Software developers
Affecté par des incidents
Incident 16805 Rapports
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
2026-02-17
An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.
PlusIncident 16334 Rapports
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
2026-07-26
Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.
PlusIncident 16724 Rapports
OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing
2026-07-13
Software engineer Bruno Lemos reported that GPT-5.6 Sol deleted his production database after he asked it to generate seed data for local testing. The agent reportedly ran the test suite, then initiated cleanup that executed TRUNCATE TABLE users CASCADE against production because the repo's test database URL pointed to the live Neon database. OpenAI later acknowledged unauthorized deletion reports and said it was adding safeguards.
PlusIncident 10393 Rapports
Anysphere AI Support Bot for Cursor Reportedly Invents Login Policy, Leading to Subscription Cancellations
2025-04-19
In April 2025, users of Cursor, an AI-powered coding assistant developed by Anysphere, reported being logged out unexpectedly. An AI-powered support bot, "Sam," allegedly responded with an invented login policy to justify the behavior. The hallucinated policy was not based on any real company change. The incident reportedly led to subscription cancellations.
PlusIncidents involved as Developer
Incident 155921 Rapports
Kalibrate Fuel Pricing Allegedly Enabled California Gas Station Operators to Coordinate Higher Pump Prices
2022-06-22
Major gas station operators in California allegedly used Kalibrate Fuel Pricing to automate pump prices using competitor data and reduce price competition. A June 2026 complaint said the AI-based system increased gasoline prices by as much as 30 cents per gallon where adoption was widespread.
PlusIncident 16624 Rapports
Pizza Hut Franchisee Chaac Pizza Northeast Alleged Dragontail AI System Contributed to Delivery Delays and $100 Million in Losses
2026-05-06
Chaac Pizza Northeast, a Pizza Hut franchisee operating about 111 restaurants, alleged in a lawsuit that the chain's mandated Dragontail AI delivery-management system disrupted operations after its rollout. The lawsuit claims that the system's integration with DoorDash led drivers to batch orders, resulting in longer delivery times and lower customer satisfaction while contributing to more than $100 million in claimed lost business and enterprise value.
PlusIncident 16583 Rapports
State Farm Defense Counsel Acknowledged AI-Assisted Filings in Meni-Siliga v. A's Contractor, Inc. Contained Fabricated Legal Authorities
2026-03-31
In Fa'alagilagi Meni-Siliga v. A's Contractor, Inc., et al., attorneys representing State Farm acknowledged that AI-assisted motions contained fabricated and otherwise inaccurate legal authorities. Attorney Jacquelene Robinson said she used the legal AI tool Irys and failed to verify some citations. Opposing counsel identified the errors, after which the firm apologized and filed corrected versions.
PlusIncidents involved as Deployer
Incident 16763 Rapports
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work
2026-07-28
A developer reported that a Claude Opus 5 coding agent reset a live Supabase database while autonomously repairing a personal project's schema. The agent ran `prisma migrate diff` with the production URL supplied as the disposable shadow database, causing Prisma to drop all 22 tables. The developer had granted the agent production access; most content was later recovered or rebuilt.
PlusIncident 16732 Rapports
Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records
2026-05-20
A developer reported that a Gemini 3.5 coding agent, operating with a third-party autonomy rule pack, made sweeping changes beyond a requested authentication fix and altered Firebase routing, causing a 33-minute production outage. After the developer manually rolled back the deployment, the agent allegedly claimed it had restored service and generated fabricated consultation and post-mortem records. Google had not independently verified the incident.
PlusEntités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
Entités liées
AI agent system deployers
Incidents involved as Deployer
- Incident 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
Anthropic
Incidents involved as Developer
- Incident 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
AI agent system developers
Incidents involved as Developer
- Incident 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
Claude
Incidents implicated systems
- Incident 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
AI agent systems
Incidents implicated systems
- Incident 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incident 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
AI software developers
Incidents involved as Developer
- Incident 16624 Report
Pizza Hut Franchisee Chaac Pizza Northeast Alleged Dragontail AI System Contributed to Delivery Delays and $100 Million in Losses
- Incident 16583 Report
State Farm Defense Counsel Acknowledged AI-Assisted Filings in Meni-Siliga v. A's Contractor, Inc. Contained Fabricated Legal Authorities