Skip to content

Corrections

Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.

Corrections
633
Reports received
0
Reports declined
0
Reports open
0

Each correction is listed as its own row. Group bulk changes

DateRecordChangeReasonFound by
2026-10-10Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K DownloadsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-101,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolutionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious Hugging Face model masquerading as OpenAI release hits 244K downloadsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Google discovers weaponized zero-day exploits created with AISeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial AccessSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More PackagesSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain AttackSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Copy.Fail Linux VulnerabilitySeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Shai Hulud attack ships signed malicious TanStack, Mistral npm packagesSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Fake Claude Code takes the IElevator to your browser secretsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hugging Face Packages Weaponized With a Single File TweakSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Mistral AI SDK, TanStack Router hit in npm software supply chain attackSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Memory Is a Feature. It Is Also an Attack SurfaceSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a research publication.Classifier audit
2026-10-10Hackers Targeted PraisonAI Vulnerability Hours After DisclosureSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10PraisonAI vulnerability gets scanned within 4 hours of disclosureSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of DisclosureSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenAI confirms security breach in TanStack supply chain attackSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10TeamPCP hackers advertise Mistral AI code repos for saleSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI agent finds 18-year-old remote code execution flaw in NginxSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenAI Hit by TanStack Supply Chain AttackSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS UpdatesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10'Claw Chain' Vulnerabilities Threaten OpenClaw DeploymentsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AntV data visualization tool the latest to be hit by ongoing npm supply chain attacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Anthropic Silently Patches Claude Code Sandbox BypassSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GitHub admits major source code leak after 3,800 internal repositories breachedSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Unpatched ChromaDB flaw leaves servers open to remote code executionSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10AI Attacks Are No Longer Experimental: Key Findings from the March-April 2026 AI Threat LandscapeSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10TrapDoor malware campaign puts developer workstations in CISO spotlightSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 reposSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Microsoft Copilot Cowork Exfiltrates FilesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10The NSA, ‘Mythos’ and the quiet emergence of AI cyber doctrineSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery SystemsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette frameworkSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Malicious npm Package Stole Files From Claude AI User Directory via GitHubSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10GreyVibe hackers use ChatGPT, Gemini to power cyberattacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 ExploitSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing SurfaceSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10ChatGPT share links abused to host fake outage pages to deliver malwareSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Russia-aligned crime group Greyvibe extensively uses AI in attacksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain AttackSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Flowise’s MCP implementation can run ghost commandsSeverity: critical to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Attack targeting OpenAI Codex users exposes AI software supply chain risksSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10HP Poly VoIP vulnerability sets the stage for executive voice deepfakesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10The sorry state of skill distributionSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10WhatsApp, Slack Notifications Could Hijack Google Gemini on AndroidSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hacking Meta’s AI ChatbotSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Hugging Face Transformers RCE flaw enables stealthy compromise via AI model configsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Gemini Voice Assistant Hijacked via Messaging NotificationsSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit
2026-10-10Claude Code has an MCP security problem — and your developers are already using itSeverity: high to mediumSeverity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report.Classifier audit