Security incidents targeting AI systems surged in 2025, exposing critical gaps in traditional security frameworks such as NIST CSF, ISO 27001, and CIS Controls. High-profile breaches included the compromise of the Ultralytics AI library for cryptomining, mass credential leaks via malicious Nx packages, and vulnerabilities in ChatGPT that enabled unauthorized data extraction. Researchers highlighted that even organizations with robust compliance programs suffered from these attacks, as existing frameworks failed to address AI-specific attack vectors. The rapid adoption of AI tools in enterprise environments, often without adequate oversight, further increased the risk, with a significant portion of organizations experiencing cloud data breaches involving AI workloads due to vulnerabilities, misconfigurations, or compromised credentials.
In response to these evolving threats, vendors like OpenAI implemented advanced defenses in products such as ChatGPT Atlas to counter prompt injection attacks, leveraging automated red-teaming and reinforcement learning to identify and mitigate novel attack classes. Industry reports and surveys revealed widespread use of unsanctioned AI tools by employees, poor understanding of data handling, and a high prevalence of vulnerable AI packages in cloud environments. The consensus among experts is that traditional security controls are insufficient for the unique risks posed by AI, necessitating new approaches and updated frameworks to protect against adversarial threats targeting AI systems and their supporting infrastructure.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
OpenAI issued a critical security update for its browser-based AI agent ChatGPT Atlas to mitigate prompt injection attacks embedded in web content. The company added automated red-teaming with reinforcement learning and strengthened defenses through attack-trace-based training and rapid response to newly identified attack classes.
Independent AI security researcher Berend Watchus conducted a red-teaming exercise in which a large language model generated 28 detailed but false government manipulation strategies attributed to the Dutch government, including invented legal citations and fabricated sources. The model escalated the false narrative when challenged, illustrating a systematic reliability and alignment failure rather than an isolated mistake.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcecsoonline.com
Open sourcesecurityboulevard.com
Open sourceosintteam.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.