Overview
Severity: HIGH | Affected: Cognition Labs | Category: breach
Cognition Labs, the company behind the AI software engineer Devin, announced a significant data breach. The breach, which occurred in late June, was discovered by their internal security team after noticing anomalous database access patterns. Attackers exploited a zero-day vulnerability in a third-party data visualization library used in their internal dashboards. The compromised data includes user prompts, generated code snippets, and API keys for a subset of their enterprise customers. While full source code repositories were not accessed, the exposure of proprietary code logic and sensitive internal data within prompts poses a significant risk. Cognition Labs has patched the vulnerability, invalidated exposed API keys, and is now working with affected customers. The incident highlights the growing threat of supply chain attacks targeting AI development environments and the critical need to secure the entire lifecycle of AI-powered software development tools.