An open API service indexing awesome lists of open source software.

awesome-ai-agent-attacks

A curated timeline of real AI agent security incidents, breaches, and vulnerabilities (2024-2026). Every entry sourced and dated.
https://github.com/webpro255/awesome-ai-agent-attacks

Last synced: 10 days ago
JSON representation

  • 2024 Incidents

    • 2024-01-18 - DPD AI Chatbot Malfunction

    • 2024-02-14 - Air Canada Chatbot Lawsuit Ruling

      • CBC - law-today/2024-february/bc-tribunal-confirms-companies-remain-liable-information-provided-ai-chatbot/)
    • 2024-02 - PoisonedRAG Research

    • 2024-03 - ChatGPT Plugin/Extension Vulnerabilities

    • 2024-03 - OpenAI Compromised Credentials on Dark Web

      • The Hacker News - credentials-stolen-by-the-thousands-for-sale-on-the-dark-web/)
    • 2024-04-02 - Many-Shot Jailbreaking Research

    • 2024-04 - Hugging Face Cross-Tenant Attack

      • Wiz - security/critical-bugs-hugging-face-ai-platform-pickle)
    • 2024-05 - GitHub Copilot Training Data Secret Leakage

    • 2024-06-25 - Rabbit R1 Hardcoded API Keys

    • 2024-06 - Hugging Face Spaces Breach

    • 2024-06 - McDonald's Ends AI Drive-Thru After Failures

    • 2024-07 - ChatGPT macOS Cleartext Storage

    • 2024-07 - Grok AI Election Misinformation

      • Axios - of-state-urge-x-to-stop-its-grok-chatbot-from-spreading-election-misinformation/)
    • 2024-07 - Microsoft 365 Copilot ASCII Smuggling

    • 2024-08-06 - Microsoft Copilot Studio SSRF

      • Tenable - patches-critical-copilot.html)
    • 2024-08-08 - LOLCopilot - Black Hat USA 2024 Copilot Attacks

    • 2024-08-20 - Slack AI Prompt Injection and Data Exfiltration

      • PromptArmor - data-breaches/slack-ai-patches-bug-that-let-attackers-steal-data-from-private-channels)
    • 2024-09-25 - NVIDIA Container Toolkit Vulnerability

    • 2024-09 - ChatGPT "SpAIware" Persistent Memory Exploitation

    • 2024-10-17 - Imprompter Attack on AI Chatbots

    • 2024-10-22 - Claude Computer Use Launch Security Warnings

    • 2024-11-22 - Freysa AI Agent Game - Function Manipulation

    • 2024-11 - Microsoft Copilot Exposes Private GitHub Repos

      • Lasso Security - copilot-chat-flaw-leaked-data-from-private-repositories/)
    • 2024-11 - Microsoft Copilot Studio XSS

    • 2024-12-04 - Ultralytics PyPI Supply Chain Attack

      • PyPI Blog - ai-library-hacked-via-github-for-cryptomining), [Snyk](https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/)
    • 2024 - LangChain Arbitrary Code Execution

      • NVD - PYTHON-LANGCHAINEXPERIMENTAL-7278171)
    • 2024 - LangChain Code Execution via LLMSymbolicMathChain

    • 2024 - LangChain GraphCypherQAChain Injection

  • 2025 Incidents

    • 2025-01-24 - OmniGPT Data Breach

      • Hackread - allegedly-puts-massive-omnigpt-breach-data-for-sale-on-the-dark-web.html)
    • 2025-02-21 - Bybit $1.5B Cryptocurrency Heist

      • FBI IC3 - korea-bybit-hack-ethereum-safe-dprk-lazarus-group-tradertraitor/), [TRM Labs](https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit)
    • 2025-02 - Google Gemini Prompt Injection via Calendar Invites

      • The Register - security/google-gemini-flaw-calendar-invites-attack-vector), [Miggo](https://www.miggo.io/post/weaponizing-calendar-invites-a-semantic-attack-on-google-gemini)
      • The Register - security/google-gemini-flaw-calendar-invites-attack-vector), [Miggo](https://www.miggo.io/post/weaponizing-calendar-invites-a-semantic-attack-on-google-gemini)
    • 2025-03-15 - tj-actions/changed-files GitHub Actions Supply Chain Attack

      • CISA - action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066), [Unit 42](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/)
    • 2025-03-18 - Rules File Backdoor Attack on Cursor and Copilot

    • 2025-04 - MCP Tool Poisoning / WhatsApp Data Exfiltration

      • Invariant Labs - horror-stories-whatsapp-data-exfiltration-issue/), [Simon Willison](https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/)
    • 2025-05 - ElizaOS Memory Injection Vulnerability

    • 2025-05 - Langflow CISA KEV Addition - Confirmed Active Exploitation

      • The Hacker News - research/cve-2025-3248-rce-vulnerability-langflow), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-3248)
    • 2025-06 - Anthropic Filesystem MCP Server "EscapeRoute"

      • Cymulate - mcp-server-flaws-lead-to-code-execution-data-exposure/)
    • 2025-06 - EchoLeak - Microsoft 365 Copilot Zero-Click Prompt Injection

    • 2025-06 - GitHub Copilot CamoLeak

      • Legit Security - security/github-copilot-camoleak-ai-attack-exfils-data)
    • 2025-06 - Langflow Flodrix Botnet Exploitation

      • Trend Micro - langflow-vulnerability-exploited-by-flodrix-botnet/), [Dark Reading](https://www.darkreading.com/vulnerabilities-threats/hackers-exploit-langflow-flaw-flodrix-botnet)
    • 2025-07-09 - Hugging Face Poisoned GGUF Templates

    • 2025-07-17 - Amazon Q VS Code Extension Compromise

      • AWS-2025-015 - inserts-destructive-code-in-amazon-q-as-update-goes-live.html)
    • 2025-07 - mcp-remote Critical RCE

      • JFrog - mcp-remote-vulnerability.html)
    • 2025-08-20 - Salesloft Drift OAuth Supply Chain Breach

      • Google Cloud Blog - takes-drift-offline-after.html), [Cloudflare Blog](https://blog.cloudflare.com/response-to-salesloft-drift-incident/)
    • 2025-08 - Claude Code InversePrompt Command Injection

      • Cymulate - code/security/advisories/GHSA-x56v-x2h6-7j34)
    • 2025-08 - Claude Code WebSocket Auth Bypass

    • 2025-08 - Cursor CurXecute RCE via Slack MCP

    • 2025-08 - Cursor MCPoison Silent Backdoor

    • 2025-08 - GitHub Copilot RCE via Prompt Injection

    • 2025-08 - OpenAI Codex CLI Command Injection

      • SecurityWeek - codex-cli-command-injection-vulnerability/)
    • 2025-08 - Varonis "Reprompt" - Microsoft Copilot Single-Click Data Theft

      • Varonis - reprompt-attack-silently-siphons-microsoft-copilot-data/)
    • 2025-09 - Salesforce Agentforce "ForcedLeak"

      • Noma Security - patches-critical-forcedleak.html), [The Register](https://www.theregister.com/2025/09/26/salesforce_agentforce_forceleak_attack/)
    • 2025-11-04 - GitHub Copilot Filename Prompt Injection

    • 2025-11-13 - GTG-1002 Chinese State-Sponsored AI-Orchestrated Espionage

      • Anthropic report (PDF) - state-actor-ai-tool-espionage/805550/), [The Hacker News](https://thehackernews.com/2025/11/chinese-hackers-use-anthropics-ai-to.html), [The Register](https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/), [BlackFog](https://www.blackfog.com/gtg-1002-claude-hijacked-first-ai-led-cyberattack/), [ExtraHop](https://www.extrahop.com/blog/anthropic-reveals-the-first-ai-orchestrated-cyber-espionage-campaign), [AI Incident Database](https://incidentdatabase.ai/cite/1263/)
      • Anthropic report (PDF) - state-actor-ai-tool-espionage/805550/), [The Hacker News](https://thehackernews.com/2025/11/chinese-hackers-use-anthropics-ai-to.html), [The Register](https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/), [BlackFog](https://www.blackfog.com/gtg-1002-claude-hijacked-first-ai-led-cyberattack/), [ExtraHop](https://www.extrahop.com/blog/anthropic-reveals-the-first-ai-orchestrated-cyber-espionage-campaign), [AI Incident Database](https://incidentdatabase.ai/cite/1263/)
    • 2025-11 - Claude Desktop Extensions RCE

      • Koi AI - dxt-poses-critical-rce-vulnerability-by-running-with-full-system-privileges.html)
    • 2025-11 - CrewAI "Uncrew" GitHub Token Exposure

      • Noma Security - github-token-exposure-highlights-the-growing-risk-of-static-credentials-in-ai-systems/)
    • 2025-11 - ServiceNow Now Assist Second-Order Prompt Injection

    • 2025-12 - Copilot Studio Prompt Injection Data Leak

      • Tenable - copilot-studio-security-risk-how-simple-prompt-injection-leaked-credit-cards-and-booked-a-0-trip/)
    • 2025-12 - IDEsaster - 30+ Flaws Across AI Coding Tools

    • 2025-12 - LangChain "LangGrinch" Serialization Injection

      • Cyata - langchain-core-vulnerability.html), [Orca Security](https://orca.security/resources/blog/cve-2025-68664-langchain-serialization-flaw/)
    • 2025 - Cursor Case Sensitivity Bypass

    • 2025 - DB-GPT Plugin Upload RCE

    • 2025 - GitHub Copilot RoguePilot Repository Takeover

      • Orca Security - issues-abused-in-copilot-attack-leading-to-repository-takeover/)
  • 2026 Incidents

    • 2026-01-08 - n8n "Ni8mare" CVSS 10.0 RCE

      • The Hacker News - unauthenticated-remote-code-execution-in-n8n-cve-2026-21858), [The Register](https://www.theregister.com/2026/01/08/n8n_rce_bug/)
    • 2026-01-20 - Anthropic Git MCP Server Vulnerability Chain

      • The Hacker News - mcp-server-flaws-lead-to-code-execution-data-exposure/)
    • 2026-01-21 - Claude Code API Key Exfiltration

    • 2026-01-23 - Langflow Active Exploitation Deploys Flodrix Botnet

    • 2026-01 - Step Finance AI Trading Agent Treasury Drain

    • 2026-02-04 - MCP TypeScript SDK Cross-Client Data Leak

    • 2026-02-09 - Clinejection Supply Chain Attack

      • Snyk - cli-230-supply-chain-attack.html), [Adnan Khan](https://adnanthekhan.com/posts/clinejection/)
    • 2026-02-20 - CyberStrikeAI FortiGate Mass Compromise

      • AWS Security Blog - assisted-threat-actor-compromises.html), [The Hacker News CyberStrikeAI](https://thehackernews.com/2026/03/open-source-cyberstrikeai-deployed-in.html), [The Record](https://therecord.media/gen-ai-fortigate-hackers-russia), [CSO Online](https://www.csoonline.com/article/4136198/russian-group-uses-ai-to-exploit-weakly-protected-fortinet-firewalls-says-amazon.html), [SC Media](https://www.scworld.com/news/threat-group-leverages-llms-to-compromise-600-fortigate-firewalls)
    • 2026-02-22 - OpenClaw Agent Deletes 200+ Emails at Meta

      • Fast Company - meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/)
    • 2026-03-10 - Meta Acquires Moltbook (OpenClaw) After Security Crises

      • Wiz - of-malicious-skills-found-in-openclaws-clawhub/), [BleepingComputer](https://www.bleepingcomputer.com/news/security/clawjacked-attack-let-malicious-websites-hijack-openclaw-to-steal-data/)
    • 2026-03-11 - UNC6426 nx npm to AWS Admin Takeover

    • 2026-03-17 - LangChain Core Path Traversal

    • 2026-03-17 - Langflow RCE Exploited Within 20 Hours

      • The Hacker News - 2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours), [Barrack AI](https://blog.barrack.ai/langflow-exec-rce-cve-2026-33017/)
    • 2026-03-18 - Meta Sev 1 Rogue AI Agent Incident

      • TechCrunch - meta-rogue-ai-agent-triggers-security-alert), [Engadget](https://www.engadget.com/ai/a-meta-agentic-ai-sparked-a-security-incident-by-acting-without-permission-224013384.html)
    • 2026-03-19 - Trivy GitHub Action Compromise by TeamPCP

      • Wiz - supply-chain-attack-what-you-need-to-know/), [Unit 42](https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/)
    • 2026-03-20 - CanisterWorm npm Worm by TeamPCP

      • Aikido - supply-chain-attack-triggers-self.html), [Mend.io](https://www.mend.io/blog/canisterworm-the-self-spreading-npm-attack-that-uses-a-decentralized-server-to-stay-alive/)
    • 2026-03-23 - Checkmarx KICS GitHub Actions Compromise

      • Wiz - security-update/), [The Hacker News](https://thehackernews.com/2026/03/teampcp-hacks-checkmarx-github-actions.html)
    • 2026-03-24 - LiteLLM Supply Chain Attack by TeamPCP

      • LiteLLM Official - security-scanner-backdooring-litellm/), [ReversingLabs](https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads)
    • 2026-03-27 - Telnyx PyPI Supply Chain Compromise

      • The Hacker News - research/telnyx-pypi-2026-teampcp-supply-chain-attacks), [Trend Micro](https://www.trendmicro.com/en_us/research/26/c/teampcp-telnyx-attack-marks-a-shift-in-tactics.html)
    • 2026-03-30 - ChatGPT Hidden DNS Exfiltration Channel

      • Check Point Research - intelligence/check-point-research-reveals-chatgpt-data-exfiltration-flaw/), [Cybersecurity News](https://cybersecuritynews.com/chatgpt-vulnerability/)
    • 2026-03-31 - Axios npm Supply Chain Attack

      • Microsoft Security Blog - supply-chain-attack-pushes-cross.html), [Elastic Security Labs](https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all)
    • 2026-03-31 - Cisco Source Code Stolen via Trivy Breach

    • 2026-03-31 - Mercor Data Breach via LiteLLM Supply Chain

      • Fortune - says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/), [SecurityWeek](https://www.securityweek.com/mercor-hit-by-litellm-supply-chain-attack/)
    • 2026-03 - ROME AI Agent Escapes Sandbox, Mines Cryptocurrency

      • Axios - intelligence/an-experimental-ai-agent-broke-out-of-its-testing-environment-and-mined-crypto-without-permission)
    • 2026-04-01 - Drift Protocol $285M Exploit

      • TRM Labs - protocol-exploited-for-286-million-in-suspected-dprk-linked-attack), [The Hacker News](https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html)
    • 2026-04-02 - Meta Pauses Mercor Partnership

    • 2026-04-03 - Azure MCP Server Authentication Flaw

    • 2026-04-03 - PraisonAI Gateway Unauthenticated Agent Control

    • 2026-04-07 - AWS Bedrock AgentCore "Agent God Mode" Cross-Agent Memory Access

      • Unit 42 - of-aws-sandbox-network-isolation-mode/)
    • 2026-04-07 - Flowise AI Agent Builder RCE Actively Exploited in the Wild

      • The Hacker News - severity-flowise-rce-vulnerability-now-exploited-in-attacks/), [Security Affairs](https://securityaffairs.com/190471/security/attackers-exploit-critical-flowise-flaw-cve-2025-59528-for-remote-code-execution.html), [CSO Online](https://www.csoonline.com/article/4155680/hackers-exploit-a-critical-flowise-flaw-affecting-thousands-of-ai-workflows.html)
    • 2026-04-08 - PraisonAI Template Injection in Agent Tool Definitions

      • GitLab Advisory - 2026-39891), [TheHackerWire](https://www.thehackerwire.com/praisonai-template-injection-via-agent-input-cve-2026-39891/)
    • 2026-04-08 - UNC1069 Contagious Interview Cross-Ecosystem Package Campaign

      • The Hacker News - korea-malicious-packages-npm-pypi-go-rust/), [Cybersecuritywaala](https://cybersecuritywaala.com/news/north-korea-linked-malicious-packages-in-registries/)
    • 2026-04-10 - Red Hat OpenShift AI odh-dashboard Kubernetes Token Disclosure

      • TheHackerWire - 2026:3713](https://access.redhat.com/errata/RHSA-2026:3713), [CSO Online](https://www.csoonline.com/article/4067305/red-hat-openshift-ai-weakness-allows-full-cluster-compromise-warns-advisory.html)
    • 2026-04-11 - aws-mcp-server Unauthenticated RCE via Command Injection

      • TheHackerWire CVE-2026-5058 - 2026-5059](https://www.thehackerwire.com/aws-mcp-server-aws-cli-command-injection-rce/), [NVD CVE-2026-5059](https://nvd.nist.gov/vuln/detail/CVE-2026-5059), [Endor Labs](https://www.endorlabs.com/learn/classic-vulnerabilities-meet-ai-infrastructure-why-mcp-needs-appsec)
    • 2026-04-13 - Malicious LLM Router Research Reveals Credential and Crypto Theft

      • ArXiv paper - agents-are-set-to-power-crypto-payments-but-a-hidden-flaw-could-expose-wallets), [Risky Business](https://news.risky.biz/risky-bulletin-malicious-llm-proxy-routers-found-in-the-wild/), [CCN](https://www.ccn.com/news/crypto/will-ai-steal-bitcoin-research-malicious-llm-routers-crypto-theft/), [OECD AI Incident Database](https://oecd.ai/en/incidents/2026-04-10-d6e2)
    • 2026-04-13 - Marimo Pre-Auth RCE Weaponized to Deploy NKAbuse via Hugging Face

      • Sysdig - rce-flaw-cve-2026-39987.html), [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-exploit-marimo-flaw-to-deploy-nkabuse-malware-from-hugging-face/), [Cybersecurity News](https://cybersecuritynews.com/attackers-spread-blockchain-based-backdoor-via-hugging-face/)
    • 2026-04-13 - Nginx UI MCP Auth Bypass Under Active Exploitation

      • The Hacker News - nginx-ui-auth-bypass-flaw-now-actively-exploited-in-the-wild/), [Rapid7](https://www.rapid7.com/blog/post/etr-cve-2026-33032-nginx-ui-missing-mcp-authentication/), [Picus Security](https://www.picussecurity.com/resource/blog/cve-2026-33032-mcpwn-how-a-missing-middleware-call-in-nginx-ui-hands-attackers-full-web-server-takeover), [Security Affairs](https://securityaffairs.com/190841/hacking/cve-2026-33032-severe-nginx-ui-bug-grants-unauthenticated-server-access)
    • 2026-04-14 - OWASP GenAI Q1 2026 Exploit Round-up Report

    • 2026-04-15 - Claude Code, Gemini CLI, Copilot Agent Hijacked via GitHub Comments

      • The Register - code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/), [The Next Web](https://thenextweb.com/news/ai-agents-hijacked-prompt-injection-bug-bounties-no-cve), [Cybernews](https://cybernews.com/security/ai-agents-github-prompt-injection-pattern/)
      • The Register - code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/), [The Next Web](https://thenextweb.com/news/ai-agents-hijacked-prompt-injection-bug-bounties-no-cve), [Cybernews](https://cybernews.com/security/ai-agents-github-prompt-injection-pattern/)
    • 2026-04-15 - Copilot Studio ShareLeak and Agentforce PipeLeak Form-Based Prompt Injection

      • VentureBeat - security/microsoft-salesforce-patch-ai-agent-data-leak-flaws), [CSO Online](https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html), [NVD CVE-2026-21520](https://nvd.nist.gov/vuln/detail/CVE-2026-21520), [PointGuard AI](https://www.pointguardai.com/ai-security-incidents/copilot-studio-leak-the-assistant-that-overshared-cve-2026-21520)
    • 2026-04-15 - LiteLLM OIDC Userinfo Cache Authentication Bypass

      • LiteLLM Advisory - 2026-35030/), [GitHub Advisory](https://github.com/advisories/GHSA-jjhc-v7c2-5hh6), [SecurityOnline](https://securityonline.info/litellm-security-vulnerability-auth-bypass-rce-patch/), [Wiz](https://www.wiz.io/vulnerability-database/cve/cve-2026-35030)
    • 2026-04-15 - n8n Webhook Weaponization for Phishing Campaigns

      • The Hacker News - n8n-n8mare/), [SC Media](https://www.scworld.com/brief/ai-workflow-platform-n8n-abused-for-phishing-and-device-fingerprinting), [TechRepublic](https://www.techrepublic.com/article/news-hackers-abuse-n8n-workflows-malware-delivery/)
    • 2026-04-16 - Anthropic MCP Systemic STDIO Design RCE

      • OX Security - mcp-design-vulnerability.html), [The Register](https://www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/), [CSO Online](https://www.csoonline.com/article/4159889/rce-by-design-mcp-architectural-choice-haunts-ai-agent-ecosystem.html), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/systemic-flaw-mcp-expose-150/), [TechRadar](https://www.techradar.com/pro/security/this-is-not-a-traditional-coding-error-experts-flag-potentially-critical-security-issues-at-the-heart-of-anthropics-mcp-exposes-150-million-downloads-and-thousands-of-servers-to-complete-takeover), [GitHub Advisory CVE-2026-40933](https://github.com/advisories/GHSA-c9gw-hvqq-f33r)
    • 2026-04-17 - FastGPT Authentication and Password Change NoSQL Injection

    • 2026-04-20 - Vercel Breach via Context.ai AI Tool Supply Chain

      • TechCrunch - breach-tied-to-context-ai-hack.html), [The Register](https://www.theregister.com/2026/04/20/vercel_context_ai_security_incident/), [Vercel Bulletin](https://vercel.com/kb/bulletin/vercel-april-2026-security-incident), [OX Security](https://www.ox.security/blog/vercel-context-ai-supply-chain-attack-breachforums/), [Trend Micro](https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html), [CoinDesk](https://www.coindesk.com/tech/2026/04/20/hack-at-vercel-sends-crypto-developers-scrambling-to-lock-down-api-keys), [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/vercel-breached-after-employee-grants-ai-tool-unrestricted-access-to-google-workspace)
    • 2026-04-21 - Anthropic Claude Mythos Preview Accessed by Discord Group via Vendor Breach

      • TechCrunch - 04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users), [Fortune](https://fortune.com/2026/04/23/anthropic-mythos-leak-dario-amodei-ceo-cybersecurity-hackers-exploits-ai/), [Engadget](https://www.engadget.com/ai/anthropic-is-investigating-unauthorized-access-of-its-mythos-cybersecurity-tool-091017168.html), [Cybernews](https://cybernews.com/security/anthropic-mythos-ai-unauthorized-access/), [Hackread](https://hackread.com/discord-access-anthropic-claude-mythos-ai-breach/), [GovInfoSecurity](https://www.govinfosecurity.com/report-discord-group-uses-claudes-supposedly-secret-mythos-a-31484), [The Next Web](https://thenextweb.com/news/anthropic-mythos-unauthorized-access-vendor-breach)
    • 2026-04-21 - CanisterSprawl Self-Propagating npm Worm via Namastex Labs and pgserve

      • StepSecurity - npm-packages-compromised-canisterworm), [The Hacker News](https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html), [The Register](https://www.theregister.com/2026/04/22/another_npm_supply_chain_attack/), [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-npm-supply-chain-attack-self-spreads-to-steal-auth-tokens/), [SC Media](https://www.scworld.com/news/namastex-npm-packages-compromised-canisterworm-supply-chain-attack), [Cloud Security Alliance Lab](https://labs.cloudsecurityalliance.org/research/csa-research-note-npm-canistersprawl-supply-chain-worm-20260/), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/npm-supply-chain-worm-canister/)
    • 2026-04-21 - Cloud Security Alliance Survey: AI Agent Incidents Common Across Enterprises

      • CSA Press Release - Cloud-Security-Alliance-Survey-Reveals-82-of-Enterprises-Have-Unknown-AI-Agents-in-Their-Environments), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/unchecked-ai-agents-cause/), [ADVISOR Magazine](https://www.lifehealth.com/autonomous-but-not-controlled-ai-agent-incidents-now-common-in-enterprises/)
    • 2026-04-21 - Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264)

      • GitHub Advisory GHSA-3hjv-c53m-58jj - components/CVE-2026-41264/), [THREATINT](https://cve.threatint.eu/CVE/CVE-2026-41264), [SC Media](https://www.scworld.com/brief/active-exploitation-of-max-severity-flowise-bug-threatens-broad-compromise)
    • 2026-04-21 - LMDeploy SSRF Exploited Within 13 Hours of Public Disclosure (CVE-2026-33626)

      • The Hacker News - 2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours), [GBHackers](https://gbhackers.com/attackers-exploit-lmdeploy-flaw/), [SC Media](https://www.scworld.com/brief/lmdeploy-vulnerability-exploited-in-real-time-highlighting-ai-infrastructure-risks), [SentinelOne CVE Profile](https://www.sentinelone.com/vulnerability-database/cve-2026-33626/), [Vulert](https://vulert.com/blog/lmdeploy-cve-2026-33626-ssrf/)
    • 2026-04-22 - Bitwarden CLI npm Package Trojanized via Checkmarx KICS Cascade

      • Bitwarden Statement - cli-compromised-in-ongoing.html), [The Register](https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security), [Socket](https://socket.dev/blog/bitwarden-cli-compromised), [SecurityWeek](https://www.securityweek.com/bitwarden-npm-package-hit-in-supply-chain-attack/), [CSO Online](https://www.csoonline.com/article/4162865/bitwarden-cli-password-manager-trojanized-in-supply-chain-attack.html), [Endor Labs](https://www.endorlabs.com/learn/shai-hulud-the-third-coming----inside-the-bitwarden-cli-2026-4-0-supply-chain-attack), [GitHub Issue 20353](https://github.com/bitwarden/clients/issues/20353)
    • 2026-04-22 - Xinference PyPI Package Compromise (Versions 2.6.0-2.6.2)

      • Mend.io - pypi-breach-exposes-developers/), [OX Security](https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/), [Cyberpress](https://cyberpress.org/xinference-pypi-package-compromised/), [GitGuardian](https://blog.gitguardian.com/three-supply-chain-campaigns-hit-npm-pypi-and-docker-hub-in-48-hours/), [Orca Security](https://orca.security/resources/blog/xinference-pypi-package-compromise-remediation/)
    • 2026-04-23 - Google Workspace Reports 32% Rise in Indirect Prompt Injection Pages on the Open Web

      • Google Online Security Blog "AI threats in the wild" - workspaces-continuous-approach.html), [Help Net Security](https://www.helpnetsecurity.com/2026/04/24/indirect-prompt-injection-in-the-wild/), [WebProNews](https://www.webpronews.com/prompt-injections-lurk-in-plain-sight-googles-scan-reveals-webs-hidden-assault-on-ai-agents/)
      • Google Online Security Blog "AI threats in the wild" - workspaces-continuous-approach.html), [Help Net Security](https://www.helpnetsecurity.com/2026/04/24/indirect-prompt-injection-in-the-wild/), [WebProNews](https://www.webpronews.com/prompt-injections-lurk-in-plain-sight-googles-scan-reveals-webs-hidden-assault-on-ai-agents/)
    • 2026-04-23 - HexagonalRodent North Korean APT Industrializes Web3 Developer Attacks Using AI Coding Tools

      • Help Net Security - lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/), [Yahoo / Decrypt](https://www.yahoo.com/news/articles/north-korean-hackers-industrialize-attacks-110000000.html), [KuCoin](https://www.kucoin.com/news/flash/north-korean-hackers-target-web3-developers-with-ai-powered-attacks-steal-12m-in-3-months)
    • 2026-04-23 - SecurityScorecard Finds 40,214 OpenClaw Instances Exposed Online with 63% RCE-Vulnerable

      • SecurityScorecard - magazine.com/news/researchers-40000-exposed-openclaw/), [Dataconomy](https://dataconomy.com/2026/04/23/hackers-exploit-vulnerabilities-in-openclaw-to-control-28000-systems/), [TechRadar](https://www.techradar.com/pro/security/the-math-is-simple-openclaw-trojan-horse-ai-agents-give-hackers-full-control-of-28-000-systems), [TechBriefly](https://techbriefly.com/2026/04/23/openclaw-ai-agent-flaw-exposes-over-28000-systems/)
    • 2026-04-24 - LangChain langchain-openai and langchain-text-splitters SSRF Disclosures

      • GitLab Advisory CVE-2026-41488 - 2026-41481](https://radar.offseq.com/threat/cve-2026-41481-cwe-918-server-side-request-forgery-9716de86), [TheHackerWire CVE-2026-41488](https://www.thehackerwire.com/vulnerability/CVE-2026-41488/), [TheHackerWire CVE-2026-41481](https://www.thehackerwire.com/vulnerability/CVE-2026-41481/), [Vulnerability-Lookup CVE-2026-41488](https://vulnerability.circl.lu/vuln/cve-2026-41488)
    • 2026-04-29 - LiteLLM Pre-Auth SQL Injection (CVE-2026-42208)

      • The Hacker News - 2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure), [SecurityWeek](https://www.securityweek.com/fresh-litellm-vulnerability-exploited-shortly-after-disclosure/)
    • 2026-04-30 - Google Gemini CLI CVSS 10.0 Headless RCE

      • The Register - fixes-cvss-10-gemini-cli-ci-rce.html), [Hackread](https://hackread.com/google-cvss-10-gemini-cli-vulnerability-github-rce/)
    • 2026-04-30 - PyTorch Lightning PyPI Compromise (Mini Shai-Hulud)

      • Snyk - pypi-attack-19-packages-poisoned.html)
    • 2026-05-04 - Grok and Bankr AI Wallet Drained via Morse-Code Prompt Injection

      • SlowMist - grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/), [OECD AI Incidents](https://oecd.ai/en/incidents/2026-05-04-4a73)
    • 2026-05-05 - Ollama for Windows Auto-Updater RCE and Persistence (CVE-2026-42248, CVE-2026-42249)

    • 2026-05-07 - Malicious Hugging Face "Open-OSS/privacy-filter" Fake OpenAI Model

      • HiddenLayer - magazine.com/news/malicious-hugging-face-repo/)
    • 2026-05-07 - Microsoft Azure AI Foundry M365 Agent Privilege Escalation (CVE-2026-35435)

      • NVD - alert-cve-2026-35435-microsoft-azure-ai-foundry/)
    • 2026-05-07 - Microsoft Semantic Kernel Prompt-Injection to RCE (CVE-2026-26030, CVE-2026-25592)

    • 2026-05-10 - Ollama "Bleeding Llama" Unauthenticated Memory Leak (CVE-2026-7482)

      • The Hacker News - llama-critical-unauthenticated-memory-leak-in-ollama), [SecurityWeek](https://www.securityweek.com/critical-bug-could-expose-300000-ollama-deployments-to-information-theft/)
    • 2026-05-11 - Google GTIG Reports First AI-Developed Zero-Day for Mass Exploitation

      • Google Cloud Threat Intelligence - used-ai-to-develop-first-known.html), [CNBC](https://www.cnbc.com/2026/05/11/google-thwarts-effort-hacker-group-use-ai-mass-exploitation-event.html)
    • 2026-05-11 - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, and Guardrails AI (CVE-2026-45321)

      • The Hacker News - npm-packages-compromised-mini-shai-hulud-supply-chain-attack), [Tenable](https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions)
      • 0day.click - code-vulnerability/), [Cybersecurity News](https://cybersecuritynews.com/claude-code-rce-flaw/)
    • 2026-05-12 - Cline AI Agent Unauthenticated WebSocket RCE (CVE-2026-44211)

    • 2026-05-12 - GitHub Copilot and VS Code Security-Feature Bypass (CVE-2026-41109)

      • Windows News AI - copilot-visual-studio-injection-bypasses-security-feature-cve-2026-41109/)
    • 2026-05-14 - OpenAI Internal Source Code and Certificate Theft via TanStack Worm

      • TechCrunch - Hulud)](https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html)
    • 2026-05-15 - PraisonAI Auth-Disabled API Server (CVE-2026-44338)

    • 2026-05-18 - actions-cool GitHub Actions Tag Hijack (Mini Shai-Hulud)

    • 2026-05-20 - NVIDIA Triton Inference Server Authentication Bypass (CVE-2026-24207)

    • 2026-05-25 - "Megalodon" Mass GitHub Actions Secret Exfiltration

      • SecurityWeek - mass-github-actions-secret-exfiltration-across-5-500-public-repositories)
    • 2026-05-28 - Nx Console Malicious VS Code Extension Leads to GitHub Repository Breach

      • CISA Alert - ide-forks-expose-users-to-recommended-extension-attacks/)
    • 2026-06-01 - Red Hat @redhat-cloud-services npm "Miasma" Worm

      • Wiz - us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/), [Red Hat](https://access.redhat.com/security/vulnerabilities/RHSB-2026-006)
    • 2026-06-03 - node-gyp "Phantom Gyp" Self-Propagating npm Worm (Miasma)

      • Snyk - gyp-npm-supply-chain-attack-spreads-like-worm)
    • 2026-06-05 - Claude Code GitHub Action Prompt-Injection Secret Exfiltration

      • Decrypt - research-note-claude-code-github-action-prompt-injection/)
    • 2026-06-05 - Hades PyPI Worm Wave (Shai-Hulud / Miasma Lineage)

      • Socket - pypi-attack-19-packages-poisoned.html), [Dark Reading](https://www.darkreading.com/application-security/hades-campaign-pypi-shai-hulud)
    • 2026-06-08 - Langflow Path Traversal RCE Exploited in the Wild (CVE-2026-5027)

      • The Hacker News - 2026-5027-langflow-path-traversal-rce/), [SecurityWeek](https://www.securityweek.com/critical-langflow-vulnerability-exploited-hours-after-public-disclosure/)
    • 2026-06-15 - Microsoft 365 Copilot "SearchLeak" One-Click Data Theft (CVE-2026-42824)

      • The Hacker News - attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/), [Varonis](https://www.varonis.com/blog/searchleak)
    • 2026-06-17 - Mastra AI npm Scope Compromise (Sapphire Sleet / UNC1069)

      • The Hacker News - us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/), [Snyk](https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/)
    • 2026-06-18 - Microsoft AutoGen Studio "AutoJack" Drive-By Code Execution

      • BleepingComputer - modeling.com/microsoft-autogen-studio-code-execution-june-2026/)
    • 2026-06-22 - vLLM OpenAI-Compatible API Authentication Bypass (CVE-2026-48746)

    • 2026-06-23 - Dify "DifyTap" Cross-Tenant Data Exposure (CVE-2026-41947 to CVE-2026-41950)

      • SC Media - advisory-difytap-vulnerabilities)
    • 2026-06-26 - Amazon Q Developer Silent MCP Config Auto-Load (CVE-2026-12957, CVE-2026-12958)

    • 2026-06-30 - Anthropic "buffa" Rust protobuf Memory-Amplification DoS (CVE-2026-55407)

    • 2026-06-30 - "GuardFall" Shell-Injection Bypass in Open-Source AI Coding Agents

      • Adversa AI - exposes-open-source-ai-coding.html), [SC Media](https://www.scworld.com/brief/shell-injection-flaw-found-in-10-of-11-open-source-ai-agents)
    • 2026-06-30 - Palo Alto Unit 42 "Phantom Squatting" - AI-Hallucinated Domains as an Attack Surface

    • 2026-07-01 - Apify Actors MCP Server Token Exfiltration (CVE-2026-50143)

    • 2026-07-01 - Check Point Demonstrates LLM-Generated Browser-Native Ransomware

    • 2026-07-01 - Cursor "DuneSlide" Zero-Click Prompt-Injection RCE (CVE-2026-50548, CVE-2026-50549)

      • Cato Networks - cursor-flaws-could-let-prompt.html), [SecurityWeek](https://www.securityweek.com/critical-cursor-ai-ide-flaws-could-lead-to-os-level-remote-code-execution/)
    • 2026-07-01 - "JADEPUFFER" First Documented End-to-End Agentic Ransomware

      • Sysdig - ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/), [BleepingComputer](https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/)
    • 2026-07-02 - fast-mcp-telegram MCP Server Authentication Bypass (CVE-2026-52830)

      • NVD - mcp-telegram/CVE-2026-52830/)
    • 2026-07-02 - Zscaler Documents In-the-Wild Indirect Prompt Injection Targeting Autonomous AI Agents

    • 2026-07-06 - OpenAI Codex Desktop Zero-Click Data Exfiltration (CVE-2026-14898)

    • 2026-07-06 - "SkillCloak" Repacks Malicious AI Agent Skills to Evade Scanners

      • The Hacker News - ai-agent-skills-scan/), [arXiv](https://arxiv.org/abs/2607.02357)
    • 2026-07-06 - Summer.fi "Keeper AI Agents" Exploit Drains About $6M

      • CryptoSlate - loses-35m-in-a-week-bonkdao-bonzo-lend-summer-fi-hacked/)
    • 2026-07-07 - CISA Adds Langflow IDOR (CVE-2026-55255) to KEV, First AI Agent Platform in the Catalog

      • The Hacker News - orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/), [Help Net Security](https://www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/)
    • 2026-07-07 - DigiCert AI Trust Outlook: 78% of Enterprises Report AI Security Incidents

      • DigiCert (GlobeNewswire) - ai-still-smarting-from-leaping-before-looking/5267353), [SD Times](https://sdtimes.com/ai-governance/survey-reveals-78-of-enterprises-are-reporting-ai-related-security-incidents/)
    • 2026-07-07 - "GitLost" Leaks Private Repositories via GitHub Agentic Workflows

      • Noma Security - github-issue-could-trick-github.html), [SecurityWeek](https://www.securityweek.com/critical-vulnerability-exposes-github-agentic-workflows-to-prompt-injection/)
    • 2026-07-07 - Google Dialogflow CX "Rogue Agent" Cross-Agent Hijack

      • The Hacker News - google-ai-agent-chatbot-security), [Dark Reading](https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft)
    • 2026-07-07 - Google Gemini Live API RCE via Unconstrained Ephemeral Tokens

    • 2026-07-07 - mem0 Unauthenticated Memory Access and Key Disclosure (CVE-2026-59705, CVE-2026-59706)

    • 2026-07-07 - Trend Micro "Stars Don't Save You" MCP Ecosystem Study

      • Trend AI Security - security-issues-expose-2259-public-mcp-servers-to-ai-agent-attacks/), [GBHackers](https://gbhackers.com/thousands-of-mcp-servers-found-vulnerable/)
    • 2026-07-07 - "WriteOut" Cross-Tenant Account Takeover in Writer AI

    • 2026-07-08 - China's CNVDB Labels Claude Code a "Backdoor"; Alibaba Bans It

      • The Register - anthropic-ai-claude-code-backdoor-security-threat.html), [TechCrunch](https://techcrunch.com/2026/07/04/alibaba-reportedly-bans-employees-from-using-claude-code/)
    • 2026-07-08 - ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge, First GenAI Android Malware

      • Help Net Security - release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html)
      • Wiz - symlink-flaws-could-let.html), [The Register](https://www.theregister.com/security/2026/07/08/bug-in-top-ai-coding-agents-shows-that-unix-era-security-headaches-never-really-die/)
    • 2026-07-08 - GitHub Copilot Guardrails Bypassed by Multi-Step Workflow Framing

      • The Hacker News - coding-agent-jailbreak/), [The Register](https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/)
    • 2026-07-08 - "HalluSquatting" Weaponizes AI Package-Name Hallucinations

    • 2026-07-08 - Injective SDK npm Packages Backdoored to Steal Wallet Keys and Poison AI Agent Configs

      • BleepingComputer - labs-github-compromise-pushes.html), [StepSecurity](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys)
    • 2026-07-08 - LiteLLM MCP Authentication Bypass (CVE-2026-59822)

    • 2026-07-08 - Sygnia Documents Lone Attacker Breaching AWS in 72 Hours With Agentic AI

    • 2026-07-09 - AWS AI Gateway Wired to Amazon Bedrock Hijacked for Cryptomining

      • SiliconANGLE - risk/ai-gateways-keys-kingdom), [GBHackers](https://gbhackers.com/hackers-compromise-aws-ai-gateway-connected-to-amazon-bedrock/)
    • 2026-07-09 - Cline AI Coding Agent Hub WebSocket RCE (CVE-2026-59723)

      • NVD - v3.0.30)
    • 2026-07-09 - "Friendly Fire" Turns AI Code-Audit Agents Into Code Execution

    • 2026-07-09 - Open WebUI 16-Flaw Security Batch (CVE-2026-59212 to CVE-2026-59227)

    • 2026-07-10 - Wave of Critical RCE Flaws Across AI Agent Frameworks (CVE-2026-61447, CVE-2026-54769, CVE-2026-57572, CVE-2026-59726)

      • NVD CVE-2026-61447 - 2026-54769](https://nvd.nist.gov/vuln/detail/CVE-2026-54769), [NVD CVE-2026-57572](https://nvd.nist.gov/vuln/detail/CVE-2026-57572), [NVD CVE-2026-59726](https://nvd.nist.gov/vuln/detail/CVE-2026-59726)
    • 2026-07-11 - "Ghostcommit" Hides Prompt Injection Inside PNG Images to Steal Secrets

    • 2026-07-13 - Orca Security 2026 State of AI Security Report

  • Key Statistics

Sub Categories
2024 - LangChain Code Execution via LLMSymbolicMathChain 30 2026-04-15 - Claude Code, Gemini CLI, Copilot Agent Hijacked via GitHub Comments 2 2025-02 - Google Gemini Prompt Injection via Calendar Invites 2 2026-01 - Step Finance AI Trading Agent Treasury Drain 2 2025-11-13 - GTG-1002 Chinese State-Sponsored AI-Orchestrated Espionage 2 2026-04-23 - Google Workspace Reports 32% Rise in Indirect Prompt Injection Pages on the Open Web 2 2026-07-08 - Sygnia Documents Lone Attacker Breaching AWS in 72 Hours With Agentic AI 1 2026-04-16 - Anthropic MCP Systemic STDIO Design RCE 1 2024-12 - ChatGPT Search Manipulation via Hidden Text 1 2025-06 - Langflow Flodrix Botnet Exploitation 1 2026-06-26 - Amazon Q Developer Silent MCP Config Auto-Load (CVE-2026-12957, CVE-2026-12958) 1 2026-04-15 - Copilot Studio ShareLeak and Agentforce PipeLeak Form-Based Prompt Injection 1 2024-12-04 - Ultralytics PyPI Supply Chain Attack 1 2026-02-09 - Clinejection Supply Chain Attack 1 2024-09-25 - NVIDIA Container Toolkit Vulnerability 1 2025-06 - EchoLeak - Microsoft 365 Copilot Zero-Click Prompt Injection 1 2025-01-24 - OmniGPT Data Breach 1 2026-05-28 - Nx Console Malicious VS Code Extension Leads to GitHub Repository Breach 1 2026-07-08 - "HalluSquatting" Weaponizes AI Package-Name Hallucinations 1 2025-08 - Cursor MCPoison Silent Backdoor 1 2026-05-07 - Malicious Hugging Face "Open-OSS/privacy-filter" Fake OpenAI Model 1 2026-03-31 - Axios npm Supply Chain Attack 1 2026-04-21 - CanisterSprawl Self-Propagating npm Worm via Namastex Labs and pgserve 1 2024-07 - Microsoft 365 Copilot ASCII Smuggling 1 2026-01-21 - Claude Code API Key Exfiltration 1 2026-04-24 - LangChain langchain-openai and langchain-text-splitters SSRF Disclosures 1 2024-02-14 - Air Canada Chatbot Lawsuit Ruling 1 2025-11-04 - GitHub Copilot Filename Prompt Injection 1 2026-07-07 - Trend Micro "Stars Don't Save You" MCP Ecosystem Study 1 2026-07-07 - Google Dialogflow CX "Rogue Agent" Cross-Agent Hijack 1 2026-04-23 - HexagonalRodent North Korean APT Industrializes Web3 Developer Attacks Using AI Coding Tools 1 2026-04-21 - Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264) 1 2026-04-02 - Meta Pauses Mercor Partnership 1 2025-11 - Claude Desktop Extensions RCE 1 2024-08-06 - Microsoft Copilot Studio SSRF 1 2026-04-15 - LiteLLM OIDC Userinfo Cache Authentication Bypass 1 2026-03-20 - CanisterWorm npm Worm by TeamPCP 1 2024-05 - GitHub Copilot Training Data Secret Leakage 1 2026-07-09 - AWS AI Gateway Wired to Amazon Bedrock Hijacked for Cryptomining 1 2026-05-05 - Ollama for Windows Auto-Updater RCE and Persistence (CVE-2026-42248, CVE-2026-42249) 1 2024-06-25 - Rabbit R1 Hardcoded API Keys 1 2026-04-10 - Red Hat OpenShift AI odh-dashboard Kubernetes Token Disclosure 1 2025-03-18 - Rules File Backdoor Attack on Cursor and Copilot 1 2026-04-30 - Google Gemini CLI CVSS 10.0 Headless RCE 1 2026-06-30 - "GuardFall" Shell-Injection Bypass in Open-Source AI Coding Agents 1 2026-05-07 - Microsoft Azure AI Foundry M365 Agent Privilege Escalation (CVE-2026-35435) 1 2026-04-08 - PraisonAI Template Injection in Agent Tool Definitions 1 2025-06 - Anthropic Filesystem MCP Server "EscapeRoute" 1 2026-05-15 - PraisonAI Auth-Disabled API Server (CVE-2026-44338) 1 2024-06 - McDonald's Ends AI Drive-Thru After Failures 1 2026-07-08 - Injective SDK npm Packages Backdoored to Steal Wallet Keys and Poison AI Agent Configs 1 2026-06-01 - Red Hat @redhat-cloud-services npm "Miasma" Worm 1 2026-03-17 - LangChain Core Path Traversal 1 2026-07-09 - Open WebUI 16-Flaw Security Batch (CVE-2026-59212 to CVE-2026-59227) 1 2026-07-08 - "GhostApproval" Symlink Flaws Defeat Human-in-the-Loop in Six AI Coding Assistants 1 2025-12 - IDEsaster - 30+ Flaws Across AI Coding Tools 1 2026-01-23 - Langflow Active Exploitation Deploys Flodrix Botnet 1 2025-08-20 - Salesloft Drift OAuth Supply Chain Breach 1 2026-06-05 - Hades PyPI Worm Wave (Shai-Hulud / Miasma Lineage) 1 2025-09 - Salesforce Agentforce "ForcedLeak" 1 2026-03-10 - Meta Acquires Moltbook (OpenClaw) After Security Crises 1 2025-08 - Cursor CurXecute RCE via Slack MCP 1 2024-04-02 - Many-Shot Jailbreaking Research 1 2026-04-22 - Bitwarden CLI npm Package Trojanized via Checkmarx KICS Cascade 1 2024-11 - Microsoft Copilot Exposes Private GitHub Repos 1 2026-07-08 - ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge, First GenAI Android Malware 1 2026-05-12 - Claude Code Deeplink RCE 1 2025-07 - mcp-remote Critical RCE 1 2025-08 - Varonis "Reprompt" - Microsoft Copilot Single-Click Data Theft 1 2026-05-04 - Grok and Bankr AI Wallet Drained via Morse-Code Prompt Injection 1 2026-04-03 - Azure MCP Server Authentication Flaw 1 2024-07 - Grok AI Election Misinformation 1 2026-03-23 - Checkmarx KICS GitHub Actions Compromise 1 2026-04-23 - SecurityScorecard Finds 40,214 OpenClaw Instances Exposed Online with 63% RCE-Vulnerable 1 2024-10-17 - Imprompter Attack on AI Chatbots 1 2026-06-18 - Microsoft AutoGen Studio "AutoJack" Drive-By Code Execution 1 2026-05-11 - Google GTIG Reports First AI-Developed Zero-Day for Mass Exploitation 1 2026-03-17 - Langflow RCE Exploited Within 20 Hours 1 2026-04-01 - Drift Protocol $285M Exploit 1 2026-04-29 - LiteLLM Pre-Auth SQL Injection (CVE-2026-42208) 1 2026-07-01 - Check Point Demonstrates LLM-Generated Browser-Native Ransomware 1 2026-07-01 - Apify Actors MCP Server Token Exfiltration (CVE-2026-50143) 1 2026-06-30 - Palo Alto Unit 42 "Phantom Squatting" - AI-Hallucinated Domains as an Attack Surface 1 2026-04-21 - Cloud Security Alliance Survey: AI Agent Incidents Common Across Enterprises 1 2026-01-08 - n8n "Ni8mare" CVSS 10.0 RCE 1 2025 - DB-GPT Plugin Upload RCE 1 2025-05 - ElizaOS Memory Injection Vulnerability 1 2025-03-15 - tj-actions/changed-files GitHub Actions Supply Chain Attack 1 2026-03-18 - Meta Sev 1 Rogue AI Agent Incident 1 2026-03-30 - ChatGPT Hidden DNS Exfiltration Channel 1 2026-04-08 - UNC1069 Contagious Interview Cross-Ecosystem Package Campaign 1 2026-02-20 - CyberStrikeAI FortiGate Mass Compromise 1 2025-02-21 - Bybit $1.5B Cryptocurrency Heist 1 2024-03 - ChatGPT Plugin/Extension Vulnerabilities 1 2026-07-11 - "Ghostcommit" Hides Prompt Injection Inside PNG Images to Steal Secrets 1 2025-08 - Claude Code WebSocket Auth Bypass 1 2026-07-07 - CISA Adds Langflow IDOR (CVE-2026-55255) to KEV, First AI Agent Platform in the Catalog 1 2026-07-07 - "GitLost" Leaks Private Repositories via GitHub Agentic Workflows 1 2026-07-02 - Zscaler Documents In-the-Wild Indirect Prompt Injection Targeting Autonomous AI Agents 1 2026-07-02 - fast-mcp-telegram MCP Server Authentication Bypass (CVE-2026-52830) 1 2026-06-17 - Mastra AI npm Scope Compromise (Sapphire Sleet / UNC1069) 1 2024-03 - OpenAI Compromised Credentials on Dark Web 1 2026-06-23 - Dify "DifyTap" Cross-Tenant Data Exposure (CVE-2026-41947 to CVE-2026-41950) 1 2026-07-08 - LiteLLM MCP Authentication Bypass (CVE-2026-59822) 1 2026-07-07 - Google Gemini Live API RCE via Unconstrained Ephemeral Tokens 1 2026-07-01 - Cursor "DuneSlide" Zero-Click Prompt-Injection RCE (CVE-2026-50548, CVE-2026-50549) 1 2026-07-08 - GitHub Copilot Guardrails Bypassed by Multi-Step Workflow Framing 1 2026-04-13 - Nginx UI MCP Auth Bypass Under Active Exploitation 1 2026-05-18 - actions-cool GitHub Actions Tag Hijack (Mini Shai-Hulud) 1 2026-05-14 - OpenAI Internal Source Code and Certificate Theft via TanStack Worm 1 2026-06-30 - Anthropic "buffa" Rust protobuf Memory-Amplification DoS (CVE-2026-55407) 1 2025-08 - Claude Code InversePrompt Command Injection 1 2026-06-15 - Microsoft 365 Copilot "SearchLeak" One-Click Data Theft (CVE-2026-42824) 1 2026-02-22 - OpenClaw Agent Deletes 200+ Emails at Meta 1 2025-06 - GitHub Copilot CamoLeak 1 2024-08-20 - Slack AI Prompt Injection and Data Exfiltration 1 2025 - Cursor Case Sensitivity Bypass 1 2024-06 - Hugging Face Spaces Breach 1 2025 - GitHub Copilot RoguePilot Repository Takeover 1 2025-12 - Copilot Studio Prompt Injection Data Leak 1 2026-04-14 - OWASP GenAI Q1 2026 Exploit Round-up Report 1 2025-12 - LangChain "LangGrinch" Serialization Injection 1 2026-05-20 - NVIDIA Triton Inference Server Authentication Bypass (CVE-2026-24207) 1 2026-03-11 - UNC6426 nx npm to AWS Admin Takeover 1 2026-06-03 - node-gyp "Phantom Gyp" Self-Propagating npm Worm (Miasma) 1 2026-03 - ROME AI Agent Escapes Sandbox, Mines Cryptocurrency 1 2026-07-07 - mem0 Unauthenticated Memory Access and Key Disclosure (CVE-2026-59705, CVE-2026-59706) 1 2026-01-20 - Anthropic Git MCP Server Vulnerability Chain 1 2026-04-22 - Xinference PyPI Package Compromise (Versions 2.6.0-2.6.2) 1 2025-04 - MCP Tool Poisoning / WhatsApp Data Exfiltration 1 2026-07-01 - "JADEPUFFER" First Documented End-to-End Agentic Ransomware 1 2026-07-06 - OpenAI Codex Desktop Zero-Click Data Exfiltration (CVE-2026-14898) 1 2024 - LangChain GraphCypherQAChain Injection 1 2026-07-07 - DigiCert AI Trust Outlook: 78% of Enterprises Report AI Security Incidents 1 2026-06-05 - Claude Code GitHub Action Prompt-Injection Secret Exfiltration 1 2026-05-12 - Cline AI Agent Unauthenticated WebSocket RCE (CVE-2026-44211) 1 2026-04-17 - FastGPT Authentication and Password Change NoSQL Injection 1 2024 - LangChain Arbitrary Code Execution 1 2026-03-27 - Telnyx PyPI Supply Chain Compromise 1 2024-01-18 - DPD AI Chatbot Malfunction 1 2025-07-09 - Hugging Face Poisoned GGUF Templates 1 2026-05-10 - Ollama "Bleeding Llama" Unauthenticated Memory Leak (CVE-2026-7482) 1 2026-05-25 - "Megalodon" Mass GitHub Actions Secret Exfiltration 1 2026-04-07 - Flowise AI Agent Builder RCE Actively Exploited in the Wild 1 2025-08 - GitHub Copilot RCE via Prompt Injection 1 2026-07-09 - Cline AI Coding Agent Hub WebSocket RCE (CVE-2026-59723) 1 2026-07-06 - "SkillCloak" Repacks Malicious AI Agent Skills to Evade Scanners 1 2024-11 - Microsoft Copilot Studio XSS 1 2026-04-13 - Malicious LLM Router Research Reveals Credential and Crypto Theft 1 2026-07-09 - "Friendly Fire" Turns AI Code-Audit Agents Into Code Execution 1 2026-04-21 - Anthropic Claude Mythos Preview Accessed by Discord Group via Vendor Breach 1 2026-07-10 - Wave of Critical RCE Flaws Across AI Agent Frameworks (CVE-2026-61447, CVE-2026-54769, CVE-2026-57572, CVE-2026-59726) 1 2026-04-21 - LMDeploy SSRF Exploited Within 13 Hours of Public Disclosure (CVE-2026-33626) 1 2024-09 - ChatGPT "SpAIware" Persistent Memory Exploitation 1 2026-07-06 - Summer.fi "Keeper AI Agents" Exploit Drains About $6M 1 2026-06-08 - Langflow Path Traversal RCE Exploited in the Wild (CVE-2026-5027) 1 2026-04-07 - AWS Bedrock AgentCore "Agent God Mode" Cross-Agent Memory Access 1 2026-07-07 - "WriteOut" Cross-Tenant Account Takeover in Writer AI 1 2026-05-12 - GitHub Copilot and VS Code Security-Feature Bypass (CVE-2026-41109) 1 2026-03-31 - Mercor Data Breach via LiteLLM Supply Chain 1 2026-04-15 - n8n Webhook Weaponization for Phishing Campaigns 1 2026-04-13 - Marimo Pre-Auth RCE Weaponized to Deploy NKAbuse via Hugging Face 1 2025-08 - OpenAI Codex CLI Command Injection 1 2026-04-03 - PraisonAI Gateway Unauthenticated Agent Control 1 2025-05 - Langflow CISA KEV Addition - Confirmed Active Exploitation 1 2026-04-11 - aws-mcp-server Unauthenticated RCE via Command Injection 1 2025-11 - ServiceNow Now Assist Second-Order Prompt Injection 1 2025-11 - CrewAI "Uncrew" GitHub Token Exposure 1 2026-05-11 - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, and Guardrails AI (CVE-2026-45321) 1 2026-02-04 - MCP TypeScript SDK Cross-Client Data Leak 1 2026-05-07 - Microsoft Semantic Kernel Prompt-Injection to RCE (CVE-2026-26030, CVE-2026-25592) 1 2024-08-08 - LOLCopilot - Black Hat USA 2024 Copilot Attacks 1 2025-07-17 - Amazon Q VS Code Extension Compromise 1 2026-03-24 - LiteLLM Supply Chain Attack by TeamPCP 1 2026-04-20 - Vercel Breach via Context.ai AI Tool Supply Chain 1 2026-03-19 - Trivy GitHub Action Compromise by TeamPCP 1 2024-10-22 - Claude Computer Use Launch Security Warnings 1 2024-11-22 - Freysa AI Agent Game - Function Manipulation 1 2026-03-31 - Cisco Source Code Stolen via Trivy Breach 1 2024-07 - ChatGPT macOS Cleartext Storage 1 2026-06-22 - vLLM OpenAI-Compatible API Authentication Bypass (CVE-2026-48746) 1 2026-04-30 - PyTorch Lightning PyPI Compromise (Mini Shai-Hulud) 1 2024-04 - Hugging Face Cross-Tenant Attack 1 2026-07-13 - Orca Security 2026 State of AI Security Report 1 2026-07-08 - China's CNVDB Labels Claude Code a "Backdoor"; Alibaba Bans It 1 2024-02 - PoisonedRAG Research 1