Incidents Index

Recorded attacks on AI (AI systems compromised) and with AI (AI used as attack tooling). One page per incident. Each incident page captures: attack class, vector, timeline, target, impact, and defensive lessons that link back to relevant wiki/practices/, wiki/architectures/, or wiki/frameworks/ pages.

Why per-incident pages

Incidents are the empirical record that frameworks and controls get measured against. Tracking them individually preserves the evidence trail and enables rate-of-occurrence analysis. Generic rollups lose this.

2024

DateIncidentClass
2024-08-20Slack AI private-channel exfiltrationPrompt injection — indirect; canonical Lethal Trifecta case

2025

DateIncidentClass
2025-05-07Cursor npm credential stealerSupply chain — npm packages targeting AI IDE
2025-07-16Claude → Stripe coupons via iMessage metadata spoofingPrompt injection — multi-MCP context pollution
2025-11-11VS Code AI output validation bypassPrompt injection — IDE security feature bypass

Q1 2026

DateIncidentClass
2026-01 → 2026-02ClawHavocSupply chain — agentic skill marketplace
2026-02-17ClinejectionPrompt injection — AI-attacks-AI
2026-02-20SANDWORM_MODE npm wormToolchain poisoning — MCP injection
2026-03-03Unit 42 in-the-wild prompt injection observationsPrompt injection — telemetry
2026-03-18Meta Sev 1 agent breachAutonomous breach — proprietary code exposure
2026-03-24LiteLLM supply chain compromiseSupply chain — Google ADK dependency

Ongoing

  • MCP CVEs Q1 2026 — 30+ filed Jan–Feb 2026; 82% of 2,614 surveyed MCP implementations vulnerable to path traversal. See MCP CVEs Q1 2026.

Adding a New Incident

  1. Copy _templates/incident.md.
  2. Choose incident_class from the enum.
  3. Set attack_with_or_on_ai: an “on AI” incident has the AI system as the target; a “with AI” incident uses AI as the attack vector; “both” if both apply.
  4. Cross-reference defensive lessons to relevant practices/, architectures/, frameworks/ pages.
  5. Add to the table above and to wiki/index.md.

Pages

14 items under this folder.