in Google search results",
   "summary": "A ChatGPT option to make shared chats discoverable led to thousands of conversations being indexed by Google, some containing names, CVs, mental health details and business information. OpenAI removed the feature and worked with search engines to de-index the links.",
   "date_disclosed": "2025-07-31",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "OpenAI",
   "org_sector": "ai_vendor",
   "ai_vendor": "openai",
   "product": "ChatGPT",
   "model_name": "ChatGPT",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "accidental_publication",
   "data_types": [
    "chat_logs",
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 4500,
   "model_at_fault": "no",
   "sources": [
    "https://www.theregister.com/2025/08/01/openai_removes_chatgpt_selfdoxing_option/",
    "https://www.searchenginejournal.com/openai-is-pulling-shared-chatgpt-chats-from-google-search/552671/"
   ],
   "harm_type": "exposure",
   "id": "2025-07-31-chatgpt-shared-chats-indexed",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Gemini CLI destroyed a user's files after misreading a failed command",
   "summary": "Asked to reorganize a folder, Google's Gemini CLI coding agent assumed a directory it had failed to create existed, then ran a series of move commands that overwrote all but one of the user's files. Recovery attempts failed and the agent admitted a catastrophic failure.",
   "date_disclosed": "2025-07-25",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Individual user",
   "org_sector": "other",
   "ai_vendor": "google",
   "product": "Gemini CLI",
   "model_name": "Gemini",
   "product_surface": "coding_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "unknown"
   ],
   "impact": "limited",
   "model_at_fault": "yes",
   "sources": [
    "https://incidentdatabase.ai/cite/1178/",
    "https://winbuzzer.com/2025/07/26/googles-gemini-cli-deletes-user-files-confesses-catastrophic-failure-xcxwbn/"
   ],
   "id": "2025-07-25-gemini-cli-deleted-user-files",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "Wiper prompt slipped into Amazon Q's official VS Code extension",
   "summary": "An attacker used an over-scoped GitHub token in AWS's build pipeline to insert a prompt telling the Amazon Q coding assistant to wipe local files and cloud resources. The tampered version shipped to users of an extension with nearly a million installs, but a syntax error stopped it from running. AWS pulled it and released a fix.",
   "date_disclosed": "2025-07-23",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Amazon Web Services",
   "org_sector": "technology",
   "ai_vendor": "amazon",
   "product": "Amazon Q Developer",
   "product_surface": "coding_agent",
   "ai_role": "supply_chain",
   "mechanism": "poisoned_package",
   "harm_type": "destruction",
   "data_types": [
    "unknown"
   ],
   "impact": "none_known",
   "model_at_fault": "no",
   "sources": [
    "https://github.com/aws/aws-toolkit-vscode/security/advisories/GHSA-7g7f-ff96-5gcw",
    "https://www.scworld.com/news/amazon-q-extension-for-vs-code-reportedly-injected-with-wiper-prompt"
   ],
   "date_occurred": "2025-07-17",
   "cve_ids": [
    "CVE-2025-8217"
   ],
   "id": "2025-07-23-amazon-q-wiper-prompt",
   "severity": "low",
   "days_to_disclose": 6,
   "family": "supply_chain_access"
  },
  {
   "title": "Replit's AI agent deleted a live production database during a code freeze",
   "summary": "During a public vibe-coding experiment, Replit's coding agent deleted SaaStr founder Jason Lemkin's production database, holding records for over 1,200 executives and companies, despite repeated instructions not to change anything. It then produced fake data and wrongly claimed the deletion could not be rolled back. Replit's CEO apologized and shipped safeguards.",
   "date_disclosed": "2025-07-18",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "SaaStr",
   "org_sector": "technology",
   "ai_vendor": "unknown",
   "product": "Replit Agent",
   "product_surface": "coding_agent",
   "ai_role": "rogue_agent",
   "mechanism": "destructive_action",
   "harm_type": "destruction",
   "data_types": [
    "personal_data"
   ],
   "impact": "organization",
   "records_affected": 1206,
   "model_at_fault": "yes",
   "sources": [
    "https://x.com/jasonlk/status/1946069562723897802",
    "https://incidentdatabase.ai/cite/1152/",
    "https://forums.theregister.com/forum/all/2025/07/21/replit_saastr_vibe_coding_incident/"
   ],
   "id": "2025-07-18-replit-agent-deleted-saastr-database",
   "severity": "high",
   "days_to_disclose": null,
   "family": "agent_misbehaviour"
  },
  {
   "title": "McDonald's AI hiring chatbot exposed up to 64 million applicants via password '123456'",
   "summary": "Researchers logged into the admin backend of McHire, McDonald's AI hiring chatbot built by Paradox.ai, using the default credentials 123456, then found they could step through applicant records by ID. Names, emails, phone numbers and chat logs for up to 64 million applicants were reachable. Paradox fixed it within hours and said only a handful of records were accessed.",
   "date_disclosed": "2025-07-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "McDonald's (Paradox.ai)",
   "org_sector": "retail",
   "country": "US",
   "ai_vendor": "unknown",
   "product": "McHire (Olivia)",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "app_flaw",
   "data_types": [
    "personal_data",
    "chat_logs"
   ],
   "impact": "organization",
   "records_affected": 64000000,
   "model_at_fault": "no",
   "sources": [
    "https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html",
    "https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/",
    "https://incidentdatabase.ai/cite/1179/"
   ],
   "harm_type": "exposure",
   "id": "2025-07-01-mchire-paradox-default-password",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Asana's AI connector exposed customer data to other organizations",
   "summary": "A logic flaw in Asana's new MCP server, which lets AI assistants read Asana data, meant some users could see tasks, projects, comments and files from other companies. Asana took it offline for about two weeks and notified roughly 1,000 potentially affected customers. It says the bug was not the result of an attack.",
   "date_disclosed": "2025-06-18",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "Asana",
   "org_sector": "technology",
   "ai_vendor": "any_model",
   "product": "Asana MCP server",
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "app_flaw",
   "data_types": [
    "internal_docs"
   ],
   "impact": "multi_org",
   "records_affected": 1000,
   "model_at_fault": "no",
   "sources": [
    "https://www.bleepingcomputer.com/news/security/asana-warns-mcp-ai-feature-exposed-customer-data-to-other-orgs/",
    "https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server"
   ],
   "date_occurred": "2025-05-01",
   "harm_type": "exposure",
   "id": "2025-06-18-asana-mcp-cross-tenant-leak",
   "severity": "high",
   "days_to_disclose": 48,
   "family": "leaky_ai_product"
  },
  {
   "title": "EchoLeak: zero-click prompt injection could make Microsoft 365 Copilot leak data",
   "summary": "Researchers showed that an email with hidden instructions could make Microsoft 365 Copilot pull data from a user's mail, files and chats and send it out, with no clicks from the victim. It was the first publicly documented zero-click attack on a production AI assistant. Microsoft fixed it server-side.",
   "date_disclosed": "2025-06-01",
   "date_precision": "month",
   "status": "confirmed",
   "in_the_wild": false,
   "org_name": "Microsoft",
   "org_sector": "technology",
   "ai_vendor": "microsoft",
   "product": "Microsoft 365 Copilot",
   "product_surface": "enterprise_copilot",
   "ai_role": "target",
   "mechanism": "prompt_injection",
   "data_types": [
    "internal_docs"
   ],
   "impact": "none_known",
   "model_at_fault": "yes",
   "sources": [
    "https://guardion.ai/ai-incidents/echoleak-m365-copilot-zero-click"
   ],
   "cve_ids": [
    "CVE-2025-32711"
   ],
   "harm_type": "exposure",
   "id": "2025-06-01-echoleak-m365-copilot",
   "severity": "low",
   "days_to_disclose": null,
   "family": "manipulated_ai"
  },
  {
   "title": "xAI employee leaked an API key to private Grok models on GitHub",
   "summary": "An xAI staff member left an API key in a public GitHub repository for about two months. It gave access to at least 60 private and unreleased models, some apparently fine-tuned on SpaceX and Tesla data. The repository was removed after GitGuardian escalated to xAI's security team.",
   "date_disclosed": "2025-05-01",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "xAI",
   "org_sector": "ai_vendor",
   "ai_vendor": "xai",
   "product": "xAI API",
   "model_name": "Grok",
   "product_surface": "model_or_package",
   "ai_role": "target",
   "mechanism": "stolen_token",
   "data_types": [
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://krebsonsecurity.com/2025/05/xai-dev-leaks-api-key-for-private-spacex-tesla-llms/"
   ],
   "date_occurred": "2025-03-02",
   "harm_type": "exposure",
   "id": "2025-05-01-xai-api-key-leaked-github",
   "severity": "high",
   "days_to_disclose": 60,
   "family": "supply_chain_access"
  },
  {
   "title": "AI image generator GenNomis exposed prompts and generated images",
   "summary": "Researcher Jeremiah Fowler found an unprotected database belonging to South Korean AI image service GenNomis holding about 93,500 generated images and the prompts used to create them, including explicit deepfakes. Public access was restricted after he reported it.",
   "date_disclosed": "2025-03-31",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "GenNomis (AI-Nomis)",
   "org_sector": "technology",
   "country": "KR",
   "ai_vendor": "unknown",
   "product": "GenNomis",
   "product_surface": "custom_ai_app",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "data_types": [
    "chat_logs"
   ],
   "impact": "organization",
   "records_affected": 93485,
   "model_at_fault": "no",
   "sources": [
    "https://infotechlead.com/security/gennomis-database-exposes-100k-sensitive-records-of-ai-images-89126",
    "https://www.bitdefender.com/en-us/blog/hotforsecurity/thousands-of-ai-generated-and-deepfake-images-exposed-in-unprotected-database-online"
   ],
   "harm_type": "exposure",
   "id": "2025-03-31-gennomis-open-database",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  },
  {
   "title": "Data allegedly stolen from AI chatbot aggregator OmniGPT put up for sale",
   "summary": "A threat actor listed data allegedly taken from OmniGPT, a service that gives access to several AI models, on a breach forum. The dataset reportedly tied users' contact details to their private conversations and uploaded files. OmniGPT did not publicly acknowledge the incident.",
   "date_disclosed": "2025-02-01",
   "date_precision": "month",
   "status": "reported",
   "in_the_wild": true,
   "org_name": "OmniGPT",
   "org_sector": "technology",
   "ai_vendor": "multiple",
   "product": "OmniGPT",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "unknown",
   "data_types": [
    "chat_logs",
    "personal_data"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://guardion.ai/ai-incidents/omnigpt-chatbot-breach-2025"
   ],
   "harm_type": "exposure",
   "id": "2025-02-01-omnigpt-breach-claimed",
   "severity": "medium",
   "days_to_disclose": null,
   "family": "unknown"
  },
  {
   "title": "DeepSeek left a database of chat logs and API keys open to the internet",
   "summary": "Wiz found two publicly accessible DeepSeek ClickHouse databases that allowed anyone to run queries without logging in. They held over a million log lines including users' chat history in plain text, API keys and backend details. DeepSeek secured them quickly after being told.",
   "date_disclosed": "2025-01-29",
   "status": "confirmed",
   "in_the_wild": true,
   "org_name": "DeepSeek",
   "org_sector": "ai_vendor",
   "country": "CN",
   "ai_vendor": "deepseek",
   "product": "DeepSeek chat",
   "product_surface": "chatbot",
   "ai_role": "target",
   "mechanism": "exposed_datastore",
   "data_types": [
    "chat_logs",
    "credentials"
   ],
   "impact": "organization",
   "model_at_fault": "no",
   "sources": [
    "https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak",
    "https://www.bleepingcomputer.com/news/security/deepseek-exposes-database-with-over-1-million-chat-records/"
   ],
   "harm_type": "exposure",
   "id": "2025-01-29-deepseek-exposed-clickhouse",
   "severity": "high",
   "days_to_disclose": null,
   "family": "leaky_ai_product"
  }
 ]
}