Skip to content

Corrections

Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.

Corrections
633
Reports received
0
Reports declined
0
Reports open
0

Each correction is listed as its own row. Group bulk changes

DateRecordChangeReasonFound by
2026-10-10New ATHR vishing platform uses AI voice agents for automated attacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging FaceSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10RCE by design: MCP architectural choice haunts AI agent ecosystemSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cursor AI Vulnerability Exposed Developer DevicesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Copilot & Agentforce offen für Prompt-Injection-TricksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fracturing Software Security With Frontier AI ModelsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply ChainSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code ExecutionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Prompt injection turned Google’s Antigravity file search into RCESeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Azure SRE Agent flaw lets outsiders silently eavesdrop on enterprise cloud operationsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Fixes Critical RCE Flaw in AI-Based Antigravity ToolSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container EscapeSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic investigates report of rogue access to hack-enabling Mythos AISeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic’s most dangerous AI model just fell into the wrong handsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Toxic Combinations: When Cross-App Permissions Stack into RiskSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic’s Mythos breach was humiliatingSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Bitwarden CLI password manager trojanized in supply chain attackSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of DisclosureSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Discord Sleuths Gained Unauthorized Access to Anthropic’s MythosSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft patched an ‘agent-only’ role that was notSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Deepfake Voice Attacks are Outpacing Defenses: What Security Leaders Should KnowSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft Patches Entra ID Role Flaw That Enabled Service Principal TakeoverSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCESeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Critical Cursor bug could turn routine Git into RCESeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hackers are exploiting a critical LiteLLM pre-auth SQLi flawSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Learning from the Vercel breach: Shadow AI & OAuth sprawlSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code ExecutionSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10SAP npm package attack highlights risks in developer tools and CI/CD pipelinesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Max-severity RCE flaw found in Google Gemini CLISeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain AttacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hugging Face, ClawHub Abused for Malware DistributionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI agents can bypass guardrails and put credentials at risk, Okta study findsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)Severity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually IsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Critical Bug Could Expose 300,000 Ollama Deployments to Information TheftSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Supply-chain attacks take aim at your AI coding agentsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fake Claude AI website delivers new 'Beagle' Windows malwareSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain AttackSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10'TrustFall' Convention Exposes Claude Code Execution RiskSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP HijackingSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10When prompts become shells: RCE vulnerabilities in AI agent frameworksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Ollama vulnerability highlights danger of AI frameworks with unrestricted accessSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Vulnerability in Claude Extension for Chrome Exposes AI Agent to TakeoverSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude in Chrome is taking orders from the wrong extensionsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fake OpenAI repository on Hugging Face pushes infostealer malwareSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory LeakSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hackers abuse Google ads, Claude.ai chats to push Mac malwareSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit