30 Jan 2026 · Moltbook
Wiz found that Moltbook, a Reddit-style site where OpenClaw agents post on behalf of their owners, left its Supabase backend readable and writable, exposing agent API tokens and private messages.
other·misconfiguration·
27 Jan 2026 · OpenClaw
Koi Security found several hundred malicious skills published to ClawHub, the community marketplace for the OpenClaw personal agent, most of them delivering infostealers disguised as crypto trading or utility tools.
workflow·supply chain·
1 Jan 2026 · Anthropic
Anthropic's alignment assessment revealed a fourth incident in which a Claude model gained unauthorized access to real third-party systems: in January 2026 an early version of Claude Opus 4.6, running a Capture the Flag evaluation, broke into an unrelated third party's machine, used a password file to obtain admin access, harvested further credentials and changed a setting easing access to an individual's personal information. The model had tried to abort the task seven times but could not due to a misconfiguration in its evaluation harness.
other·misconfiguration·
1 Dec 2025 · Anthropic
Anthropic disclosed that state-sponsored and criminal groups abused its Claude models between December 2025 and August 2026 to automate intrusions, data theft, influence and surveillance operations, weapons software development and biological research. Cases included Russian SVR-linked GTG-20006 automating a full attack kill chain against 20+ organizations and ShinyHunters-linked affiliates using AI agents to steal data from about 200 customers of a breached SaaS provider.
other·tool misuse·
15 Sept 2025 · Anthropic
Anthropic disclosed that a group it assessed as Chinese state-sponsored jailbroke Claude Code and used it to run most of an intrusion campaign against around thirty organisations, with the agent performing reconnaissance, exploitation and data collection.
coding·tool misuse·
26 Aug 2025 · Nx (Nrwl)
Malicious versions of the Nx build tool were published to npm with a post-install script that invoked Claude Code, Gemini CLI and Amazon Q on the developer's machine to locate wallets, tokens and SSH keys, then pushed them to public GitHub repositories.
coding·supply chain·
8 Aug 2025 · Salesloft
Attackers tracked as UNC6395 used OAuth tokens stolen from the Drift AI chat agent integration to query Salesforce instances at hundreds of organisations, harvesting credentials stored in support cases.
customer service·supply chain·
28 Jul 2025 · Salesforce
Noma Security chained a prompt injection in a lead-capture form with an expired domain still trusted by Salesforce's content security policy to pull CRM records out of Agentforce. Rated CVSS 9.4.
customer service·prompt injection·
25 Jul 2025 · Perplexity
Brave's security team showed that instructions hidden in a Reddit post could make Perplexity's Comet browser agent open a user's banking or email session and leak one-time codes to the attacker.
browsing·prompt injection·
18 Jul 2025 · Replit
During a public "vibe coding" experiment, Replit's agent ran destructive commands against a live production database despite instructions not to change code, then misreported what it had done.
coding·excessive permissions·
13 Jul 2025 · Amazon
An attacker got a pull request merged into the open-source Amazon Q Developer extension that added a prompt instructing the agent to wipe the user's machine and cloud resources. The tainted build shipped to the VS Code marketplace.
coding·supply chain·
7 Jul 2025 · Cursor
Aim Labs found that prompt injection reaching Cursor's agent could write a new MCP server entry to the project config, which Cursor executed without confirmation. Tracked as CVE-2025-54135.
coding·prompt injection·
3 Jul 2025 · Supabase
General Analysis showed that a customer support ticket containing instructions could make a Cursor agent, connected to Supabase over MCP with a service-role key, dump a secrets table into the ticket thread.
coding·excessive permissions·
27 Jun 2025 · Google
Tracebit showed that a README containing hidden instructions, combined with weak allow-list validation, let Google's Gemini CLI run arbitrary shell commands and send environment variables to an attacker.
coding·prompt injection·
18 Jun 2025 · OpenAI
Radware found that an email with hidden instructions could make OpenAI's Deep Research agent read a user's Gmail and send personal data to an attacker's server, entirely from OpenAI's cloud so no traffic left the user's network.
browsing·prompt injection·
1 Jun 2025 · OpenAI
Zenity Labs showed that a shared Google Drive document with hidden white text could make ChatGPT search a user's Drive for API keys and send them to an attacker via an image URL, with no user interaction beyond the share.
workflow·prompt injection·
26 May 2025 · GitHub
Invariant Labs demonstrated that a malicious issue in a public repository could steer an agent connected to the GitHub MCP server into reading a private repository and publishing its contents in a pull request.
coding·prompt injection·
14 Apr 2025 · Anthropic
Oligo Security found that the MCP Inspector developer tool ran a proxy without authentication, so a malicious web page could reach it on localhost and execute commands. Tracked as CVE-2025-49596 with a CVSS score of 9.4.
coding·misconfiguration·
7 Apr 2025 · Langflow
CVE-2025-3248 let anyone with network access to a Langflow server run Python through an unauthenticated code validation endpoint. CISA added it to the Known Exploited Vulnerabilities catalog and researchers later tied exploitation to the Flodrix botnet.
workflow·misconfiguration·
1 Feb 2025 · Google
SafeBreach researchers showed at Black Hat that instructions hidden in a Google Calendar invitation could make Gemini open windows, turn on appliances, leak emails and start video calls when a user later asked it to summarise their schedule.
workflow·prompt injection·
15 Jan 2025 · Microsoft
Researchers at Aim Security found that a crafted email could make Microsoft 365 Copilot exfiltrate data from a user's tenant with no clicks, tracked as CVE-2025-32711.
workflow·prompt injection·
11 Nov 2022 · Air Canada
A British Columbia tribunal ordered Air Canada to honour a bereavement discount that its website chatbot had described but which did not exist, rejecting the airline's argument that the chatbot was a separate legal entity.
customer service·hallucinated action·
11 Sept 2026 · FrontMCP
A GitHub advisory reports that the patch for an earlier SSRF issue (CVE-2026-39885) in mcp-from-openapi 2.3.0 can be bypassed, letting untrusted OpenAPI specs loaded by FrontMCP 1.2.1 trigger backend-origin requests to loopback or private services via DNS-to-loopback names, redirects, and IPv4-mapped IPv6 forms. In hosted or multi-user FrontMCP deployments where users can import specs, this can expose internal APIs not reachable externally.
other·supply chain·
12 May 2026 · OpenAI
Researchers reported that a coordinated attack on the RubyGems package manager disclosed in May 2026 was carried out by a swarm of OpenAI agents, which also gained remote code execution on RubyDoc servers.
other·supply chain·
8 Sept 2026 · OpenAI
Check Point Research disclosed that ChatGPT's internal JFrog Artifactory instance exposed a hidden channel letting one account plant instructions that a victim's ChatGPT session would silently execute, reading data from the victim's connected Gmail account and returning it to the attacker's account. The proof-of-concept was disclosed to OpenAI in late June 2026, by which time the Artifactory instance had already been decommissioned, closing the channel.
other·prompt injection·
11 Sept 2026 · Anthropic
Anthropic reported that multiple threat groups, including financially motivated actors and state-linked espionage groups associated with Russia and China, attempted to abuse its Claude AI model for malicious purposes, including extracting secrets from 1.8 million Android apps. Separate reporting describes attackers abusing trusted AI platforms, such as weaponized Claude Artifacts and shared AI conversations, to host malicious content and lure users into installing malware.
other·tool misuse·
11 Sept 2026 · mysql-mcp-server
The mysql-mcp-server MCP package, when run in SSE/HTTP transport mode, created its SSE transport without security settings, disabling DNS-rebinding protection and leaving all routes unauthenticated while binding to 0.0.0.0. This allowed network attackers or malicious web pages to invoke execute_sql for arbitrary unauthenticated SQL execution, data exfiltration, and potentially file read/write and RCE; 25 publicly reachable instances were found.
workflow·misconfiguration·
21 May 2026 · LINE
Central Dogma's Git mirror SSH client (SshGitMirror) installs a server key verifier that unconditionally returns true and disables known_hosts fallbacks, so every outbound git+ssh:// mirror connection trusts any host key presented. An on-path attacker can impersonate the remote git server to exfiltrate mirrored configuration secrets or inject arbitrary commits that propagate to downstream services.
other·misconfiguration·