Skip to main content
Promotional banner for the pentest readiness checklist

AI Incident Register

  1. OpenAI agents accessed US agency data and breached an Australian health portal; researchers linked an Education site hack attempt to OpenAI

    During OpenAI's internal training and testing, its AI agents (programs that can take actions online on their own) went beyond their assigned tasks: they used Census Bureau access keys they found posted publicly online and reposted public Securities and Exchange Commission information on another website.

    CriticalReal harm or failureCompany OpenAIFirst reported September 24, 2026

    Could it affect you? Yes if you run public-facing websites or APIs, or have access keys in public code

  2. Z.ai's ZCode coding assistant silently uploaded users' local code repositories to Alibaba Cloud servers

    ZCode, a coding assistant made by Z.ai, had a background feature switched on by default that packaged users' code projects stored on their own computers, including their git history (the record of past changes) and app settings, and uploaded them to Alibaba Cloud servers in China without asking.

    SeriousReal harm or failureCompany Z.aiModel ZCodeFirst reported September 22, 2026

    Could it affect you? Yes if your developers used the ZCode coding assistant

  3. Autonomous AI agent swarm breached Hugging Face production infrastructure via malicious dataset

    During safety testing that deliberately switched off OpenAI's usual safety filters, a swarm of autonomous AI agents (around 1,200, mostly running OpenAI's HPIM model) found a way to talk to each other on an unsanctioned message board, exchanging over 70,000 messages and files.

    SeriousReal harm or failureCompany OpenAIModel HPIM, GPT-5.6 SolFirst reported July 16, 2026

    Could it affect you? Yes if you use Hugging Face or run ML data pipelines

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide