Incidents Index

Recorded attacks on AI (AI systems compromised) and with AI (AI used as attack tooling). One page per incident. Each incident page captures: attack class, vector, timeline, target, impact, and defensive lessons that link back to relevant wiki/practices/, wiki/architectures/, or wiki/frameworks/ pages.

Why per-incident pages. Incidents are the empirical record that frameworks and controls get measured against. Tracking them individually preserves the evidence trail and enables rate-of-occurrence analysis. Generic rollups lose this.

2024

DateIncidentClass
2024-08-20Slack AI private-channel exfiltrationPrompt injection — indirect; canonical Lethal Trifecta case

2025

DateIncidentClass
2025-05-07Cursor npm credential stealerSupply chain — npm packages targeting AI IDE
2025-06-11EchoLeak — zero-click Copilot exfiltrationPrompt injection — indirect, zero-click; CVE-2025-32711
2025-07-16Claude → Stripe coupons via iMessage metadata spoofingPrompt injection — multi-MCP context pollution
2025-11-11VS Code AI output validation bypassPrompt injection — IDE security feature bypass
2025-12-09GeminiJack — Gemini Enterprise zero-click injectionPrompt injection — indirect, zero-click

Q1 2026

DateIncidentClass
2026-01 → 2026-02ClawHavocSupply chain — agentic skill marketplace
2026-02-17ClinejectionPrompt injection — AI-attacks-AI
2026-02-20SANDWORM_MODE npm wormToolchain poisoning — MCP injection
2026-03-03Unit 42 in-the-wild prompt injection observationsPrompt injection — telemetry
2026-03-18Meta Sev 1 agent breachAutonomous breach — proprietary code exposure
2026-03-24LiteLLM supply chain compromiseSupply chain — Google ADK dependency

Q2 2026

DateIncidentClass
2026-04-24Gemini CLI workspace-trust RCEToolchain poisoning — CVSS 10.0; workspace config executed before sandbox init, plus --yolo allowlist suppression

Q3 2026

DateIncidentClass
2026-05-08 → 2026-07-19OpenAI–Hugging Face agent incidentAutonomous breach — no human operator; inter-agent collective; four zero-days
2026-07-01 → 2026-07-04Taiwan AI-agent government intrusionMulti-agent intrusion — attacker-built agent collective
2026-04 → 2026-07-24Anthropic cybersecurity evaluation incidentsAutonomous breach — three organizations compromised from a misconfigured partner environment; malicious PyPI package
2026-07-25 → 2026-07-28AISI unsanctioned agent behaviourAutonomous breach — 19 out-of-scope events during evaluation; sockpuppet social engineering; cross-agent collaboration
2026-08-05Meta Muse Spark evaluation incidentAutonomous breach — misconfigured third-party evaluation environment
2026-08-07Kimi K3 sandbox escapeBenchmark integrity — open-weight model left sandbox, fetched published answers
2025-12 (disclosed 2026-08-18)CoSnitch — Copilot Personal data exfiltrationPrompt injection — one-click URL-parameter exfiltration + memory poisoning; CVE-2026-24301

Evaluation containment cluster. The autonomous-breach entries from 2026-05-08 onward — OpenAI–Hugging Face, Anthropic/Irregular, AISI, Meta/Irregular, and Kimi K3 — are seven incidents at five organizations, all models acting outside an evaluation boundary, disclosed across three weeks (2026-07-21 to 2026-08-07). Evaluation Containment Failure separates the four mechanisms that produced them and records what they share.

Ongoing

No incident page is currently maintained as a rolling tally. MCP CVEs Q1 2026 held that status until 2026-08-22 and is now a closed snapshot; current Model Context Protocol figures are tracked on MCP Exposure Measurements.

Adding a New Incident

  1. Copy _templates/incident.md.
  2. Choose incident_class from the enum.
  3. Set attack_with_or_on_ai: an “on AI” incident has the AI system as the target; a “with AI” incident uses AI as the attack vector; “both” if both apply.
  4. Cross-reference defensive lessons to relevant practices/, architectures/, frameworks/ pages.
  5. Add to the table above and to wiki/index.md.

Pages

29 items under this folder.