Affected Technology
Google incidents
Google AI and Gemini security developments
OpenAI Security Breach
Researchers Breach OpenAI Using Claude in 72 Hours 조선일보
AI Security Breach
When AI Hacks AI: Inside the Shocking OpenAI Security Breach JO24
Data Breach Investigations Report application-local accounts not in centralized access reviews Vulnerability
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
Google Security Breach
Google's Gemini AI Breaks Out, Hacks Systems in Security Breach The Tech Buzz
Three-Person Team Uses Claude to Breach OpenAI's Core Codebase; $6,500 Bounty Triggers AI Security Alarm
Three-Person Team Uses Claude to Breach OpenAI's Core Codebase; $6,500 Bounty Triggers AI Security Alarm finance.biggo.com
Claude Security Breach
Three-Person Team Uses Claude to Breach OpenAI's Core Codebase; $6,500 Bounty Triggers AI Security Alarm finance.biggo.com
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
Astra hidden vulnerability
The AI Security Problem Is Bigger Than the Hugging Face Breach HackerNoon
Claude Remote Code Execution Vulnerability
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
ChatGPT Remote Code Execution Vulnerability
AI agents, including Claude Sonnet 4.5, GPT-5, and Gemini 2.5 Pro, demonstrated high proficiency by solving 9 out of 10 lab challenges that simulated real-world web application vulnerabilities with minimal cost. These successes encompassed exploits like authentication bypass, IDOR, stored XSS, S3 bucket takeover, and AWS IMDS SSRF, highlighting AI's capability for multi-step reasoning and rapid pattern recognition.
ChatGPT Data Exposure
Autonomous AI agent hit Spanish firm with vulnerability scans before accessing files and data TechRadar
Spain reports first data breach involving autonomous AI agent
Spain reports first data breach involving autonomous AI agent Help Net Security
ChatGPT Security Incident
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the
AI Data Exposure
Using AI tools without browser security literacy is a vulnerability companies can't ignore diginomica.com
Claude Authentication Bypass
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
OpenAI Security Incident
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
Claude Security Vulnerability
Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.
Claude Credential Exposure
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
FlexPLM Remote Code Execution Vulnerability
A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.
Google Authentication Bypass
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News
OpenAI AI Security Breach Triggers 14-State Legal Reckoning
OpenAI's new GPT-5.5-Cyber tops Claude Mythos 5 in vulnerability benchmark Neowin
Microsoft Copilot Remote Code Execution Vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package Ars Technica
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit The Hacker News
AI Agents Before Prompt Injection Vulnerability
Fortinet Buys Virtue AI to Hunt Vulnerabilities in AI Agents Before Hackers Do Startup Fortune
GitHub Supply-Chain Compromise
Fortunately, the company had a policy of checking source code on GitHub first
Google Security Vulnerability
Google Chrome and Mozilla Firefox have received critical updates to address a multitude of security vulnerabilities. These essential patches are deployed to mitigate potential exploitation risks within the web browser platforms.