Corrections
Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.
- Corrections
- 633
- Reports received
- 0
- Reports declined
- 0
- Reports open
- 0
Each correction is listed as its own row. Group bulk changes
| Date | Record | Change | Reason | Found by |
|---|---|---|---|---|
| 2026-10-10 | SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | JadePuffer: The First Complete LLM-Driven Ransomware Attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | 'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | CISA orders feds to prioritize patching Langflow auth bypass flaw | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | GitHub AI agent leaks private repositories via prompt injection attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI coding tool hole illustrates a big problem with human in the loop | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | New bugs in Claude for Chrome allow extensions to abuse AI privileges | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | How I tricked Claude into leaking your deepest, darkest secrets | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google Gemini CLI abused as a hacking agent, malware botnet operator | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Chrome extension flaw lets malicious extensions trigger AI actions | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Hugging Face Hacked in Autonomous AI Attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Hugging Face discloses breach linked to autonomous AI agent | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ServiceNow’s sandbox escape RCE hole now exploited in the wild | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | JadePuffer agentic attacks now target AI model data with ransomware | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI Models Escaped Containment and Hacked Hugging Face | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI says its AI models hacked Hugging Face during testing | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | CISA orders urgent action on actively exploited Langflow RCE flaw | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI model escape puts enterprise AI defenses on notice | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | How OpenAI’s human mistake led to the AI-powered hack on Hugging Face | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Fake Claude app promoted by Bing ads pushes SectopRAT malware | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |