Security Desk · live log
AI Risk Radar
92 AI-security incidents logged since 1 Jan 2026
The emerging risks of frontier AI, logged as they are reported: prompt injection, jailbreaks, hijacked agents, poisoned and leaked models, deepfake fraud and the first vulnerabilities found by AI itself. What was hit, how serious it was, and whether it was seen in the wild, with the source on every record.
Showing 92 of 92 incidents
Overview
Incidents loggedSince 1 Jan 202692Cumulative, Jan 2026 to date
Exploited in the wildStatus1516% of 92 · the rest patched, contained, research or proof-of-concept
Critical severityDesk assessment2951 more rated high
PatchedFix shipped4151 in other recorded statuses
Most common typeAll timeAgent Hijack33 of 92 incidents
Days since lastLogged–Days between the last 13 incidents
Incidents · by attack type
Where they sit · lab to live
- In the wild15
- Proof-of-concept15
- Research12
- Patched41
- Contained9
Incidents · by month
Severity · all time
92total
- Critical
- 2931.5%
- High
- 5155.4%
- Medium
- 1213.0%
- Low
- 00.0%
- A rejected request with max_tokens=0 exhausts decode-worker memory in disaggregated vLLMHigh
- Azure AI Foundry carried a CVSS 10 missing-authentication flaw, mitigated in the service before customers heard of itCritical
- One malicious extension hijacked the built-in AI agents in five browsers, including Claude in Chrome and CometHigh
- PraisonAI's jobs API took any caller's YAML and let it pre-approve its own commandsCritical
- A forum exploit chained with an SSO flaw walked researchers into OpenAI internal codeCritical
- Four vLLM advisories in one day, each an unauthenticated request that stalls or bloats the serverMedium
- Anthropic disrupts four operations that ran their attacks through AI agentsCritical
- Google's Agent Development Kit took a replayed test session straight to code executionCritical
- VS Code agent network filters bypassed by alternate URL and address representationsHigh
- Untrusted VS Code repositories could configure a remote agent host with local-file accessHigh
- DeepSeek Harness accepted a spoofed loopback Host header as proof a request was localCritical
- Roo-Code's auto-approve gate read a command one way while bash ran anotherHigh
- n8n patches a 17-CVE batch led by an expression-sandbox escape to backend code executionHigh
- Two Triton Inference Server flaws let unauthenticated callers exhaust compute or reach unguarded functionsHigh
- IBM's MCP Gateway carried four separate holes, all fixed nowHigh
- Langflow's localhost-only MCP install check fell for a spoofed headerHigh
- AWS's own Postgres MCP server let read-only sessions write past their scopeHigh
- OGX’s MCP connector accepted unchecked destinations, exposing internal servicesHigh
- Postgres MCP Pro's restricted mode had a hole a FROM clause fits throughCritical
- OWL's document tool fetched whatever URL a prompt injection handed itHigh
- AgentScope copied any directory on the server into an agent's workspace if askedHigh
- Google's Agent Development Kit let an unauthenticated caller read files off the builder endpointHigh
- Goose recipe security scan misses executable extension and retry fieldsHigh
- Nous Research's Hermes Agent ran an attacker's command the moment it checked git statusHigh
- One negative token ID crashes the GPU behind vLLM's embeddings routes until a restartHigh
- Grafana’s MCP server accepted a session ID that looked valid but was never issuedCritical
- CISA puts a LiteLLM authentication bypass on the exploited list and gives agencies two weeksCritical
- A preprint shows a third-party agent skill can steer decisions while passing every scannerHigh
- An agent’s own memory can grant it permissions its history never gaveHigh
- Hugging Face Transformers wrote remote code to disk before asking whether to trust itHigh
- Codex read PowerShell’s stop-parsing token differently to PowerShell, and approval was skippedHigh
- Eclipse Theia’s agent mode wrote wherever the model pointed itHigh
- MCPHub let any signed-in user rewrite the prompt templates served to everyone elseHigh
- Coder registry compromise exposes provisioning and AI-tool credentialsCritical
- An Argo CD MCP server listened on every interface and lent out the operator’s tokenCritical
- Hermes Agent shipped an MCP catalogue pinned to a branch instead of a commitCritical
- ESET finds malware carrying a fake nuclear-weapon request to derail AI analysisMedium
- ServiceNow patches two AI Platform flaws, both scored a flat tenCritical
- The Agno agent framework passed model output straight into exec()Critical
- GitLab Duo could be pointed at an attacker’s endpoint and hand over cloud model credentialsCritical
- A ToolUniverse sandbox let a caller walk from a literal to the subprocess moduleCritical
- Google’s langfun ran model output through exec() by defaultCritical
- A cyber-capable model escaped a virtual machine three times, chaining unknown bugsCritical
- OpenAI says its own agents reward-hacked their way onto Hugging Face production systemsCritical
- A web page walks Claude Code's Auto Mode into running an attacker's payloadHigh
- NemoClaw lets a visited web page poison the model template behind a developer's agentHigh
- A pair of critical escapes in OpenShell, the sandbox NVIDIA built to contain AI agentsCritical
- A crafted prompt slips past the human approval gate on Amazon's Strands agent toolkitCritical
- Chainlit's MCP endpoint took shell commands from anyone who could reach itCritical
- Four hundred AI-enabled malware samples, twelve of them on anyone's machineMedium
- An inference server ran every model's own Python, and offered no way to stop itHigh
- Poisoned monitoring data talks an AI site-reliability agent into deploying ransomwareHigh
- Encrypted instructions on a web page make Grok hand a reader's chat history to an attackerHigh
- An unmonitored Anthropic agent deleted jobs inside a cluster holding sensitive resourcesHigh
- Z.ai holds back GLM-5.3's open weights after the model's exploit chaining outgrew its trainingHigh
- Dream documents a near-autonomous multi-agent framework used against Taiwanese government systemsHigh
- Resemble AI ties Grok to 87 per cent of the deepfake files behind documented fraud attacks in H1 2026High
- Encrypted chains of thought replay into weaker sibling models and come back readableHigh
- Kimi K3 escapes its sandbox and reads a UK AISI benchmark's answers off GitHubMedium
- OpenAI pauses internal work on Astra after it cannot rule out a Critical cyber capability thresholdCritical
- Black Hat 2026: a single GitHub issue reaches CI secrets in Claude Code, Gemini CLI and CodexCritical
- Meta says its Muse Spark 1.1 model breached an outside company during a cyber testHigh
- Poison Claude resells Claude access through a proxy that reads every customer promptMedium
- AISI cyber-range agents took 19 unsanctioned actions on the live internetHigh
- ChainDrop npm worm plants a Claude Code startup hook to run before a developer types a promptCritical
- OpenAI models exploited a real website after a third-party CTF evaluation misconfigurationHigh
- Anthropic revises its assessment after identifying a fourth unauthorised-access incidentHigh
- Claude Mythos Preview breaks new ground in cryptanalysis: HAWK and reduced-round AESMedium
- Kimi K3 finds a Redis zero-day and writes a working exploitCritical
- Criminal turns a jailbroken Claude into a commercial offensive-security toolMedium
- AWS Kiro agentic IDE flaw let a poisoned web page rewrite its config and run codeHigh
- OpenAI models escape a sandbox and breach Hugging FaceCritical
- FBI warns of deepfake videos impersonating IC3 and FBI leadershipMedium
- Researcher back-doors an open-weight AI model for under $100Medium
- Bought search ads steered Mac users to weaponised shared Claude chats and a pasted Terminal commandHigh
- Grok Build CLI uploaded entire developer repositories, secrets included, to a Google Cloud Storage bucketHigh
- Workflow-level jailbreak makes GitHub Copilot write code it would otherwise refuseMedium
- HalluSquatting: attackers register the names AI assistants inventMedium
- Agent data injection corrupts the data AI agents trust, across major assistantsHigh
- DuneSlide: critical Cursor AI editor flaws allow OS-level code executionCritical
- BioShocking technique tricks six AI browsers into stealing credentialsHigh
- SearchLeak: one-click Microsoft 365 Copilot flaw could exfiltrate emails and codesHigh
- AI vulnerability pipeline finds a SQL-injection flaw in a WordPress pluginHigh
- LiteLLM AI gateway flaw exploited in the wild for unauthenticated RCECritical
- Google says criminals used an AI-built zero-day in a planned mass-hack campaignHigh
- FAR.AI finds DeepSeek V4 Pro's safeguards collapse under three simple jailbreaksHigh
- Google Antigravity IDE prompt-injection flaw enabled code executionHigh
- OpenAI patches ChatGPT data-exfiltration flaw and Codex token vulnerabilityHigh
- Popular LiteLLM PyPI package backdoored in a supply-chain attackHigh
- PerplexedBrowser: Perplexity Comet agent leaks local files via calendar-invite injectionHigh
- Group-IB documents a maturing market for AI-enabled fraud and deepfakesMedium
- Google Gemini tricked into leaking private meeting data via poisoned calendar invitesHigh
No incidents match those filters.
Each row opens the incident's own record page, with the detail and the sources. Download the data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.
Severity is the Security Desk's assessment at the time of logging, from public reporting. Attribution claims are reported as claims, not findings.Last update · 18 Sept 2026
