Affected Technology
Google incidents
Google AI and Gemini security developments
AI Security Breach
AI Weaponizes Bugs in 48 Hours, Breaches Hit $6.04M [2026] tech-insider.org
AI Security Incident
CISA Flags First MCP Flaw: LiteLLM CVE-2026-59822 tech-insider.org
OpenAI Security Incident
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
Claude Security Vulnerability
Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.
OpenAI Supply-Chain Compromise
OpenAI AI agents attack: 1,200 bots coordinated Hugging Face breach The Cryptonomist
Claude Credential Exposure
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
FlexPLM Remote Code Execution Vulnerability
A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.
Google Authentication Bypass
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News
OpenAI AI Security Breach Triggers 14-State Legal Reckoning
OpenAI's new GPT-5.5-Cyber tops Claude Mythos 5 in vulnerability benchmark Neowin
Google Security Breach
Hundreds of agents went rogue in lead up to Hugging Face breach Cybersecurity Dive
Microsoft Copilot Remote Code Execution Vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package Ars Technica
OpenAI Security Breach
OpenAI Details How Its AI Agents Bypassed Security Controls in Hugging Face Breach Gadgets 360
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit The Hacker News
AI Data Exposure
Fortinet Buys Virtue AI to Hunt Vulnerabilities in AI Agents Before Hackers Do Startup Fortune
GitHub Supply-Chain Compromise
Fortunately, the company had a policy of checking source code on GitHub first
Google Security Vulnerability
Google Chrome and Mozilla Firefox have received critical updates to address a multitude of security vulnerabilities. These essential patches are deployed to mitigate potential exploitation risks within the web browser platforms.