YFarmX logoYFarmX
Security Desk · live log

AI Risk Radar

92 AI-security incidents logged since 1 Jan 2026

The emerging risks of frontier AI, logged as they are reported: prompt injection, jailbreaks, hijacked agents, poisoned and leaked models, deepfake fraud and the first vulnerabilities found by AI itself. What was hit, how serious it was, and whether it was seen in the wild, with the source on every record.

Showing 92 of 92 incidents

Overview
Incidents loggedSince 1 Jan 202692Cumulative, Jan 2026 to date
Exploited in the wildStatus1516% of 92 · the rest patched, contained, research or proof-of-concept
Critical severityDesk assessment2951 more rated high
PatchedFix shipped4151 in other recorded statuses
Most common typeAll timeAgent Hijack33 of 92 incidents
Days since lastLogged–Days between the last 13 incidents

Incidents · by attack type

  1. Agent Hijack3335.9%
  2. Prompt Injection1617.4%
  3. Poisoning1112.0%
  4. Data Leak99.8%
  5. AI-Found Vuln88.7%
  6. Infra Vuln55.4%
  7. Jailbreak55.4%
  8. Deepfake/Fraud55.4%

Where they sit · lab to live

  • In the wild15
  • Proof-of-concept15
  • Research12
  • Patched41
  • Contained9

Incidents · by month

Severity · all time

92total
Critical
2931.5%
High
5155.4%
Medium
1213.0%
Low
00.0%
  1. A rejected request with max_tokens=0 exhausts decode-worker memory in disaggregated vLLMInfra VulnProof-of-conceptvLLM through 0.29.0 in prefill/decode disaggregated deploymentsCVE-2026-93436High
  2. Azure AI Foundry carried a CVSS 10 missing-authentication flaw, mitigated in the service before customers heard of itInfra VulnPatchedMicrosoft Azure AI Foundry (cloud service)CVE-2026-85889Critical
  3. One malicious extension hijacked the built-in AI agents in five browsers, including Claude in Chrome and CometAgent HijackProof-of-conceptChrome with Gemini, Perplexity Comet, Microsoft Edge with Copilot, Opera Neon, Claude in ChromeCVE-2026-0628High
  4. PraisonAI's jobs API took any caller's YAML and let it pre-approve its own commandsAgent HijackPatchedpraisonai through 4.6.48 and praisonaiagents through 1.6.48CVE-2026-57125Critical
  5. A forum exploit chained with an SSO flaw walked researchers into OpenAI internal codeData LeakContainedOpenAI community forum, an employee's ChatGPT and Codex accounts, and an internal repositoryCVE-2026-32882Critical
  6. Four vLLM advisories in one day, each an unauthenticated request that stalls or bloats the serverInfra VulnPatchedvLLM before 0.29.0Medium
  7. Anthropic disrupts four operations that ran their attacks through AI agentsJailbreakIn the wildGovernment, corporate and individual targets of operations run on stolen customer API keysCritical
  8. Google's Agent Development Kit took a replayed test session straight to code executionAgent HijackPatchedgoogle/adk-python 2.0.0 to 2.6.0 where pytest is installedCVE-2026-79696Critical
  9. VS Code agent network filters bypassed by alternate URL and address representationsAgent HijackPatchedVisual Studio Code before 1.136.2CVE-2026-81378, CVE-2026-81357High
  10. Untrusted VS Code repositories could configure a remote agent host with local-file accessAgent HijackPatchedVisual Studio Code before 1.136.2CVE-2026-78462High
  11. DeepSeek Harness accepted a spoofed loopback Host header as proof a request was localAgent HijackPatchedDeepSeek Harness before dsh-v0.1.2-alpha.1CVE-2026-82533Critical
  12. Roo-Code's auto-approve gate read a command one way while bash ran anotherAgent HijackProof-of-conceptRoo-Code through 3.54.0CVE-2026-82536, CVE-2026-82537High
  13. n8n patches a 17-CVE batch led by an expression-sandbox escape to backend code executionAgent HijackPatchedn8n before 1.123.76, 2.37.7 and 2.38.2CVE-2026-86076, CVE-2026-86083, CVE-2026-86082High
  14. Two Triton Inference Server flaws let unauthenticated callers exhaust compute or reach unguarded functionsInfra VulnPatchedNVIDIA Triton Inference Server for Linux through 26.06CVE-2026-16497High
  15. IBM's MCP Gateway carried four separate holes, all fixed nowData LeakPatchedIBM ContextForge MCP GatewayCVE-2026-18905High
  16. Langflow's localhost-only MCP install check fell for a spoofed headerAgent HijackPatchedIBM Langflow OSS 1.0.0 to 1.11.2CVE-2026-9186High
  17. AWS's own Postgres MCP server let read-only sessions write past their scopeAgent HijackPatchedawslabs.postgres-mcp-server before 1.1.7CVE-2026-85787High
  18. OGX’s MCP connector accepted unchecked destinations, exposing internal servicesData LeakProof-of-conceptogx-ai/ogx (formerly Llama Stack)CVE-2026-85666High
  19. Postgres MCP Pro's restricted mode had a hole a FROM clause fits throughData LeakProof-of-conceptcrystaldba/postgres-mcp 0.3.0CVE-2026-85620Critical
  20. OWL's document tool fetched whatever URL a prompt injection handed itPrompt InjectionProof-of-conceptcamel-ai/owl DocumentProcessingToolkitCVE-2026-85675High
  21. AgentScope copied any directory on the server into an agent's workspace if askedData LeakProof-of-conceptAgentScope through 2.0.7.post1CVE-2026-85685High
  22. Google's Agent Development Kit let an unauthenticated caller read files off the builder endpointData LeakPatchedgoogle/adk-python 1.9.0 to 1.21.0CVE-2026-79707High
  23. Goose recipe security scan misses executable extension and retry fieldsAgent HijackProof-of-conceptgoose recipesCVE-2026-85623High
  24. Nous Research's Hermes Agent ran an attacker's command the moment it checked git statusAgent HijackPatchedHermes Agent 0.18.2 to 0.21.0CVE-2026-71963High
  25. One negative token ID crashes the GPU behind vLLM's embeddings routes until a restartInfra VulnPatchedvLLM before 0.28.0, /v1/embeddings and /pooling endpointsCVE-2026-93592High
  26. Grafana’s MCP server accepted a session ID that looked valid but was never issuedAgent HijackPatchedGrafana mcp-grafana up to and including 1.0.0CVE-2026-19516Critical
  27. CISA puts a LiteLLM authentication bypass on the exploited list and gives agencies two weeksAgent HijackIn the wildBerriAI LiteLLM proxy, before 1.84.0CVE-2026-59822Critical
  28. A preprint shows a third-party agent skill can steer decisions while passing every scannerPoisoningResearchLLM agents that install reusable third-party skillsHigh
  29. An agent’s own memory can grant it permissions its history never gaveAgent HijackResearchLLM agents with persistent memoryHigh
  30. Hugging Face Transformers wrote remote code to disk before asking whether to trust itPoisoningPatchedHugging Face Transformers 4.49.0 to 5.8.1CVE-2026-80047High
  31. Codex read PowerShell’s stop-parsing token differently to PowerShell, and approval was skippedPrompt InjectionPatchedOpenAI Codex CLI and Codex DesktopCVE-2026-19591High
  32. Eclipse Theia’s agent mode wrote wherever the model pointed itPrompt InjectionPatchedEclipse Theia 1.73.0 up to 1.75.0CVE-2026-82217High
  33. MCPHub let any signed-in user rewrite the prompt templates served to everyone elsePoisoningPatchedMCPHub before 1.0.32CVE-2026-79745High
  34. Coder registry compromise exposes provisioning and AI-tool credentialsData LeakContainedCoder workspace registry and provisionersCritical
  35. An Argo CD MCP server listened on every interface and lent out the operator’s tokenAgent HijackPatchedargocd-mcp 0.8.0CVE-2026-82456Critical
  36. Hermes Agent shipped an MCP catalogue pinned to a branch instead of a commitPoisoningPatchedHermes Agent 0.18.2 up to 0.19.0CVE-2026-82021Critical
  37. ESET finds malware carrying a fake nuclear-weapon request to derail AI analysisJailbreakIn the wildAI-assisted malware analysis toolsMedium
  38. ServiceNow patches two AI Platform flaws, both scored a flat tenAgent HijackPatchedServiceNow AI PlatformCVE-2026-18885Critical
  39. The Agno agent framework passed model output straight into exec()Prompt InjectionPatchedAgno up to and including 2.5.8CVE-2026-37003Critical
  40. GitLab Duo could be pointed at an attacker’s endpoint and hand over cloud model credentialsData LeakPatchedGitLab AI Gateway 18.9.0 to 19.2.2CVE-2026-19889Critical
  41. A ToolUniverse sandbox let a caller walk from a literal to the subprocess moduleAgent HijackPatchedToolUniverse up to and including 1.2.6CVE-2026-81096Critical
  42. Google’s langfun ran model output through exec() by defaultPrompt InjectionPatchedGoogle langfun before 0.1.2CVE-2026-75062Critical
  43. A cyber-capable model escaped a virtual machine three times, chaining unknown bugsAI-Found VulnResearchQEMU/KVM virtual machine isolationCVE-2026-9539Critical
  44. OpenAI says its own agents reward-hacked their way onto Hugging Face production systemsAgent HijackContainedHugging Face production infrastructure and ArtifactoryCritical
  45. A web page walks Claude Code's Auto Mode into running an attacker's payloadPrompt InjectionProof-of-conceptClaude Code running in Auto Mode on a developer's machineHigh
  46. NemoClaw lets a visited web page poison the model template behind a developer's agentPoisoningPatchedNVIDIA NemoClaw's bundled Ollama server and the local models behind itCVE-2026-65105High
  47. A pair of critical escapes in OpenShell, the sandbox NVIDIA built to contain AI agentsAgent HijackPatchedNVIDIA OpenShell, the sandbox NemoClaw runs agents insideCVE-2026-65093Critical
  48. A crafted prompt slips past the human approval gate on Amazon's Strands agent toolkitPrompt InjectionPatchedAmazon Strands Agents Tools' python_repl on the agent hostCVE-2026-78379Critical
  49. Chainlit's MCP endpoint took shell commands from anyone who could reach itAgent HijackPatchedChainlit conversational-AI deployments with the MCP feature switched onCVE-2026-45018Critical
  50. Four hundred AI-enabled malware samples, twelve of them on anyone's machinePoisoningIn the wildWindows endpoints reached by trojanised AI applications and AI-assisted malware familiesMedium
  51. An inference server ran every model's own Python, and offered no way to stop itPoisoningPatchedXinference inference servers and any model a user can register on themCVE-2026-76841High
  52. Poisoned monitoring data talks an AI site-reliability agent into deploying ransomwarePrompt InjectionProof-of-conceptAI site-reliability agents that read OpenTelemetry data, tested on a lab build on Amazon BedrockHigh
  53. Encrypted instructions on a web page make Grok hand a reader's chat history to an attackerPrompt InjectionProof-of-conceptxAI's Grok assistant and the session data of anyone who asks it to summarise a pageHigh
  54. An unmonitored Anthropic agent deleted jobs inside a cluster holding sensitive resourcesAgent HijackContainedAn Anthropic compute cluster holding sensitive resourcesHigh
  55. Z.ai holds back GLM-5.3's open weights after the model's exploit chaining outgrew its trainingAI-Found VulnResearchLinux, WebKit, FreeBSD and 266 further open source projectsHigh
  56. Dream documents a near-autonomous multi-agent framework used against Taiwanese government systemsAgent HijackIn the wildTaiwanese government systems: 21 connected systems, 85 accounts, 2,564 personnel records on Dream's countHigh
  57. Resemble AI ties Grok to 87 per cent of the deepfake files behind documented fraud attacks in H1 2026Deepfake/FraudIn the wildIndividuals and organisations targeted by AI-generated deepfakes$7M lostHigh
  58. Encrypted chains of thought replay into weaker sibling models and come back readableData LeakPatchedThe reasoning traces returned by Anthropic, OpenAI and Google APIs, and whatever users left inside themHigh
  59. Kimi K3 escapes its sandbox and reads a UK AISI benchmark's answers off GitHubAgent HijackResearchA UK AISI-framework cybersecurity benchmark evaluation environmentMedium
  60. OpenAI pauses internal work on Astra after it cannot rule out a Critical cyber capability thresholdAI-Found VulnResearchOpenAI's own unreleased Astra model, under its Preparedness FrameworkCritical
  61. Black Hat 2026: a single GitHub issue reaches CI secrets in Claude Code, Gemini CLI and CodexPrompt InjectionPatchedAnthropic Claude Code, Google Gemini CLI and OpenAI Codex, in the vendors' own default CI/CD configurationsCVE-2026-12537Critical
  62. Meta says its Muse Spark 1.1 model breached an outside company during a cyber testAgent HijackContainedAn undisclosed third-party companyHigh
  63. Poison Claude resells Claude access through a proxy that reads every customer promptDeepfake/FraudIn the wildBuyers of grey-market Anthropic Claude API accessMedium
  64. AISI cyber-range agents took 19 unsanctioned actions on the live internetAgent HijackContainedLive internet systems, including a real open-source maintainer on GitHubHigh
  65. ChainDrop npm worm plants a Claude Code startup hook to run before a developer types a promptPoisoningIn the wildnpm packages and developers using Claude Code and VS CodeCritical
  66. OpenAI models exploited a real website after a third-party CTF evaluation misconfigurationAgent HijackContainedA real website whose domain coincided with a simulated CTF challenge's fictional targetHigh
  67. Anthropic revises its assessment after identifying a fourth unauthorised-access incidentAgent HijackContainedThird-party production systems during Claude cybersecurity evaluationsHigh
  68. Claude Mythos Preview breaks new ground in cryptanalysis: HAWK and reduced-round AESAI-Found VulnResearchHAWK (NIST PQC signature candidate), AES-128 reduced to 7 roundsMedium
  69. Kimi K3 finds a Redis zero-day and writes a working exploitAI-Found VulnProof-of-conceptRedisCVE-2026-25589Critical
  70. Criminal turns a jailbroken Claude into a commercial offensive-security toolJailbreakIn the wildAnthropic ClaudeMedium
  71. AWS Kiro agentic IDE flaw let a poisoned web page rewrite its config and run codePrompt InjectionPatchedAWS KiroCVE-2026-10591High
  72. OpenAI models escape a sandbox and breach Hugging FaceAI-Found VulnIn the wildHugging FaceCritical
  73. FBI warns of deepfake videos impersonating IC3 and FBI leadershipDeepfake/FraudIn the wildDeepfake impersonationMedium
  74. Researcher back-doors an open-weight AI model for under $100PoisoningResearchOpen-weight modelsMedium
  75. Bought search ads steered Mac users to weaponised shared Claude chats and a pasted Terminal commandDeepfake/FraudContainedMac users searching for Claude; browser credentials, the macOS keychain, crypto wallets, SSH and cloud credentialsHigh
  76. Grok Build CLI uploaded entire developer repositories, secrets included, to a Google Cloud Storage bucketAgent HijackPatchedDevelopers using xAI's Grok Build CLIHigh
  77. Workflow-level jailbreak makes GitHub Copilot write code it would otherwise refuseJailbreakResearchGitHub CopilotMedium
  78. HalluSquatting: attackers register the names AI assistants inventPoisoningResearchAI coding assistantsMedium
  79. Agent data injection corrupts the data AI agents trust, across major assistantsPrompt InjectionProof-of-conceptAI agentsHigh
  80. DuneSlide: critical Cursor AI editor flaws allow OS-level code executionPrompt InjectionPatchedCursorCVE-2026-50548Critical
  81. BioShocking technique tricks six AI browsers into stealing credentialsAgent HijackProof-of-conceptAI browsersHigh
  82. SearchLeak: one-click Microsoft 365 Copilot flaw could exfiltrate emails and codesPrompt InjectionPatchedMicrosoft 365 CopilotCVE-2026-42824High
  83. AI vulnerability pipeline finds a SQL-injection flaw in a WordPress pluginAI-Found VulnResearchWordPress pluginCVE-2026-3985High
  84. LiteLLM AI gateway flaw exploited in the wild for unauthenticated RCEAgent HijackIn the wildLiteLLMCVE-2026-42271Critical
  85. Google says criminals used an AI-built zero-day in a planned mass-hack campaignAI-Found VulnIn the wildOpen-source toolHigh
  86. FAR.AI finds DeepSeek V4 Pro's safeguards collapse under three simple jailbreaksJailbreakResearchDeepSeek V4 ProHigh
  87. Google Antigravity IDE prompt-injection flaw enabled code executionPrompt InjectionPatchedGoogle AntigravityHigh
  88. OpenAI patches ChatGPT data-exfiltration flaw and Codex token vulnerabilityAgent HijackPatchedOpenAI ChatGPTHigh
  89. Popular LiteLLM PyPI package backdoored in a supply-chain attackPoisoningIn the wildLiteLLMHigh
  90. PerplexedBrowser: Perplexity Comet agent leaks local files via calendar-invite injectionAgent HijackPatchedPerplexity CometHigh
  91. Group-IB documents a maturing market for AI-enabled fraud and deepfakesDeepfake/FraudIn the wildDeepfake servicesMedium
  92. Google Gemini tricked into leaking private meeting data via poisoned calendar invitesPrompt InjectionProof-of-conceptGoogle GeminiHigh

Each row opens the incident's own record page, with the detail and the sources. Download the data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.

Severity is the Security Desk's assessment at the time of logging, from public reporting. Attribution claims are reported as claims, not findings.Last update · 18 Sept 2026