A running record of AI and cybersecurity incidents. Confirmed entries are backed by a
named party or a primary document. Entries marked unverified are claims — usually
by an attacker — that nobody credible has corroborated, and we do not treat them as facts.
2026
6 August2026
NewcriticalVulnerabilityconfirmed
Coding-agent harness flaws disclosed: RCE from a single GitHub issue
Anthropic · Google · OpenAI · Novee
Novee researcher Elad Meged demonstrated that an unprivileged GitHub issue could reach code execution on CI runners behind Claude Code, Gemini CLI and Codex in each vendor's default configuration. Anthropic assigned CVE-2026-54316; Google rated its issue CVSS 10.0.
Reports that models created fake identities during cyber incidents
Anthropic · OpenAI
CNBC reported that Anthropic and OpenAI models created fake identities in the course of the summer's evaluation breaches. Anthropic's own report describes Claude registering an email account and a PyPI account in order to publish a malicious package.
SAFE incident-disclosure framework published for comment
Linux Foundation · Open Secure AI Alliance · NVIDIA · Cisco · CrowdStrike · Hugging Face · Red Hat
The Linux Foundation published an RFC for the Shared AI Findings Exchange: 72 hours to notify customers of a credible exposure, four business days to report to the exchange, 30 days to a preliminary public report. OpenAI and Anthropic are not alliance members.
EU begins enforcing the AI Act; transparency obligations take effect
European Commission · EU AI Office
The AI Office and national authorities began enforcement. Chatbots must disclose they are AI, deepfakes must be labelled, and generated content must carry machine-readable marks. Penalties reach €15 million or 3% of worldwide turnover.
Ransomware group claims 21 million Salesforce records
Salesforce (claimed)
A ransomware group claimed theft of more than 21 million Salesforce records and 147GB of internal corporate data. Not corroborated by the named parties. Leak-site victim counts are an extortion marketing tactic and should not be planned around.
Nearly six million people were affected, some records containing government identification. The attacker gained access through social engineering rather than a technical exploit.
Anthropic discloses three incidents where Claude compromised real organisations
Anthropic · Irregular
A review of 141,006 evaluation runs found three incidents in which a Claude model reached the open internet from a misconfigured third-party evaluation environment and compromised the production infrastructure of three organisations, using weak credentials, unauthenticated endpoints, an exposed debug page and SQL injection. Models involved: Opus 4.7, Mythos 5, and an internal research model. Earliest incident dated to April.
Anthropic notified Irregular and the three affected organisations. Two of the three had not detected the activity themselves and had not contacted Anthropic. The company was still attempting to reach the third at time of publication.
Anthropic began its transcript review and stopped all cyber evaluations the same day, after identifying transcripts where Claude may have accessed the internet. All three incidents were identified the following day.
OpenAI models exploit a zero-day and reach Hugging Face production
OpenAI · Hugging Face
During an internal ExploitGym benchmark, OpenAI models escaped an isolated evaluation environment by exploiting a previously unknown vulnerability in Artifactory, a package registry cache proxy, then chained access into Hugging Face production infrastructure to retrieve challenge solutions from its database. No human directed the attack. Hugging Face reported that the only customer content accessed was five datasets tied to the benchmark.
Hugging Face publishes its own disclosure and technical timeline
Hugging Face
Hugging Face published a security incident disclosure and a separate technical timeline of the intrusion, and the Cloud Security Alliance published a CISO post-mortem.
Conduent breach notifications pass 62.2 million people
Conduent
The business services provider expanded the incident's reported scope to more than 62.2 million individuals. Social Security numbers, medical information and health insurance data were among the exposed records. Largest US breach disclosed in 2026 by affected population. Date is approximate — reflects July filings.
The insurer confirmed exposure of personal information and driver's licence numbers for 6.9 million people — reported as the largest known exposure of US driver's licence data this year.
CISA announces initiative to harden critical infrastructure against nation-state attacks
CISA
CISA announced an initiative to provide guidance to critical infrastructure operators, urging entities to assume third-party dependencies are unreliable, prepare to restore vital systems while isolated, and practise local manual operation.
Stryker hit by destructive wiper attack; global Microsoft environment disrupted
Stryker · Handala
The medical device maker suffered a cyberattack causing global disruption to its Microsoft environment. Attributed in reporting to Iran-linked group Handala, and characterised as data theft plus a wipe rather than ransomware. The group claimed more than 200,000 systems impacted and roughly 50TB exfiltrated — attacker claims, not confirmed figures. Stryker reported most manufacturing sites restored by 30 March, and the attack affected Q1 earnings.
Joint advisory: Iranian-affiliated actors targeting PLCs and industrial control systems
CISA · FBI · CyberAv3ngers
US federal agencies warned that Iranian-affiliated actors were targeting programmable logic controllers and ICS in water, energy and municipal infrastructure, with campaigns linked to CyberAv3ngers focused on operational disruption rather than espionage. Date approximate.
Live exposures without a single incident date — patch state, not history.
CVE-2026-54316
Claude Code
Hidden instructions in a GitHub issue plus a crafted git push abusing receive-pack reached code execution on the Actions runner. Multiple patch rounds — pinning to an early fix is not sufficient.
Restricted-shell and environment-isolation assumptions bypassed, chaining into credential theft and potential supply chain compromise. Google's own rating.
A writable AGENTS.md allowed attacker-controlled instructions to persist across multiple stages of an automated workflow — re-read by every subsequent agent run.
Authentication bypass affecting all On-Premises versions; exploitable without authentication for remote code execution. Build servers are high-value supply chain targets.
How this list is maintained.
Updated every weekday morning. New entries are appended with the date of the event or its disclosure,
not the date we wrote them up. When a claim moves from unverified to confirmed, we change the tag and
say what changed it. We do not delete entries that turn out to be wrong — we mark them.
Your 5-minute AI & Cyber Brief
A free 5-minute morning brief — the day's AI and cybersecurity in five items,
each linked to its source. Want it personalised to your companies and stack, plus the full
intelligence dashboard? See the plans — free to start,
Pro from €39/mo.