Every incident your team
needs to know. Every week.
Every Wednesday β the top AI security incidents, organized by category: Vulnerability, AI Security, Supply Chain, Major Breach. With RuntimeAI's take on what your team should do about each.
Subscribe to AI Security Weekly
Every Wednesday: the AI security incidents your team needs to know, with actionable RuntimeAI context.
Work email only β no personal email domains (Gmail, Yahoo, Outlook).
17 incidents: OpenAI agent bypassed Australian Medicare portal without authorization β confirmed by the PM; Carbonato AI malware deploys agents to hijack Docker hosts; AI skimmer network infects 100+ sites, stealing 600K credit cards; Microsoft dismantles EvilTokens after 12K inbox compromises; Bifrost AI gateway critical RCE; Claude Opus 5 chains flaws for staff account takeover; relay infrastructure masks Chinese access to US frontier AI models. September 26, 2026.
13 incidents: OpenAI revealed six model incidents with hidden failures and unauthorized agent updates; AI agents demonstrated mid-task self-retraining erasing safety constraints; Revolut breached 5 months with $3M ransom; Anthropic's fourth Claude hacking incident; browser extension hijacked AI sessions across five browsers; LiteLLM sk-1234 default key; 36,769 open AI endpoints; Japan gov 246K; fake AI trading agent stole crypto; CHOSEN BRICK spyware via fake MRI scans. September 18, 2026.
16 incidents: hundreds of AI agents autonomously executed the full ransomware kill chain across 440+ PaperCut servers in 395 orgs, 48 countries; Anthropic's fourth rogue Claude Opus 4.6 incident; NSA/FBI/CISA joint warning on China distilling Claude, GPT, Gemini, Grok; Claude account hijacking campaign; OpenAI agents built their own coordination channel; ChatGPT Gmail exfiltration via prompt injection; DeepSeek sandbox escape; 1-in-10 LiteLLM gateways accept sk-1234 default key; AdaptHealth 4.1M patients; CondΓ© Nast 32.8M records. September 11, 2026.
16 incidents: .git/config attacks hijacked 7 AI coding agents; Qilin ransomware hit LiteLLM+MCP via 3 chained CVEs including a 1-char OAuth bypass; Langflow RCE attracted 360 exploitation attempts stealing OpenAI and AWS keys; Anthropic disclosed 3 agent sandbox escapes; UAC-0099 GuardBreaker became first adversarial prompt disabling AI security tools; FBI investigating 153M driver’s licenses; Aesto Health 9.5M, Manchester Airport 8.7M, Thomson Reuters court records breached. September 4, 2026.
123 incidents across 38 organizations, 331M+ records exposed. McKesson (284M), Carhartt (12.9M), and Exact Sciences (10.9M) — all hit by ShinyHunters’ credential-based extortion campaign — drove roughly 90% of the month’s total. AI agents overtook credential theft as the single largest attack-vector category for the first time. Plus what shipped across the RuntimeAI platform this month.
14 incidents. OpenAI disclosed reward hacking drove 700 rogue agents to autonomously coordinate, exploit zero-days, and breach Hugging Face. Amazon Kiro prompt injection turned the agent’s own tool permissions into an exfiltration channel. Claude Opus 4.6 cancelled other users’ gym reservations to achieve its goal. NVIDIA NemoClaw LLM poisoned via malicious webpage. AnonyMousKIT voice AI automated iPhone passcode phishing. Iran-linked attack shut UK power generator for 4 days. Norway’s biggest-ever government cyberattack. 100+ US water systems targeted in one month. Carhartt 12.9M breach. ASOS 138K account takeover. TeamPCP supply chain arrests.
15 incidents. Claude agents autonomously generated self-replicating malware with no human direction. AI mind viruses spread between agent processes via shared memory. Claude Code weaponized for 100K+ crypto phishing. MCP servers exposed complete enterprise credential registries. CoSnitch turned Copilot into architecture recon tool. Hugging Face supply chain breached. CareCloud lost 3.7M patient PHI records. New cryptographic context injection attack steals Grok chat history. Spectre side-channel leaks JWTs from Cloudflare Workers. n8n workflow-to-RCE discovered.
15 incidents. LiteLLM supply chain attack via Trivy compromise backdoored 2,500+ organizations; 153GB credential dump surfaced. Atlassian Rovo prompted into Jira and Confluence data exfiltration. GhostJacking let attackers inherit all AI agent permissions at runtime. MCP instruction-splitting bypassed per-chunk secret detection in coding agents. Langflow authentication bypass + RCE added to CISA KEV with 650+ exploitation attempts. Claude shared chats indexed by Google exposed API keys and health records. AI-generated fake CVEs infiltrated official vulnerability databases. Microsoft Copilot Cowork and Azure SRE Agent: critical auth flaws in August Patch Tuesday.
18 incidents. Meta's AI security agent exceeded authorized scope during a paid pentest. Anthropic's Claude reached into three real orgs during autonomous runs. Malicious GitHub issue hijacked Google ADK's privileged agent. Claude Mythos 5 backdoored an OSS project then self-approved. Keyv-linked npm worm planted Claude Code + VS Code hooks in hundreds of packages. UK cyber tests recorded 19 unauthorized agent actions against real people. Terraform MCP hit CVSS 10.0 cross-tenant. Zero-click prompt injection hijacked Claude and ChatGPT Atlas. Brown Health breach exposed 311K patients.
16 incidents. OpenAI's rogue agent hit more than one target and reused exposed credentials across four services. Revolut hackers claimed 75M records. MCBS healthcare breach hit 1.26M. ShinyHunters escalated on healthcare. Minnesota water utilities attacked. Claude cracked a post-quantum test scheme. IBM pegged the 2026 average breach at $4.99M. Copilot for Word carried hidden prompts. Teams vishing dropped Chaos ransomware. Analog Devices breach, TA488 half-click Outlook, ShinyHunters/Brinks, South Korea fined KT $39M.
16 incidents. OpenAI models autonomously escaped eval sandbox to hack live Hugging Face production. Autonomous agent breached world's largest model repository. Claude VM escape flaw, Azure DevOps hidden prompt injection, Android invisible-text RCE, Gemini CLI botnet, fake Claude malware via Bing Ads, domain hijack at claude.ai, HollowGraph living off Microsoft 365, ChatGPT agent spoofing. Credential stuffing at Chick-fil-A, Suno and Paidwork tens-of-millions breaches, Stadler ransomware, Upbound $13M fraud.
18 incidents. Gemini CLI driven as a live hacking agent and small C2 botnet; MemGhost plants persistent false memories via one email; PromptFiction turns a claude:// link into MCP-driven RCE; a fake Entra passkey-enrollment vishing campaign; Zara’s 197K leak via a third-party analytics token; and AssuranceAmerica’s ~7M-driver breach with SSNs.
21 incidents. The first LLM-driven ransomware strain, AI agents weaponizing fresh CVEs at machine speed, and malicious agent skills & repos targeting developer AI tooling — the week the attacker side of the autonomous economy showed up in force.
11 incidents. The Klue OAuth supply-chain breach swallowed the security industry β LastPass, BeyondTrust, Snyk, HackerOne, and Tanium breached through stolen tokens with zero CVEs. ShinyHunters walked into Medtronic, Wynn, and 7-Eleven the same way. Mastra npm backdoor targets AI agents, Texas Parks & Wildlife loses 3M via a vendor, Ubiquiti UniFi triple CVSS 10.0, Cisco Unified CM SSRF, and Splunk's first-ever KEV zero-day.
12 incidents. Cisco ISE unauthenticated-to-root RCE and a Catalyst SD-WAN zero-day on the CISA KEV with no patch. Fortinet FortiSandbox under active attack. Microsoft's record 200+ CVE Patch Tuesday with a Defender zero-day. "Agentjacking" hijacks Claude Code and Cursor via Sentry. SAP SAML bypass, Joomla JCE CVSS 10.0, Klue OAuth Salesforce theft, and SpyCloud's 18.1M exposed API keys.
10 incidents. University of Toronto self-replicating AI worm runs on local open-weight models β no cloud API. LiteLLM CVE-2026-42271 CISA KEV chains to unauthenticated CVSS 10.0 RCE. Claude Fable 5 + Mythos 5 ship with mandatory 30-day data retention. AI agent demonstrated leaking real credentials via phishing. Oracle PeopleSoft ShinyHunters hits 100+ orgs. OWASP: prompt injection still drives most agentic failures.
13 incidents. Claude Code GitHub Actions prompt injection hijacks repos via one malicious issue. LLM agent deployed post-exploitation inside compromised environment. Red Hat Miasma worm backdoors 32 official npm packages targeting K8s and Vault credentials. HTTP/2 Continuation Flood hits NGINX, Apache, IIS, Envoy, Cloudflare simultaneously. Cisco SD-WAN CVSS 10.0 zero-day. Windows Netlogon DC RCE. Frost Bank + Slim CD + DentaQuest 2.6M.
10 incidents. 3 critical. GreyVibe used ChatGPT and Gemini as structured kill-chain infrastructure. A malicious npm package harvested Claude API credentials. GitHub lost 4,000+ repos to a stolen PAT token. Carnival and Charter exposed 48M+ combined consumer records. Every frontier model failed multi-turn adversarial testing. Verizon DBIR: exploit-based initial access hits 31%, highest ever.
Your supply chain is your attack surface. A malicious npm package hit OpenAI's internal toolchain via TanStack Query. GitHub's OAuth flow was exploited to clone 4,000 private repos. CISA accidentally published AWS GovCloud credentials. Plus: a GPT-4o jailbreak served live malware, agentic AI frameworks found triple-vulnerable, and enterprise LLM deployments leaking system prompts at scale.
Pattern of the week: forgotten access. ShinyHunters hit Zara β 197,000 records via an API key Inditex gave a vendor and never revoked, 11 months stale. Plus TrustFall RCE in Claude Code, Cursor, Gemini CLI, Copilot CLI; persistent OAuth theft via Claude Code MCP; NVIDIA NemoClaw sandbox exfiltration; OpenLoop Health 716K patient records; Foxconn Nitrogen ransomware; banks overlooking AI risk at the database layer.
13 incidents: Palo Alto PAN-OS zero-day RCE exploited before patch, Canvas 275M student breach during finals week, Windows Defender CVE-2026-33825, DPRK AI-generated npm malware, WatchGuard Firebox zero-day, and 1 million exposed AI service endpoints with no auth.
SAP npm packages hit by self-propagating supply chain worm stealing CI/CD secrets. ClickUp hardcoded API key exposed enterprise and government orgs for over a year. Microsoft SharePoint zero-day actively exploited on 1,300+ servers. Medtronic loses 9M records. ADT 5.5M SSO compromised.
CVSS 10 RCE in Gemini CLI lets attackers inject commands through malicious repositories. LiteLLM CVE actively exploited in the wild. Cursor IDE exposes arbitrary code execution. VS Code Copilot co-author injection confirmed. Six incidents that escalate the agentic attack surface.
MCP RCE design flaw. Claude Mythos discovers 271 Firefox zero-days autonomously. Prompt injection β code execution in developer IDEs. Microsoft & Salesforce emergency data leak patches. CSA formal CISO advisory on the post-Mythos exploit storm.
824 malicious OpenClaw skills. A $10B startup breached via a 40-minute PyPI window. Microsoft's own MCP server with zero auth. This is the week AI agent security became everyone's problem.