Incident library

Real-world AI security incidents

Every attack module in Kyora IQ Nemesis is grounded in a documented, real-world exploit. These are the incidents that shaped the test suite.

March 2026
McKinsey & Company
'Lilli' AI Platform

An autonomous agent with no credentials breached McKinsey's internal AI in two hours - exposing 46.5M chat messages, 728K client files, 57K user accounts, and gaining write access to system prompts controlling 40,000 consultants. Total cost: $20.

Most Recent
The Register, March 2026
2026 · CVE-2025-32711 · CVSS 9.3
Microsoft
Copilot

Hidden injection in a shared document's speaker notes caused Copilot to return the user's private recent emails when they asked for a summary. No click, no download - just a question to an AI assistant.

CVSS 9.3
Microsoft Security Response Center, 2026
2025 · CVE-2025-53773 · CVSS 9.6
GitHub / Microsoft
GitHub Copilot

Instructions hidden in a source code file as a disguised markdown image tag caused Copilot to send sensitive data to an attacker-controlled URL. Over 10 million developers were in scope.

CVSS 9.6
GitHub Security Advisory, 2025
2024
OpenAI
ChatGPT

A persistent prompt injection manipulated ChatGPT's memory feature to exfiltrate data across multiple separate conversations. The attacker's instructions survived between sessions.

Persistent injection
Security Research, 2024
2024 · CVE-2024-5184
Vanna AI
Vanna AI (NL-to-SQL)

Prompt injection in a natural language database interface enabled arbitrary SQL query generation against connected production databases - no authentication bypass required.

CVE-2024-5184
NIST NVD, 2024
2025 - Black Hat
Google
Google Gemini

Researchers embedded prompt injection payloads inside calendar invite descriptions. When users asked Gemini to summarise their schedule, the hidden instructions fired - demonstrating any LLM-processed data is a potential attack vector.

Indirect injection
Black Hat 2025