Affected Technology
AI Agents incidents
Security concerns related to AI agents
OpenAI Security Breach
OpenAI apologises for Medicare breach, shelves next gen ChatGPT abc.net.au
Anthropic Security Vulnerability
Anthropic Rolls Out Claude Security for AI Vulnerability Scanning Infosecurity Magazine
Claude Security Vulnerability
Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.
AI Security Breach
OpenAI battles to contain rogue AI agents months after security breach news24.com
OpenAI Security Vulnerability
OpenAI’s Agent Hacked Australia’s Medicare Portal. It Found the Vulnerability Itself. forkast.news
Claude Security Breach
Three Open-Source AI Agents Ran 27+ Breaches for $25 a Target. 600,000+ Cards Followed. forkast.news
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
OpenAI Security Incident
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.
Adobe Commerce Zero-day Vulnerability
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
Amazon AWS Security Incident
Muse Mac App Security Flaw Allows Hackers to Exploit the AI Agent iPhone in Canada
Three-Person Team Uses Claude to Breach OpenAI's Core Codebase; $6,500 Bounty Triggers AI Security Alarm
Three-Person Team Uses Claude to Breach OpenAI's Core Codebase; $6,500 Bounty Triggers AI Security Alarm finance.biggo.com
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
Astra hidden vulnerability
The AI Security Problem Is Bigger Than the Hugging Face Breach HackerNoon
ChatGPT Remote Code Execution Vulnerability
AI agents, including Claude Sonnet 4.5, GPT-5, and Gemini 2.5 Pro, demonstrated high proficiency by solving 9 out of 10 lab challenges that simulated real-world web application vulnerabilities with minimal cost. These successes encompassed exploits like authentication bypass, IDOR, stored XSS, S3 bucket takeover, and AWS IMDS SSRF, highlighting AI's capability for multi-step reasoning and rapid pattern recognition.
ChatGPT Data Exposure
Autonomous AI agent hit Spanish firm with vulnerability scans before accessing files and data TechRadar
Spain reports first data breach involving autonomous AI agent
Spain reports first data breach involving autonomous AI agent Help Net Security
AI Data Breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
OpenAI Supply-Chain Compromise
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
AI Data Exposure
Using AI tools without browser security literacy is a vulnerability companies can't ignore diginomica.com
Claude Authentication Bypass
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
FlexPLM Remote Code Execution Vulnerability
A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.
Linux Kernel Security Incident
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
Google Authentication Bypass
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News
OpenAI AI Security Breach Triggers 14-State Legal Reckoning
OpenAI's new GPT-5.5-Cyber tops Claude Mythos 5 in vulnerability benchmark Neowin
Microsoft Copilot Remote Code Execution Vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package Ars Technica
Claude Security Incident
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an