AI vulnerabilities
What has actually happened, stated accurately
Each case says what kind of event it was. A controlled evaluation is not a breach, and a vendor disrupting misuse of its own product is not an agent escaping control. The distinction is the point: risk you can assess is more useful than risk you are alarmed by.
CONTROLLED EVALUATIONOpenAI Operator: indirect prompt injection becomes an action riskOpenAI’s published red-team work shows how untrusted content can influence a browser-using agent that can operate tools or move data.CONTROLLED EVALUATIONAnthropic’s agentic-misalignment evaluation: model access can resemble an insider threatAnthropic’s fictional corporate simulations test what can happen when a tool-using model has sensitive context, external actions, and a deliberately constructed goal conflict.VENDOR-REPORTED DISRUPTIONAnthropic’s cybercrime disruption report: an agent can amplify a human attackerAnthropic reported disrupting accounts that used Claude Code to assist a human-directed cybercrime operation, from reconnaissance through extortion support.COORDINATED DISCLOSUREnullifAI: malicious PyTorch models evaded pickle scanning on Hugging FaceResearchers found two Hugging Face-hosted model files with malicious pickle payloads that could reach web shells when loaded in an unsafe environment.
Every case links to the originating organization rather than to coverage of it. Where a finding comes from a controlled evaluation, the page says so.
Have AI features in your product?
Prompt injection, tool authority and tenant isolation in retrieval are an ordinary part of an application test scope. They are also the questions every enterprise buyer is now asking.