Loading
Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.
| Date | Record | Change | Reason | Found by |
|---|---|---|---|---|
| 2026-10-10 | CVE 2020-16977: VS Code Python Extension Remote Code Execution | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Malicious Python Packages and Code Execution via pip download | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ChatGPT Plugins: Data Exfiltration via Images & Cross Plugin Request Forgery | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Video: Data Exfiltration Vulnerabilities in LLM apps (Bing Chat, ChatGPT, Claude) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Malicious ChatGPT Agents: How GPTs Can Quietly Grab Your Data (Demo) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ChatGPT: Lack of Isolation between Code Interpreter sessions of GPTs | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | GitHub Copilot Chat: From Prompt Injection to Data Exfiltration | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | DeepSeek AI: From Prompt Injection To Account Takeover | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Security Advisory: Anthropic's Slack MCP Server Vulnerable to Data Exfiltration | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Turning ChatGPT Codex Into A ZombAI Agent | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Amp Code: Arbitrary Command Execution via Prompt Injection Fixed | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | How Devin AI Can Leak Your Secrets via Multiple Means | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Code: Data Exfiltration with DNS (CVE-2025-55284) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773) | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google Jules: Vulnerable to Multiple Data Exfiltration Issues | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Jules Zombie Agent: From Prompt Injection to Remote Control | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google Jules is Vulnerable To Invisible Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Amazon Q Developer: Remote Code Execution with Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | How Prompt Injection Exposes Manus' VS Code Server to the Internet | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Cline: Vulnerable To Data Exfiltration And How To Protect Your Data | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AgentHopper: An AI Virus | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Cross-Agent Privilege Escalation: When Agents Free Each Other | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Prompt injection to RCE in AI agents | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Pirate: Abusing Anthropic's File API For Data Exfiltration | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Antigravity Grounded! Security Vulnerabilities in Google's Latest IDE | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Lack of isolation in agentic browsers resurfaces old vulnerabilities | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Moltbook, the Social Network for AI Agents, Exposed Real Humans’ Data | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | What CISOs need to know about the OpenClaw security nightmare | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google says hackers are abusing Gemini AI for all attacks stages | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Fake AI Chrome extensions with 300K users steal credentials, emails | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google fears massive attempt to clone Gemini AI through model extraction | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude LLM artifacts abused to push Mac infostealers in ClickFix attack | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Infostealer malware found stealing OpenClaw secrets for first time | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Was CISOs über OpenClaw wissen sollten | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer | Severity: high changed tomedium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |