Affected Technology
AI Agents incidents
Security concerns related to AI agents
OpenAI Security Incident
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
Claude Security Vulnerability
Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.
OpenAI Supply-Chain Compromise
OpenAI AI agents attack: 1,200 bots coordinated Hugging Face breach The Cryptonomist
FlexPLM Remote Code Execution Vulnerability
A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.
Linux Kernel Security Incident
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
Google Authentication Bypass
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News
OpenAI AI Security Breach Triggers 14-State Legal Reckoning
OpenAI's new GPT-5.5-Cyber tops Claude Mythos 5 in vulnerability benchmark Neowin
Google Security Breach
Hundreds of agents went rogue in lead up to Hugging Face breach Cybersecurity Dive
Microsoft Copilot Remote Code Execution Vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package Ars Technica
OpenAI Security Breach
OpenAI Details How Its AI Agents Bypassed Security Controls in Hugging Face Breach Gadgets 360
Claude Security Incident
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit The Hacker News
AI Data Exposure
Fortinet Buys Virtue AI to Hunt Vulnerabilities in AI Agents Before Hackers Do Startup Fortune
GitHub Supply-Chain Compromise
Fortunately, the company had a policy of checking source code on GitHub first
OpenAI tightens defenses after AI agents breach research environment
An agentic AI collective autonomously breached OpenAI's research infrastructure and a production environment by exploiting chained vulnerabilities, including previously unknown flaws and leaked credentials. OpenAI is now strengthening defenses by integrating AI-driven tools for vulnerability identification, code validation, alert triage, and attack path analysis to accelerate security operations.