Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

10

agent security incidents recorded in 2026

Browse the incident database →

28 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
30 Jan 2026Moltbook, a social network for AI agents, exposes its database and agent tokensMoltbookothermisconfigurationresolved
27 Jan 2026Hundreds of malicious skills found on the OpenClaw skill marketplaceOpenClawworkflowsupply chainresolved
1 Jan 2026Anthropic discloses fourth case of Claude accessing third-party systems without authorizationAnthropicothermisconfigurationconfirmed
1 Dec 2025Anthropic reports threat actors abusing Claude for cyberattacks, weapons and surveillanceAnthropicothertool misuseconfirmed
15 Sept 2025State-sponsored group uses Claude Code to automate an espionage campaignAnthropiccodingtool misuseconfirmed
26 Aug 2025s1ngularity: compromised Nx packages use AI coding agents to steal credentialsNx (Nrwl)codingsupply chainresolved
8 Aug 2025Stolen Salesloft Drift tokens used to pull Salesforce data from hundreds of companiesSalesloftcustomer servicesupply chainresolved
28 Jul 2025ForcedLeak: Salesforce Agentforce leaks CRM data through a Web-to-Lead formSalesforcecustomer serviceprompt injectionresolved
25 Jul 2025Perplexity Comet browser agent hijacked by text on a web pagePerplexitybrowsingprompt injectionresolved
18 Jul 2025Replit coding agent deletes a production database during a code freezeReplitcodingexcessive permissionsresolved
13 Jul 2025Malicious prompt planted in Amazon Q Developer VS Code extensionAmazoncodingsupply chainresolved
7 Jul 2025CurXecute: Cursor agent turned into remote code execution via MCP configCursorcodingprompt injectionresolved
3 Jul 2025Supabase MCP server with service-role key leaks SQL data to a support ticketSupabasecodingexcessive permissionsresolved
27 Jun 2025Gemini CLI tricked into silent command execution and data exfiltrationGooglecodingprompt injectionresolved
18 Jun 2025ShadowLeak: zero-click data theft through ChatGPT Deep Research and GmailOpenAIbrowsingprompt injectionresolved
1 Jun 2025AgentFlayer: poisoned document leaks API keys through ChatGPT ConnectorsOpenAIworkflowprompt injectionresolved
26 May 2025GitHub MCP server leaks private repository data via a public issueGitHubcodingprompt injectionconfirmed
14 Apr 2025Anthropic MCP Inspector exposed developers to browser-based remote code executionAnthropiccodingmisconfigurationresolved
7 Apr 2025Langflow code-validation endpoint gives unauthenticated remote code executionLangflowworkflowmisconfigurationresolved
1 Feb 2025Calendar invite hijacks Gemini to control smart home devicesGoogleworkflowprompt injectionresolved
15 Jan 2025EchoLeak: zero-click prompt injection in Microsoft 365 CopilotMicrosoftworkflowprompt injectionresolved
11 Nov 2022Air Canada held liable for refund policy invented by its chatbotAir Canadacustomer servicehallucinated actionresolved
11 Sept 2026CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handlingFrontMCPothersupply chainconfirmed
12 May 2026OpenAI agent swarm tied to May 2026 RubyGems supply chain attackOpenAIothersupply chainconfirmed
8 Sept 2026Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theftOpenAIotherprompt injectionresolved
11 Sept 2026Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android appsAnthropicothertool misuseconfirmed
11 Sept 2026MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971)mysql-mcp-serverworkflowmisconfigurationresolved
21 May 2026Central Dogma Git mirror disables SSH host-key verification (CVE-2026-11745)LINEothermisconfigurationconfirmed

Latest incident reports