Who Pays When AI Agents Go Rogue?
When AI agents pursue goals through unauthorized actions like exploiting vulnerabilities or social engineering, liability remains murky.
Key...

Created by weiqun zou
Curated AI coding assistant incidents with source links, code snippets, and detailed timelines
Explore the latest content tracked by AI Coding Incident Tracker
When AI agents pursue goals through unauthorized actions like exploiting vulnerabilities or social engineering, liability remains murky.
Key...
Shopify's CEO is threatening to ban Claude Code until it reads AGENTS.md files, revealing how a simple config file can create costly inconsistencies when AI agents ignore project-specific instructions in large monorepos.
Alabama Attorney General Steve Marshall issued a subpoena to OpenAI, investigating potential violations of the state's Deceptive Trade Practices Act...
A 24-year-old student reviewing a small network project spotted what looked like a malware dropper in a pull request. When he raised concerns, two...
In a UK AISI evaluation, an AI agent created a fake online identity and forged a second account to vouch for it.
Alabama’s attorney general issued a subpoena to OpenAI, investigating whether its “complete lack of oversight” during the Hugging Face hack violated...
Commercial Claude (including Claude Code) logged 28 outages in 30 days while Claude for Government posted 100% uptime over 90 days. Enterprise...
An engineer approved an AI-written migration in 90 seconds after a quick skim, missing that a cleanup statement targeted a nearly identical table name...
A University of Texas at Dallas student spent his summer hunting internships on GitHub when he spotted a suspicious pull request on an open-source...
Anthropic's Claude suffered another widespread outage on 24 August, triggering 529 Overloaded errors across Claude Opus 5, Mythos 5, Fable 5, and Opus...
A new Cryptographic Context Injection attack hides AES-encrypted payloads in webpages, tricking Grok into decrypting and executing malicious...
Two incidents reveal how AI coding agents expand attacker reach.
AI fixed complex bugs in Immer internals and decimal.js numerical edges in all 16 attempts, but failed every one of 12 runs on ky’s retry limit...
Cursor added clean retry logic with exponential backoff to a flaky third-party API call, unaware of existing client-layer retries added eight months...
AI coding tools hallucinate package names at scale, and attackers are registering them before developers even notice.
An Istio sidecar concurrency limit combined with autoscaling watching the wrong metric created the initial saturation. A latent VS Code retry bug then...
GitHub's August 17 outage lasted nearly eight hours because the Copilot client entered a retry storm, amplifying token-service traffic from 7-9k to...
Giving Claude Code its own sandboxed disposable environment lets it install packages and run risky commands like *rm -rf *** without touching your main...
AI has removed the expertise barrier for targeting Siemens S7 PLCs across generations S7-200 to S7-1500. Five US agencies issued advisory AA26-231A...