Corrections
Every change made to a record's classification after it was published, with the reason. Reports come from the form on each record page; the classifier audit and the maintainer's own review find the rest. Dataset releases are frozen, so a correction applies to the live site and to the next release.
- Corrections
- 633
- Reports received
- 0
- Reports declined
- 0
- Reports open
- 0
Each correction is listed as its own row. Group bulk changes
| Date | Record | Change | Reason | Found by |
|---|---|---|---|---|
| 2026-10-10 | When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Some Claude Chats Are Searchable on Google | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Google ADK flaws reveal what happens when AI agents trust the wrong message | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Critical Azure Cosmos DB flaw threatened cross-tenant database takeover | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ChainDrop credential stealing worm infects over 400 npm packages | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OK, Well, Rogue AI Agents Are Hacking Again | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI, Anthropic AI agents targeted real people and systems in cyber tests | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI used new levels of 'autonomy and deception' to trick people in safety test | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI threat report: Rogue agents, workflow attacks | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Critical Paperclip bugs expose AI agent trust failures | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Flaws in Google APK for Python Unlock Agent-to-Agent Attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | An AI model from Meta also hacked another company during testing | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Meta AI Hacked External Systems During Cybersecurity Testing | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Cloud Threat Highlights: H1 2026 | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Meta AI model hacked a company during misconfigured cyber test | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Researcher Claims Control of ChatGPT Secure Sandbox | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Python package security in 2026: How supply chain attacks are targeting your AI development environment | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Trojanized AI skills gain 1.7M installs in agent-targeted attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Now we have a timeline of the OpenAI accidental attack against Hugging Face | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Now we have a timeline of the OpenAI accidental attack against Hugging Face | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | The AI safety test is becoming a safety risk | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Vague Task, Total Access: When AI Delegation Becomes a Security Risk | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Stealing Reasoning Traces from Proprietary LLM APIs | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Stealing Reasoning Traces from Proprietary LLM APIs | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Zoom zero-click RCE flaws allow attackers to compromise meeting participants | Severity: critical to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | AI agents wage near-autonomous cyberattack on Asian government networks | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |
| 2026-10-10 | Anthropic confirms Claude is down in major outage affecting multiple services | Severity: high to medium | Severity capped at medium. High and critical measure technical exploitability and are reserved for vulnerabilities and incidents; this record is a news report. | Classifier audit |