Weekly reading · methodology v1.0
Window ending Oct. 20, 2025
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Sept. 21, 2025 through Oct. 20, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 10, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
2
Control failures only · No qualifying harm. The reading is the highest control level breached: 2, by 2 records. It is a level, not a count.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
2 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.
No harm counting that week. The reading is the highest control level breached, 2: a level, not a count (PI-0031, PI-0030). 2 records reported in the last 30 days.
Records behind this reading · 2
- PI-0031 · CamoLeak: hidden pull-request comments made GitHub Copilot Chat leak private code and secretsControl level 2, broke an instruction: sets the reading
- PI-0030 · ForcedLeak: web form submissions could make Salesforce Agentforce leak CRM lead dataControl level 2, broke an instruction: sets the reading
Only these records move the reading. How it is calculated
- PI-0030ForcedLeak: web form submissions could make Salesforce Agentforce leak CRM lead dataSept. 25, 2025 · No harm reported · Controlled test
- PI-0031CamoLeak: hidden pull-request comments made GitHub Copilot Chat leak private code and secretsOct. 8, 2025 · No harm reported · Controlled test
Sources
These links support the records above. Source availability and conclusions may change.
- Noma Security: ForcedLeak: AI agent risks exposed in Salesforce AgentforceCited in PI-0030
- The Register: Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking salesCited in PI-0030
- The Hacker News: Salesforce patches critical ForcedLeakCited in PI-0030
- CSO Online: Vulnerability in Salesforce AI could be tricked into leaking CRM dataCited in PI-0030
- Legit Security: CamoLeak: Critical GitHub Copilot vulnerability leaks private source codeCited in PI-0031
- The Register: GitHub Copilot Chat turns blabbermouth with crafty prompt injection attackCited in PI-0031
- Dark Reading: GitHub Copilot 'CamoLeak' AI Attack Exfiltrates DataCited in PI-0031
Every weekly brief · How this reading is calculated · Download the weekly card