Here's a list of AI security incidents, privacy breaches, data leaks and other related information
Submit an AI Security Issue ยท Email usCounted by the month an incident became public. The shaded band is the current month, which is still in progress and not comparable to the ones before it.
Each incident carries exactly one category.
โGlobalโ covers incidents with no single jurisdiction. Smaller regions are grouped.
This is a periodic briefing built from: the attack classes worth understanding, how defences are changing, and the attack patterns. Context and analysis are curated for people who build with AI and defend AI breaches.
Your address is stored by Kit and used only to send these updates. Unsubscribe any time.
Category | Title | Region | Date | |||
|---|---|---|---|---|---|---|
Rogue Agent | OpenAI agents hijack dormant German developer wiki DseWiki as a coordination board, making ~15,000 edits | ๐ฉ๐ช Germany | September 20264 months after May 2026 | |||
Rogue Agent | Anthropic finds fourth incident: early Claude Opus 4.6 accessed third-party system in January 2026 evaluation | ๐บ๐ธ US | September 20268 months after January 2026 | |||
Rogue Agent | OpenAI agents linked to 'GemStuffer' campaign of 3,000 RubyGems packages and RCE on RubyDoc.info | ๐บ๐ธ US | September 20264 months after May 2026 | |||
Rogue Agent | OpenAI launches misalignment-reporting framework and discloses six training-time incidents | ๐บ๐ธ US | September 2026 | |||
Rogue Agent | Google confirms Gemini models broke into three real companies during Irregular security evaluation | ๐บ๐ธ US | September 20264 months after May 2026 | |||
Rogue Agent | OpenAI agent accessed non-public files on Services Australia Medicare statistics portal, PM reveals | ๐ฆ๐บ Australia | September 20263 months after June 2026 | |||
Vulnerability | Attackers chain JFrog Artifactory flaws disclosed after OpenAI agent incident to gain admin, plant backdoors | ๐ Global | September 2026 | |||
Hack | Bug-bounty researchers breach OpenAI employee accounts and internal monorepo via forum image-upload flaw | ๐บ๐ธ US | September 2026 | |||
Vulnerability | 'BragJack': one malicious extension hijacks AI assistants in Chrome, Edge, Comet, Opera Neon and Claude | ๐ Global | September 2026 | |||
Vulnerability | Wiz 'Off Guard': LiteLLM MCP auth bypass exploited, 9.6% of exposed gateways accept default 'sk-1234' key | ๐บ๐ธ US | September 2026 |
Rows per page