AI-powered tools and agents are increasingly being adopted in both personal and professional environments, but this rapid integration is outpacing the implementation of adequate security measures. A recent study by the National Cybersecurity Alliance and CybNet found that 43% of workers have shared sensitive information, including financial and client data, with AI tools such as ChatGPT and Gemini, often without any formal training on the associated risks. This widespread use of generative AI has introduced significant data security and privacy concerns, as many employees are unaware of the potential for data leakage or misuse. The vulnerabilities of AI-powered applications are further highlighted by the discovery of two critical flaws in Wondershare RepairIt, an AI-based repair tool used by millions. According to Trend Micro, RepairIt not only contradicted its privacy policy by storing user data in unsecured cloud storage but also exposed users to supply chain attacks by allowing attackers to swap or modify AI models, potentially infecting countless users through a single update. The vulnerabilities in RepairIt were rated with CVSS scores of 9.1 and 9.4, among the highest for consumer AI applications this year, underscoring the severity of the threat. In another case, Notion’s release of version 3.0 with AI agents introduced a new attack vector where prompt injection could be used to exfiltrate confidential data. By embedding malicious instructions in a PDF, attackers could instruct the AI agent to collect and transmit sensitive information to an external server, exploiting the agent’s access to private data and its ability to communicate externally. This attack demonstrates the inherent risks when AI agents are given broad access and communication capabilities without sufficient safeguards. The broader landscape of AI-driven threats is also evolving, as highlighted by the 2025 Global Bot Security Report, which found that most websites remain vulnerable to even basic automated attacks, let alone sophisticated AI-powered bots. Traditional security defenses are struggling to keep pace with the complexity and speed of AI-driven threats, making it increasingly difficult to distinguish between benign and malicious AI activity. Anthropic’s release of Claude Sonnet 4.5, a large language model with enhanced safety and security features, represents an industry effort to address these challenges. The model incorporates advanced safeguards against prompt injection, internal security measures to protect model weights, and restrictions on queries related to dangerous topics. However, even with these improvements, the risk of false positives and the need for ongoing vigilance remain. Collectively, these incidents and studies illustrate the urgent need for organizations to implement robust security training, enforce strict data handling policies, and adopt advanced technical safeguards when deploying AI-powered tools and agents. The convergence of user behavior, technical vulnerabilities, and evolving threat tactics is creating a complex risk environment that demands proactive and comprehensive security strategies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A reported survey found that 43% of workers said they had shared sensitive information with AI systems, including financial and client data. The survey finding was publicly reported on the reference's publication date.
A 2025 global bot security report was published, stating that the web's bot problem is not improving and providing updated threat insights. No earlier report-release date is given in the reference, so the publication date is used.
Anthropic publicly touted safety and security enhancements in Claude Sonnet 4.5, marking a product security update for the model. With no separate event date in the reference, the publication date is used.
Research describing how Notion's AI agent could be abused for data theft was published, revealing a new AI-related attack technique. The reference does not provide an earlier event date, so the publication date is used.
A report disclosed security breaches in the AI-powered Wondershare RepairIt tool, indicating vulnerabilities affecting the product's security posture. No earlier event date is provided in the reference, so the publication date is used as the best estimate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
5 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcecyberscoop.com
Open sourcesecurityboulevard.com
Open sourceschneier.com
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.