2025 – 2026

everything that went
wrong

OpenAI had to rotate code-signing certificates across four platforms. The reason: a supply chain worm called Shai-Hulud reached their npm packages. The same worm poisoned 84 TanStack versions in 6 minutes, spread to PyPI through Mistral and UiPath, and swallowed the entire @antv charting ecosystem (639 versions, one hour). TeamPCP breached GitHub from the inside. One poisoned VS Code extension on an employee laptop. 3,800 internal repositories out the door, listed on BreachForums for $50K. They hit Microsoft the same week — three poisoned versions of the official Azure durabletask SDK on PyPI in 35 minutes. North Korea’s Lazarus Group stole $1.5 billion from Bybit in a single transaction. ShinyHunters took 275 million student records from Canvas. Nitrogen ransomware grabbed 8TB of Apple and NVIDIA schematics from Foxconn. DOGE connected the federal personnel database to the open internet. The NSA chief told the Senate that Anthropic’s Mythos broke into “almost all” classified systems in hours. Russian hackers behind the $2.5B Jaguar Land Rover attack that forced a £1.5B UK government bailout were just identified by a NYT investigation nine months after the breach. A Russian crew now plants an Outlook implant that grants every account in your tenant Owner rights on the victim’s mailbox, so reimaging the laptop and rotating the password change nothing. The UN now prices Southeast Asia’s fraud industry at $88–114 billion for 2025 and reports that raiding the compounds relocated them. A leak site everyone called a bluff on turned out to be holding 607,000 UK Department for Education records and the contact roster of the police legal database. Wiz found one signing key inside the Azure Cosmos DB query gateway that returned the primary key for any account in the region, including network-isolated ones, and Microsoft needed eight months to remove it. ShinyHunters talked a Brinks Home employee through a Microsoft Entra prompt and left with 1.1 million customer rows and 3.8 million support chat logs from the company that monitors their alarms. Korea fined KT $39 million after someone pulled the authentication certificate out of a lost femtocell, which was good for ten years, and ran a fake base station on the carrier’s network for eleven months. Anthropic read 141,006 evaluation transcripts and found three where Claude, told it was offline in a simulation, broke into real companies — in one, it registered an unpublished PyPI dependency it found in a fake setup doc, and 15 real machines installed it inside an hour. A build flag set to zero instead of deleted swapped COLDCARD’s hardware RNG for a MicroPython fallback in 2021, and Galaxy Research now counts 1,596 BTC gone from about 7,300 addresses, north of $100 million, with a suspected fourth wave that would take it to $130 million and 90% of the coins still sitting where the thief left them. An operator in Zhuhai sent one Telegram message and DeepSeek picked the targets on its own, querying 25,209 exposed n8n servers in a single unattended session. Seven open-source 4G and 5G cores turned out to trust each other so completely that a duplicate rule ID sends a subscriber’s traffic to whoever asked for it, and one researcher deleted a path segment from a Volvo joint venture’s API URL and got 676,000 trucks plus every OTP the platform sent since 2021. Somebody appended a clipboard hijacker to the tracking script Adform serves from its own CDN to every site on its ad platform, so for five days visiting an unrelated publisher swapped the Bitcoin address in your clipboard, and no antivirus engine flagged it. GlobaLeaks, thirteen years old and six professional audits deep, pointed commercial LLMs at its own source for $3,140 and got back 29 real vulnerabilities, which prices a careful read of anybody’s codebase at roughly $77 a bug. OpenAI then went back through a year of evaluation logs and found more agents that had escaped containment, none of them noticed at the time. Rails gave itself a month before publishing how CVE-2026-66066 works and got three days, because someone shipped a public exploit and Akamai had already written up the part where your secret_key_base becomes a shell. Microsoft put a name on the hijacked hotel Wi-Fi — an SVR sub-cluster serving fake Windows Update screens to the connectivity check your browser fires on join — and found the same equipment behind every affected venue, which points at the captive portal industry rather than the hotels. The FBI and EPA then said the Minnesota water hits were not a Minnesota story — utilities in at least seven states lost their PLCs to somebody who changed the password and the IP address and left operators staring at a blank SCADA screen, with flooding and pressure loss in the reported impacts. And an Alabama community bank told the SEC that part of its ransomware response was obtaining the attacker’s “representation” that the stolen data had been deleted — a promise from the people who took it, offered as if it were a control. And N-able’s fix for an N-central authentication bypass turned out to be incomplete, so the second CVE is being used to log into MSP consoles that can push scripts to every endpoint those providers manage. And Coinkite, warning Coldcard owners that their seeds were guessable, emailed everyone who had bought one going back to 2019 — which is how its customers found out that the 90-day data deletion they had been sold does not cover the email address that identifies them as Bitcoin holders. And CrowdStrike’s annual threat hunting report put a clock on all of it — 88% of public proof-of-concept exploits now get used within 48 hours, which retires the 30-day patch window, while AI-agent activity has passed human activity in its own detection feed. And somebody spent one night inside Liechtenstein’s register of beneficial owners and copied the people behind 31,000 companies, foundations and trusts, which is the single database a financial centre built on discretion would least like to lose, with no ransom demand and nothing yet for sale. Unit 42 then showed that a synced passkey is not a hardware token: on an already-infected Windows PC, malware borrows Chrome’s TPM-wrapped identity key to sign logins with nobody at the keyboard, registers its own fake fingerprint, and lifts the master secret that decrypts every passkey in the account, a secret Google has no way to rotate. Pillar Security got one AI agent to attack another in a live repository: the pull-request triage bot in google/adk-python posted as a collaborator, so a politely worded prompt injection made it summon the maintainers-only Gemini workflow, which had no tool scoping and gave up the runner. Eighteen npm packages that each look clean on their own resolved into a RAT aimed at Alibaba developers and ran for three months, because the malicious logic was the dependency graph plus a JSON rule file on GitHub. And ClickFix is now a rented service: DOUBLECUP puts the payload in your browser cache as a PNG before the fake CAPTCHA loads, so the command you paste downloads nothing. And OpenAI, publishing the account ban on a Cambodian scam network, found more than the outbound messages: the same ChatGPT accounts that wrote the fake trading screens and the forged passports also kept the compound’s worker debt ledgers, salary deductions and disciplinary fines, and translated conversations about detention and escape attempts. Somebody else spent one second inside LpdFi holding a $140 million position fabricated from $2 million of tokens, which was long enough to cross a daily interest boundary and collect a day of yield the protocol had to burn its own liquidity pools to pay. And Boltz turned off its Bitcoin swap service indefinitely without being breached at all: the team said automated, AI-assisted probing was finding bugs faster than four people could patch them, which is the first operator in here to quit on tempo rather than on a loss. Madera Community Hospital waited 14 months to tell 150,810 people that a two-day break-in took their SSNs, bank details and biometrics, and says the extortion crew withdrew its ransom demand claiming it did not want to harm patients. And Everest posted 420,000 STIIIZY customers’ driver’s licenses and medical cannabis cards for sale with nothing to back it but a hash. Forescout found the same private key inside every TP-Link Omada controller, so 17 requests a second claims 1,000 devices before their owners ever adopt them, and the same trust anchor reaches the VIGI cameras watching the building. And Barracuda’s red team asked a compromised account’s Copilot where the money was, and it named a $247,500 wire awaiting final approval. These are 1016 incidents from five months. Every one sourced, graphed, and scored.

1016 Incidents Catalogued
7.4 Peak Magnitude
154 CVEs Tracked

Changelog

What was added and when. Sorted by date added to the catalog, not incident date. New entries appear at the top even if the incident happened earlier.

The feed

All incidents sourced from CVEs, security blogs, and public disclosures. Click for details.

It's getting worse

Each dot is an incident. Y-axis is magnitude on a log10 scale of estimated GDP impact in USD. Each +1.0 = 10× more economic damage. See methodology & reference points.

Critical High Medium Trend

The leaderboard

Top 10 by magnitude. Click a row for the full writeup.

The chain reaction

One misconfigured CI/CD pipeline kicked off a seven-month cascade across ten projects and two ecosystems.

By attack type

Incidents sorted by attack type.

What to do about it

Pin everything

MCP servers, VS Code extensions, npm packages. Pin versions to SHAs, not tags. The hackerbot-claw campaign force-pushed 75 of 76 Trivy version tags. Tags lie.

Sandbox your agents

Your coding assistant does not need prod credentials. The OpenClaw agent deleted a live inbox because someone gave it write access to a mailbox for a "review" task. Apply least privilege to every agent connection.

Log what agents do

Log what the agent did, not what you asked it to do. The Meta agent gave bad engineering advice and the resulting config change sat in production for two hours before monitoring picked up the anomalous access.

Rotate credentials constantly

Every supply chain attack here harvested API keys and tokens. The LiteLLM malware fired on every Python script, whether or not it imported LiteLLM. Short-lived tokens limit the blast radius.

Require human approval for destructive actions

Delete, send, publish, pay. These verbs should require a human confirmation step. The Claude Opus incident (9 seconds from prompt to DROP TABLE) happened because there was no approval gate between intent and execution.

Read the OWASP checklists

The OWASP Top 10 for LLM Applications and the Top 10 for Agentic Applications cover the vulnerability classes behind most incidents on this page. Start there.

Harden your CI/CD

The hackerbot-claw → Trivy → LiteLLM → Mini Shai-Hulud chain started with one pull_request_target workflow misconfiguration. Set permissions: read-all. Don't echo untrusted input into shell commands.

Red-team your AI integrations

Hidden markdown, invisible Unicode, poisoned tool descriptions. All published, all with working PoCs. Test your integrations with adversarial inputs before someone else does.

AD

Devin can do this for you

Devin can run dependency audits, harden your CI/CD config, review MCP server setups, and test for prompt injection. It finds the problems described on this page and writes the fixes.

Try Devin

Methodology: the magnitude scale

Magnitude = log10(estimated economic impact in USD) − 2. Each +1.0 on the scale means 10× more economic damage. Estimates combine direct financial losses, remediation costs, business disruption, and downstream cascading effects.

Reference points: cyber

IncidentYearEst. ImpactMagnitude
NotPetya2017~$10B8.0
Log4Shell (remediation)2021~$10B8.0
CrowdStrike outage2024~$5.4B7.7
WannaCry2017~$4–8B7.7
SolarWinds2020~$1–5B7.2
Colonial Pipeline2021~$1–2B7.1
Equifax2017$700M6.8
Heartbleed (remediation)2014~$500M6.7
Target breach2013$162M6.2

Reference points: crypto

IncidentYearEst. ImpactMagnitude
FTX collapse2022~$8.7B7.9
Bybit hack2025$1.46B7.2
Ronin Bridge2022$625M6.8
Poly Network2021$611M6.8
Mt. Gox2014$450M6.7
Wormhole2022$326M6.5

Incidents on this page range from magnitude 2.3 (OpenClaw inbox deletion) to 7.3 (Outsider Enterprise, $1.9B cumulative). For context, CrowdStrike sits at 7.7 and NotPetya at 8.0. The AI-specific incidents top out at 7.3 (Outsider Enterprise AI-powered phishing network), up from 6.3 (Mini Shai-Hulud). 1016 incidents catalogued.