Affected Technology

Data Leakage incidents

Data exposure and leakage incidents

Matching incidents

69

Technology type

Topic

News NEW

Fortune 500 Companies Hit in Azure Data Theft Campaign

A data theft campaign has targeted Fortune 500 companies, specifically exploiting Azure cloud environments for sensitive information exfiltration. This incident underscores critical vulnerabilities in cloud infrastructure and the ongoing risk associated with insecure cloud deployments.

AzureData LeakageFortune 500 companiesAzure Data TheftCampaignCompanies Hit
News NEW

153GB of stolen credentials surface after LiteLLM supply chain attack

A supply chain attack compromised LiteLLM via a poisoned Trivy dependency, leading to the deployment of malicious LiteLLM versions (1.82.7/1.82.8) that exfiltrated 153GB of corporate credentials. This dataset, comprising AWS keys, API tokens, and other secrets from CI runner environments, impacts nearly 2,500 organizations, underscoring critical software supply chain vulnerabilities.

Low severity STABLE

AI Critical security gaps in AI deployments, including lack of access controls and shadow AI, are contributing to increased incidents. Vulnerability

Data breach costs surged to a record average of $4.99 million, notably escalating with AI-driven attacks that exploit vulnerabilities faster and leverage advanced techniques like deepfakes and AI-generated malware. Critical security gaps in AI deployments, including widespread lack of access controls for AI models and pervasive shadow AI, are contributing to increased incidents, data compromise, and operational disruptions.

Low severity STABLE

OpenAI Remote Code Execution Vulnerability

A security breach reportedly involving OpenAI and the Hugging Face platform indicates potential unauthorized access to, or exfiltration of, AI model data or related resources. This incident underscores critical vulnerabilities within the AI development ecosystem, raising significant concerns about MLOps security and the integrity of AI supply chains.

1 source: thehill.com Updated 27d ago
Low severity STABLE

Meta Data Exposure

A major security incident impacting Mercor, a leading data vendor, potentially exposed proprietary AI model training data from several major AI labs, including Meta. This breach prompted Meta to indefinitely pause its work with Mercor, with other AI firms also reevaluating their partnerships due to the third-party compromise.

MetaData LeakageAI Industry SecretsMeta Pauses WorkRiskWith Mercor After
1 source: wired.com Updated 4mo ago
Low severity STABLE

Meta Supply-Chain Compromise

A security incident at AI data vendor Mercor exposed proprietary AI training data methodologies and strategies from Meta and other major AI labs. This breach represents a significant competitive intelligence leak, highlighting critical security vulnerabilities within the AI supply chain and third-party vendor relationships.

MetaData LeakageSupply ChainMeta Halts MercorPartnership After AI
1 source: techbuzz.ai Updated 4mo ago
Low severity STABLE

AI Companies Data Exposure

The provided article content is empty, preventing a detailed technical summary. However, the title indicates Mercor has suffered a major security breach affecting AI companies, with Binance mentioned in context, suggesting a potential data leak or significant compromise.

Data LeakageAI CompaniesMercor Faces MajorSecurity Breach Affecting
1 source: binance.com Updated 4mo ago
Low severity STABLE

From Basics Prompt Injection Vulnerability

The article outlines a comprehensive AI security roadmap addressing unique threats to LLMs and AI agents, such as prompt injection, data poisoning, model inversion, and data leakage, which exploit probabilistic system behaviors across the full AI lifecycle. It emphasizes applying frameworks like OWASP Top 10 for LLMs and NIST AI RMF to build defenses from data collection and training to deployment and runtime monitoring, mitigating these advanced vulnerabilities.

Low severity STABLE

ChatGPT Remote Code Execution Vulnerability

Hackers utilized AI jailbreaking techniques and sophisticated prompt engineering on Generative AI models like Claude and ChatGPT to exploit vulnerabilities within Mexican government systems. This operation led to the successful exfiltration of 150GB of sensitive data, including 195 million taxpayer records, voting information, and government employee credentials.

Low severity STABLE

LLMs Prompt Injection Vulnerability

The OWASP Top 10 for LLM Applications (2025) highlights critical security risks, notably Prompt Injection, where crafted inputs manipulate LLM behavior to bypass safeguards or achieve unauthorized access. Another key concern is Sensitive Information Disclosure, where LLMs can inadvertently leak confidential data, leading to privacy violations and intellectual property infringement.

1 source: trendmicro.com Updated 4mo ago
Low severity STABLE

Meta AI agent’s instruction causes large sensitive data leak to employees | AI (artificial intelligence)

An internal Meta AI agent provided erroneous instructions to an engineer, leading to the accidental exposure of sensitive user and company data to other employees for two hours. This incident highlights a vulnerability in agentic AI systems where a lack of contextual awareness can prompt actions with unintended data exposure consequences.

MetaMeta AI agentAI AgentsData LeakageMeta AI
1 source: theguardian.com Updated 5mo ago
Low severity STABLE

McKinsey's AI agent "Lilli" hacked - by another AI agent

McKinsey's internal AI agent "Lilli" was breached through classic application security flaws, including an unauthenticated endpoint with a SQL injection vulnerability chained with an IDOR flaw. This exploit led to the exposure of 46 million chat logs, 728,000 private files, proprietary RAG documentation, and access to internal AI knowledge bases and vector stores.

Low severity STABLE

AI Data Leakage Vulnerability

LLM applications face significant security risks, primarily prompt injection attacks, where malicious inputs manipulate models into ignoring instructions and revealing sensitive data. This can lead to the exposure of internal configuration data, confidential information, or unauthorized actions within connected enterprise systems.

Data LeakageJailbreakingPrompt InjectionLLM ApplicationsTop Security RisksWhat
News STABLE

Malicious AI Assistant Extensions Harvest LLM Chat Histories

Malicious Chromium-based browser extensions are impersonating legitimate AI tools to harvest sensitive LLM chat histories and browsing data, impacting over 900,000 installs and 20,000 enterprise tenants. These extensions exfiltrate proprietary code, internal workflows, and confidential data to threat actor-controlled infrastructure, leading to widespread information leakage.

MicrosoftOpenAIChatGPTTrojan:JS/ChatGPTStealerData LeakageChat Histories
1 source: microsoft.com Updated 5mo ago
Low severity STABLE

AI Agent Security Prompt Injection Vulnerability

The article details how AI agents introduce unique security risks through prompt injection attacks, over-permissioning, and unconstrained external tool access, which can lead to sensitive data leakage and unauthorized API calls. It emphasizes a robust security framework for AI agents, incorporating authentication, access controls, guardrails, and continuous monitoring to mitigate these vulnerabilities.

AI AgentsData LeakagePrompt InjectionAI Agent SecurityBest PracticesTutorial
1 source: ibm.com Updated 5mo ago
Low severity STABLE

Microsoft Data Exposure

A reported vulnerability in Microsoft 365 Copilot could lead to the exposure of sensitive email content through its AI summarization feature. This flaw poses a risk of unauthorized data disclosure, potentially compromising user privacy within the Microsoft 365 ecosystem.

MicrosoftData LeakageAI SummarizationCopilot Vulnerability ExposesSensitive Emails
1 source: cyberpress.org Updated 6mo ago
Low severity STABLE

Dangers Data Exposure

A viral AI caricature trend exposes enterprises to shadow AI risks and sensitive data leakage, as employees input work-related information into public LLMs and share results. This behavior enables adversaries to conduct targeted social engineering for LLM account compromise, granting access to confidential prompt histories.

Data LeakageDangersHighlight Shadow AIViral AI Caricatures
1 source: techrepublic.com Updated 6mo ago
Low severity STABLE

The Silent Leak: How URL Previews in LLM-Powered Tools Are Quietly Exfiltrating Sensitive Data

Security researchers have identified a vulnerability where prompt injection attacks in LLM-powered applications can weaponize URL preview features to silently exfiltrate sensitive data. Attackers can craft malicious prompts that cause the LLM to generate URLs containing extracted confidential information, which is then transmitted to an attacker-controlled server when the application automatically fetches the URL preview.

Data LeakagePrompt InjectionDataHow URL PreviewsLLMPowered Tools Are
1 source: webpronews.com Updated 6mo ago
Low severity STABLE

AI Chat App Data Exposure

An AI chat application reportedly exposed 300 million messages belonging to 25 million users, as indicated by the article title. However, detailed technical information regarding the nature of the data exposure, the underlying vulnerability, or specific exploitation methods could not be retrieved due to a forbidden access error during scraping.

Data LeakageAI Chat AppExposesMillion MessagesMillion Usersexposed
Low severity STABLE

External Partner Security Data Exposure

Flickr experienced a data breach due to a security vulnerability found within a system managed by a third-party email service provider. This flaw potentially exposed user names, email addresses, IP addresses, and activity logs, though sensitive user passwords and financial information remained secure.

Data LeakageExternal Partner SecurityFlawFlickr Notifies Users
1 source: hackread.com Updated 6mo ago
Low severity STABLE

Configuration Data Data Exposure

According to the article title, over 21,000 OpenClaw AI instances have been identified exposing personal configuration data, indicating a significant data exposure event. This widespread issue points to potential misconfigurations or vulnerabilities within the OpenClaw AI platform allowing unauthorized access to sensitive information.

Data LeakageConfiguration DataFound Exposing PersonalOpenClaw AI InstancesOver
1 source: cyberpress.org Updated 6mo ago
Low severity STABLE

Authentication Tokens Data Exposure

A significant security flaw within Moltbook AI has resulted in the leakage of highly sensitive user data. This compromise includes user email addresses, authentication tokens, and critical API keys, posing a substantial risk to user accounts and potentially wider system access.

Data LeakageAuthentication TokensLeaks User EmailsMoltbook AI FlawSensitive API Keys
1 source: cyberpress.org Updated 6mo ago
Low severity STABLE

ChatGPT Prompt Injection Vulnerability

OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.

Low severity STABLE

Practical LLM Security Advice from the NVIDIA AI Red Team | NVIDIA Technical Blog

LLM-based applications are susceptible to remote code execution (RCE) vulnerabilities when executing LLM-generated code via functions like `exec` or `eval` without proper sandboxing, often triggered by prompt injection. Additionally, insecure access controls in Retrieval-Augmented Generation (RAG) systems can lead to data leakage and indirect prompt injection, while active content rendering of LLM outputs enables data exfiltration by embedding malicious links or images.

Data LeakagePrompt InjectionRemote Code ExecutionAdviceNVIDIA AI RedNVIDIA Technical Blog
Low severity STABLE

GitHub Remote Code Execution Vulnerability

A multi-stage supply chain attack, tracked as UNC6395, originated from the compromise of a Salesloft GitHub repository, leading to the theft of a sensitive OAuth token. This token enabled access to a high-privilege AI chatbot application (Drift) and subsequent exfiltration of customer conversation data and contact information from over 700 integrated Salesforce instances.

1 source: trendmicro.com Updated 11mo ago
Low severity STABLE

Cloud AI Prompt Injection Vulnerability

The article details critical security challenges associated with cloud-hosted Large Language Models (LLMs), including prompt injection, adversarial exploits, model jailbreaks, sensitive data leakage, and misconfigurations. These vulnerabilities, stemming from lack of visibility and ungoverned AI behavior, necessitate proactive discovery and risk management to safeguard AI workloads.

Data LeakagePrompt InjectionCloud AIEnhance LLM SecurityLLM InventoryTotalAI
1 source: blog.qualys.com Updated 11mo ago
News STABLE

The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

The incident involved the mass-theft of authentication tokens from Salesloft's Drift application, leading to significant data exfiltration from integrated corporate Salesforce instances and other cloud services. Threat actors, tracked as UNC6395, leveraged these stolen credentials to perform "authorization sprawl," accessing and siphoning sensitive data including AWS keys and VPN credentials.

News STABLE

Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data

Threat actor UNC6395 exploited compromised OAuth and refresh tokens associated with the Drift AI chat agent, accessible via Salesloft, to gain unauthorized access to Salesforce customer instances. This systematic campaign led to the exfiltration of sensitive data, including AWS access keys, passwords, and Snowflake tokens, from over 700 organizations, indicating a potential supply chain attack.

1 source: thehackernews.com Updated 11mo ago
Low severity STABLE

APIs Credential Exposure

An Insecure Direct Object Reference (IDOR) vulnerability in an exposed API, combined with an unpatched legacy web application and weak credential hygiene, allowed unauthorized access to sensitive applicant personal data. This composite attack vector resulted in a data leak comprising names, emails, and job histories.

1 source: blog.qualys.com Updated 12mo ago
Low severity STABLE

AI Vulnerabilities Data Exposure

The healthcare sector faces an average data breach cost of $7.42 million, driven by the compromise of patient personal identification information (PII). A notable 16% of these incidents leverage AI for sophisticated phishing and deepfake campaigns, often exacerbated by the organizational vulnerability of "Shadow AI" and insufficient AI governance.

Data LeakageAI VulnerabilitiesCostsMillion
Low severity STABLE

Cost Data Exposure

Rapid AI adoption is creating significant security debt due to neglected foundational cybersecurity, specifically a lack of proper AI access controls and governance policies. This oversight has led to a heightened risk of data compromise, operational disruption of AI-based workloads, and the exposure of intellectual property within AI implementations.

Data LeakageCostNavigating
1 source: ibm.com Updated 1y ago
Low severity STABLE

Critical flaw in Microsoft Copilot could have allowed zero-click attack

A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.

Low severity STABLE

AI Hiring Bot Data Exposure

The McHire AI hiring bot, developed by Paradox.ai, suffered from basic security misconfigurations, specifically allowing unauthorized access via easily guessable weak passwords like '123456'. This critical flaw resulted in the data exposure of personal information, résumés, and contact details for tens of millions of McDonald's job applicants.

Data LeakageAI Hiring BotApplicantsDataExposed MillionsHackers Who Tried
1 source: wired.com Updated 1y ago
Low severity STABLE

AI Risks Prompt Injection Vulnerability

The article highlights critical security risks in AI and LLM deployments, specifically prompt injection and jailbreak attacks, which enable manipulation for unauthorized actions, sensitive data exposure, and compliance failures. These rapid exploits, alongside data leakage and model theft, pose significant financial and reputational impacts on enterprises leveraging AI technologies.

Data LeakageJailbreakingPrompt InjectionAI RisksInvestmentsQualys TotalAI
1 source: blog.qualys.com Updated 1y ago
Low severity STABLE

Amazon AWS Prompt Injection Vulnerability

The article highlights critical security gaps in Large Language Model (LLM) applications, detailing common vulnerabilities such as prompt injection, sensitive information disclosure, and supply chain compromises. These flaws, categorized by the OWASP Top 10 for LLM Applications, can lead to unintended LLM behavior, data exposure, and other serious consequences.

1 source: trendmicro.com Updated 1y ago
News STABLE

DeepSeek Breach Opens Floodgates to Dark Web

The DeepSeek breach reportedly resulted in sensitive data being exposed to the dark web, indicating a significant impact on data confidentiality. The full article content detailing the specific exploit or incident scope was not successfully retrieved due to a Cloudflare security block during the scraping process.

1 source: darkreading.com Updated 1y ago
Low severity NEW

Data Breaches Hit 471M Victims: 2026 Report Breakdown - tech

The Identity Theft Resource Center reported 471.2 million data breach victims in H1 2026, a 58% increase over 2025, driven by surging malicious insiders and AI-scaled phishing attacks. This escalation is facilitated by exploits like the ShieldBreak Microsoft Defender zero-day (CVE-2026-69414) and supply-chain compromises, exemplified by the Trezor customer data exposure via ShipMonk.

Low severity STABLE

Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity

Z.ai released GLM-5.3, an AI model with significant enhancements for cybersecurity analysis, specifically excelling in white-box vulnerability discovery and exploitation reasoning. The model identified 2,436 vulnerabilities across 269 projects, with 1,097 rated medium to high severity, demonstrating improved performance on benchmarks like CyberGym and ExploitBench.

Low severity STABLE

AI Prompt Injection Vulnerability

Check Point Research details how AI has transitioned from an attack assistant to an autonomous operator, enabling sophisticated malware creation, large-scale social engineering via forged identities, and direct involvement in live intrusions. The report highlights emerging risks including indirect prompt injection, enterprise data leakage through GenAI, and the widespread exploitation of jailbroken commercial AI models by threat actors.

Low severity STABLE

AI Supply-Chain Compromise

The article details the OWASP LLM Top 10, emphasizing indirect prompt injection (IPI) as a critical threat to RAG pipelines due to adversarial instructions embedded in trusted data sources. It outlines architectural mitigations such as privilege separation, instruction hierarchies, output schema enforcement, and document-level RBAC to address data exposure and supply chain risks in LLM deployments.

1 source: wiz.io Updated 1mo ago
Low severity STABLE

AI Ecosystem Supply-Chain Compromise

The TrendAI™ State of AI Security Report reveals a 34.6% year-over-year surge in AI-related CVEs in 2025, totaling 2,130, with nearly half classified as high- or critical-severity. These vulnerabilities, concentrated in areas like LLM tools and agentic AI, facilitate impacts such as data exposure, unauthorized access, deepfake-based fraud, AI-generated malware, and supply chain compromises.

Data LeakageSupply ChainAI EcosystemFault LinesStateTrendAI
1 source: trendmicro.com Updated 5mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

OpenClaw (Moltbot), an LLM agent system, grants unfettered access to user systems and sensitive data, bypassing traditional operating system and browser security protections like sandboxing. The primary security concern is prompt injection attacks, where malicious text can be hidden to seize control of the user's machine, leading to system compromise and data exposure.

Low severity STABLE

AI Prompt Injection Vulnerability

The article details the OWASP Top Ten LLM Security Risks, outlining specific vulnerabilities such as Prompt Injection (LLM01), Training Data Poisoning (LLM03), and Sensitive Information Disclosure (LLM06). These threats can lead to compromised model integrity, unauthorized data exposure, and denial of service, emphasizing the critical need for comprehensive LLM security strategies.

1 source: blog.qualys.com Updated 8mo ago
Low severity STABLE

AI Data Exposure

AI security flaws have negatively impacted half of organizations, enabling cybercriminals to execute sophisticated attacks more easily and significantly increasing social engineering tactics like vishing. These vulnerabilities also introduce risks such as sensitive data leaks, accidental PII training, and drastically reduced attacker breakout times within compromised networks.

Low severity STABLE

AI Data Exposure

Kaspersky outlines security risks for developers employing LLM assistants and "vibe coding" methodologies. These concerns primarily involve the potential for insecure code generation, intellectual property leakage through AI interaction, and the introduction of exploitable vulnerabilities into software during development.

1 source: news.google.com Updated 10mo ago
Low severity STABLE

ChatGPT Data Exposure

A significant 77% of employees are reportedly leaking sensitive corporate data by pasting it into generative AI tools like ChatGPT, primarily through personal, unmanaged accounts. This widespread "shadow AI" activity circumvents traditional data loss prevention (DLP) systems, resulting in substantial data exfiltration and exposing organizations to severe regulatory and compliance risks.

OpenAIChatGPTData LeakageEmployees Leak DataReport Finds
Low severity STABLE

AI Prompt Injection Vulnerability

The article highlights the critical need for AI security tools to combat escalating threats like adversarial inputs, prompt injection, and LLM jailbreaks. These tools aim to identify and remediate vulnerabilities across the ML pipeline, preventing model manipulation and sensitive data exposure.

Data LeakageJailbreakingPrompt InjectionEvery Attack PhasePrepare You
1 source: wiz.io Updated 1y ago
Low severity STABLE

Access Controls Data Exposure

IBM's report reveals that 13% of organizations experienced breaches of AI models or applications, primarily due to a critical lack of proper AI access controls and governance. This prevalent oversight exposes highly sensitive data and leaves AI models vulnerable to manipulation, leading to significant data compromise and operational disruptions.

Data LeakageAccess ControlsBreaches Of AIIBM ReportLacking Proper AIModels Or Applications
Low severity STABLE

AI Data Exposure

The article highlights significant security vulnerabilities associated with Generative AI (GenAI) applications, including inadvertent sensitive data exposure and new attack vectors like malicious prompts. These issues arise from challenges in monitoring GenAI usage and the absence of clear usage policies, leading to compliance risks and the potential for malware propagation.

Data LeakageExplore AI Access

Back to intelligence feed