Active Threats
-
BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
-
MLflow Server-Side Request Forgery Vulnerability
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
-
Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution.
-
CVE-2026-86317: A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function…
-
CVE-2026-86332: A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET…
-
CVE-2026-86289: A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file…
-
CVE-2026-86228: A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls…
Research
-
Agent Memory Is a Surface for Endogenous Authorization Laundering
LLM agents' persistent memory can be corrupted, allowing unauthorized actions through endogenous authorization laundering, with 50.2% false authority creation and 98.6% exploitation rates.
Incidents & Advisories
-
OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.
-
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to poo…
-
When AI Takes Notes: Court Allows Privacy Claims Against Otter.ai to Proceed
Otter.ai's AI notetaker tool has been accused of violating Illinois's biometric privacy law, and the California court hearing the case recently let the proceedings move forward.
-
California regulators rushed their decision on driverless trucks, Teamsters’ lawsuit says
As self-driving vehicles spread across the country, a major California labor union is taking a stand against state regulators who say autonomous trucks are ready for the road.
-
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.
-
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.
-
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
-
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical"…
-
What went wrong: Opus 5 ultracode wiped a production database
What happened A developer - self-describing as a "vibe coder" - gave Claude Opus 5, running in Claude Code's ultracode mode, write access to a production Supabase database.
-
OpenAI agents hijacked German website in previously undisclosed AI breakout this spring
A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter.
-
An AI coding agent wiped a production database
Summary.
-
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclo…
-
Instinct’s powerful AI assistant is raising privacy and security concerns
AIID editor's note: Please visit the original source for the numerous embedded social media posts.
-
Is Instinct safe to use? Three things to know before you sign up
Artificial intelligence capabilities are rapidly evolving, and it seems like there's always a new buzzy use case emerging that's leaps and bounds more advanced than what came before.
-
Gemini allegedly broke production, then wrote itself the hero
A developer claims a Gemini coding agent knocked a live portal offline for 33 minutes, then generated recovery notes that made it sound as if it had fixed the failure itself.
-
The Warning Was in the Manual: GPT-5.6 Sol and the Deleted Database
Matt Shumer's Friday started with a tweet that has now been seen 4.5 million times: "GPT-5.6-Sol just accidentally deleted almost ALL of my Mac's files." Three days later, Bruno Lemos followed with the sequel: "GPT-5.6 Sol just deleted my…
-
OpenAI’s new flagship model deletes files on its own, people keep warning
Users of OpenAI's latest coding and cybersecurity-oriented flagship model, GPT-5.6 Sol, are posting horrifying accounts on social media, claiming the model just up and deleted their files, data, even entire databases on its own, without as…
-
OpenAI’s GPT-5.6 Sol users report missing files, deleted databases: Here’s what we know
Amid the buzz and excitement surrounding GPT-5.6 Sol, OpenAI's latest coding and cybersecurity-focused flagship AI model, recent posts across social media suggest that the model's rollout may have hit a few bumps.
-
Gemini accused of 30,000-line code purge and fake recovery report
A developer claims Google's Gemini coding assistant deleted nearly 30,000 lines of working production code while making changes to a live application -- the sort of productivity boost usually associated with ransomware.