Skip to content

Corrections

Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.

Corrections
633
Reports received
0
Reports declined
0
Reports open
0

Each correction is listed as its own row. Group bulk changes

DateRecordChangeReasonFound by
2026-10-10SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC InfostealerSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Researchers Show Copilot and Grok Can Be Abused as Malware C2 ProxiesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft says bug causes Copilot to summarize confidential emailsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft says Office bug exposed customers’ confidential emails to Copilot AISeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI platforms can be abused for stealthy malware communicationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious AISeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Six flaws found hiding in OpenClaw’s plumbingSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps PersistenceSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer SystemsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Compromised npm package silently installs OpenClaw on developer machinesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy ModelSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Shai-Hulud-style NPM worm hits CI pipelines and AI coding toolsSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GitHub Issues Abused in Copilot Attack Leading to Repository TakeoverSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10New ‘Sandworm_Mode’ Supply Chain Attack Hits NPMSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKENSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code Flaws Allow Remote Code Execution and API Key ExfiltrationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google API Keys Weren't Secrets. But then Gemini Changed the Rules.Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code Flaws Exposed Developer Devices to Silent HackingSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Previously harmless Google API keys now expose Gemini AI dataSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Your personal OpenClaw agent may also be taking orders from malicious websitesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10‘Silent’ Google API key change exposed Gemini AI dataSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API EnablementSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocketSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hackers Weaponize Claude Code in Mexican Government CyberattackSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ClawJacked attack let malicious websites hijack OpenClaw to steal dataSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Bug in Google's Gemini AI Panel Opens Door to HijackingSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini PanelSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenClaw Vulnerability Allowed Websites to Hijack AI AgentsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Vulnerability Allowed Hijacking Chrome’s Gemini Live AI AssistantSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini PanelSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10CyberStrikeAI tool adopted by hackers for AI-powered attacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Vulnerability in MS-Agent AI Framework Can Allow Full System CompromiseSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the WildSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious AI Assistant Extensions Harvest LLM Chat HistoriesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Used to Hack Mexican GovernmentSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fake Claude Code install guides push infostealers in InstallFix attacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10March Patch Tuesday: Three high severity holes in Microsoft OfficeSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Jack & Jill went up the hill — and an AI tried to hack themSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four MinutesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data ExfiltrationSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Open VSX extensions hijacked: GlassWorm malware spreads via dependency abuseSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AWS Bedrock’s ‘isolated’ sandbox comes with a DNS escape hatchSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCESeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10'Claudy Day’ Trio of Flaws Exposes Claude Users to Data TheftSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Meta AI agent’s instruction causes large sensitive data leak to employeesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10We Found Eight Attack Vectors Inside AWS Bedrock. Here's What Attackers Can Do with ThemSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentialsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10The Kill Chain Is Obsolete When Your AI Agent Is the ThreatSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any WebsiteSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit