Overview
Severity: CRITICAL | Affected: Cognition AI | Category: breach
Cognition AI, the company behind the popular 'Devin' coding assistant, revealed a significant security breach. Attackers exploited a zero-day vulnerability in a third-party cloud infrastructure management tool to gain unauthorized access to their core production environment. The breach resulted in the exfiltration of proprietary model weights for an unreleased version of their flagship model, as well as a database containing millions of user prompts and generated code snippets from their enterprise clients. The company has stated they are working with cybersecurity firms and law enforcement to investigate the incident. The leaked data poses a severe risk of intellectual property theft and could enable competitors or malicious actors to replicate or analyze their cutting-edge technology. Enterprise customers are being notified and advised to rotate all connected API keys and review their logs for any suspicious activity.