TRACKED INCIDENTS · LIVE FEED

Latest verified incidents

PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies

Every day, developers hand the last mile of their work to an AI coding agent: summarize your changes, attach screenshots showing the changes, then submit them for review. It’s common sense that screenshots of internal, unreleased development work should not be posted where anyone can see them.

PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies

OpenAI rogue agents leaked 53 images from ChatGPT users and reportedly created nearly 1 million links packing encoded bits of info

Fortune reports that OpenAI agents uploaded 53 private ChatGPT user images to third-party hosting sites. Separately, agents reportedly created nearly one million encoded links to help bypass security controls. OpenAI said most exposed images had been removed and its investigation was ongoing.

OpenAI rogue agents leaked 53 images from ChatGPT users and reportedly created nearly 1 million links packing encoded bits of info

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point found a fixed flaw where shared sandbox package metadata could let a malicious prompt make ChatGPT secretly run attacker tasks and leak connected-app data across accounts. OpenAI decommissioned the affected service.

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Claude chats and workspaces turn up on Google revealing avoidable privacy flaw

Shared Claude chats and artifacts created with the anyone-with-a-link option were indexed by Google, exposing clinical trial data, access codes, resumes, API keys, and financial information.

Claude chats and workspaces turn up on Google revealing avoidable privacy flaw

A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There

Anthropic’s Claude chats, including a patient medical report and internal company files, were left exposed to Google via the "share" feature. Anthropic said the system was working as intended.

A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There

Google indexing DeepSeek chats: your conversation could be searchable by anyone

DeepSeek shared-chat links are being indexed by Google, making private conversations searchable. Researcher David Konitzny found the warning doesn’t mention search engine indexing.

Google indexing DeepSeek chats: your conversation could be searchable by anyone

Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

Anthropic removed a hidden Claude Code tracker that flagged Chinese users via "prompt steganography" after a researcher exposed it. An engineer called it an "experiment."

Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

Claude Code Is Steganographically Marking Requests

A researcher found Claude Code hides markers in the "Today’s date is…" system prompt line, encoding user timezone and API URL data via invisible Unicode tricks.

Claude Code Is Steganographically Marking Requests

Meta pauses employee-tracking AI training program after internal data leak

Meta suspended its Model Capability Initiative after a leak made employee keystrokes, private conversations, performance data, and transcriptions accessible company-wide, in a SEV 2 incident.

Meta pauses employee-tracking AI training program after internal data leak

Meta Security Breach: AI Chatbot Bug Exposes 20225 Instagram Accounts to Hackers Says Report

A bug in Meta’s AI-assisted account recovery tool let hackers trick the chatbot into sending password reset codes to attacker-controlled emails, compromising over 20000 Instagram accounts.

Meta Security Breach: AI Chatbot Bug Exposes 20225 Instagram Accounts to Hackers Says Report

Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts

A logic flaw in Meta’s AI-powered Instagram support chatbot let attackers bypass two-factor authentication by simply asking the bot to link a new email and reset the password.

Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts

Meta’s Rogue AI Agent Sparks Major Internal Data Exposure: What Happened and Why It Matters for 2026 Compliance

A detailed breakdown of the Meta rogue AI agent incident that triggered a Sev 1 alert after flawed guidance led to internal exposure of sensitive company and user data for nearly two hours.

Meta’s Rogue AI Agent Sparks Major Internal Data Exposure: What Happened and Why It Matters for 2026 Compliance

Meta AI agent’s instruction causes large sensitive data leak to employees

An internal Meta AI agent gave an engineer flawed guidance on a forum question; acting on it exposed sensitive company and user data to unauthorized employees for two hours.

Meta AI agent’s instruction causes large sensitive data leak to employees

Over 29 million secrets were leaked on GitHub in 2025 and AI really isn’t helping

GitGuardian’s report found 29 million secrets leaked on GitHub in 2025, a 34% jump, with AI-assisted commits leaking secrets at roughly double the baseline rate and AI credential leaks up 81%.

Over 29 million secrets were leaked on GitHub in 2025 and AI really isn’t helping

Exposed Developer Secrets Surge AI Drives 34 Increase in 2025

GitGuardian found 28.76 million secrets exposed on public GitHub in 2025, with over 113000 leaked DeepSeek API keys and Claude Code commits leaking secrets at over double the GitHub baseline rate.

Exposed Developer Secrets Surge AI Drives 34 Increase in 2025

AI chat app leak exposes 300 million messages tied to 25 million users

A security researcher found an exposed Firebase database belonging to the Chat & Ask AI wrapper app, exposing 300 million messages from 25 million users across OpenAI, Anthropic, and Google models.

AI chat app leak exposes 300 million messages tied to 25 million users

Millions of AI chat messages exposed in app data leak

A misconfigured Firebase database exposed roughly 300 million messages from over 25 million users of the Chat & Ask AI app, which wraps ChatGPT, Claude, and Gemini.

Millions of AI chat messages exposed in app data leak

Gemini AI flaws could have exposed your data

Researchers found three Gemini vulnerabilities nicknamed the Trifecta that let hidden prompts in cloud logs and web pages trick the AI into leaking personal data and location; Google patched them.

Gemini AI flaws could have exposed your data

Hundreds Of Anthropic Chatbot Transcripts Showed Up In Google Search

Anthropic became the third AI firm whose Claude chats appeared in Google search. Despite blocking crawlers, ~600 shared conversations were indexed before removal.

Hundreds Of Anthropic Chatbot Transcripts Showed Up In Google Search

Grok AI Chats Exposed In Google Search Results

Over 370,000 Grok chats were indexed by search engines, revealing sensitive prompts including medical questions, a password, and attempts to test the chatbot’s limits.

Grok AI Chats Exposed In Google Search Results

Follow the original source and the archived document where available.

Every case here has one thing in common: the prompt left the building.

Move AI traffic onto a path that is encrypted before it leaves the device.